CVE-2025-6965-SQLite

There is CVE-2025-6965 detected for SQLite and redhat as provided the fix already.

https://access.redhat.com/errata/RHSA-2025:12010

I don’t see the updated package at rocky upstream . When can we expect the fix ?

1 Like

Released 2025-07-28. Two days ago.

Rocky Linux Release and Version Guide - Rocky Linux Wiki writes:

Updates for Rocky Linux are generally expected to be built and released between twenty-four (24) and fourty-eight (48) hours, assuming best effort allows the packages to build without any complications or unforeseen added dependencies by upstream mid-support cycle.

1 Like

Yes, you need more patience. Don’t expect updates to be available the same day that RHEL release them. As already linked by @jlehtone you can expect them in 24-48 hours which is perfectly reasonable. If you expect updates to be available immediately, then perhaps you should be purchasing RHEL subscription :wink:

You have to remember this is a community distribution, so it’s ready when it’s ready. Reset your expectations.

I totally understand the Rocky OS is community distribution and we don’t expect the fix on same day when Redhat fixes. I was asking the time frame of package availability.

I remember Centos was taking 1week for packages updates :slightly_smiling_face:

3 Likes

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.