This point release includes fixes for vulnerabilities responsibly
reported by a number of sources. It also comes at a time when
increasingly capable AI models are being used to identify
potential vulnerabilities in open-source code, significantly
increasing the volume and pace of security reports.
The potential impact and associated risks are front of mind for
everyone involved, not least the remediation team who have worked
tirelessly to triage, resolve, and compile this release.
This embargo period will last for two weeks. The source code
will not be published until 14 days have passed. During this time,
we strongly encourage everyone to upgrade. At the end of this
two-week period, the full release details will be made
available.
This delay is designed to reduce the chances of prospective
attackers reverse-engineering the fixes and exploiting them before
the network can update.