-
Overview
-
redpesk OS releases
-
Security updates
- Security CVE / errata
- CVE quick look
-
Redpesk OS Tips and Tricks
-
Application Framework Manager
-
Application Framework Binder
-
APIs & Services
-
Security manager
-
OP-TEE within redpesk
-
Trusted Boot
-
Recovery features
-
redpak
-
Minimal image
- Reduce image size
- Optimizing boot time
-
Kernel fragments description
- Introduction to Linux Kernel Configuration
- 01 Disable IPC, Timers and Audit
- 02 Disable Kconfig, Scheduler and Initrd
- 03 Disable Perf, Profiling and Errata
- 04 Disable EFI, Power Management Debug and Energy Model
- 05 Disable Schedutil, CPUFreq Governors and Virtualization
- 06 Disable Kprobes and Jump Labels
- 07 Disable GCC Plugins and Function Alignment
- 08 Disable Partition Parsers
- 09 Enable Inline Spinlocks and Kernel Operations
- 10 Disable Swap, Memory Hotplug and KSM
- 11 Disable Networking IPv4, IPv6, Netfilter
- 12 Disable SCTP, VLAN, TIPC, BATMAN
- 13 Disable Wireless, Bluetooth, CAN and RFKILL
- 14 Disable PCI and Firmware
- 15 Disable GNSS and ProcEvents
- 16 Disable Block Storage NBD and AoE
- 17 Disable EEPROM and Misc Drivers
- 18 Disable Network Device Drivers
- 19 Disable PHY Drivers
- 20 Disable PPP, WLAN Coexistence, and Failover
- 21 Disable Input Devices
- 22 Disable Serial, TTY and TPM
- 23 Disable I2C, Power and Sensor Drivers
- 24 Disable MFD, Display and Media Drivers
- 25 Disable USB, Sound, RTC and VirtIO
- 26 Disable Filesystem Encodings and Compatibility
- 27 Enable Minimal Cryptographic Core with SHA3 and XTS
- 28 Disable Hardware Cryptography, Keep DRBG and Jitter Entropy
- 29 Disable Kernel Debugging Features
- 30 Disable Filesystem Verity and SecurityFS
-
Zephyr in Redpesk
-
PERM-CHECK extension
-
Mender redpesk (OTA)
-
Hardware support
- Download images
- Image metrics
- Trusted Boot
- Boards - ARM64
- Boards - x86_64
- Boards - Virtual
- Miscs
-
Building microservices natively within SDK container
-
Building microservices and framework from sources
redpesk batz-2.2-update critical vulnerabilities status
This document shows the status of redpesk OS version batz-2.2-update regarding a
list of very critical CVEs. It was last updated on July 6, 2026. If you feel like a
vulnerability is missing from this document please reach out through
our contract form.
Copy Fail (CVE-2026-31431)
This is a kernel vulnerability.
CVE.org page with references to vendors: https://www.cve.org/CVERecord?id=CVE-2026-31431
More details about the vulnerability: https://copy.fail/
| BSP name | Kernel version in BSP | Status | Upgrade to |
|---|---|---|---|
| BeagleBoard BeaglePlay® | 6.6.32-5.redpesk.bsp.beagleplay.rpbatz_2.aarch64 | Vulnerable | 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Ezurio Nitrogen8M | 5.4.110-12.redpesk.bsp.nitrogen.rpbatz_2.aarch64 | Vulnerable | 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Generic aarch64 | 5.14.0-65.baseos.rpbatz.aarch64 | Vulnerable | 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Generic x86 | 5.14.0-65.baseos.rpbatz.aarch64 | Vulnerable | 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| NXP S32G-VNP-RDB2 | 5.15.119-3.redpesk.bsp.s32g2.rpbatz_2.aarch64 | Vulnerable | 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| NXP i.MX 8QuadXPlus MEK | 5.10.72-6.redpesk.bsp.imx8.rpbatz_2.aarch64 | Vulnerable | 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Phytec phyBOARD AM62x | 6.6.32-206.redpesk.bsp.phytec.rpbatz_2.aarch64 | Vulnerable | 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Raspberry Pi 3/CM3 IO/4 | 5.10.110-13.redpesk.bsp.rpi.rpbatz_2.ar1.aarch64 | Vulnerable | 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| Renesas R-Car H3/M3 | 5.10.41-13.redpesk.bsp.renesas.gen3.rpbatz_2.aarch64 | Vulnerable | 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| SolidRun HummingBoard IIoT i.MX8M | 5.15.71-1.redpesk.bsp.hummingboard.iiot.rpbatz_2.aarch64 | Vulnerable | 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| SolidRun HummingBoard Pulse i.MX8M | 5.15.71-3.redpesk.solidrun.hummingboard.bsp_12d603f8.rpbatz_2.ar1.aarch64 | Vulnerable | 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0 |
| SolidRun SolidSense | 5.4.47-26.redpesk.solidrun.edge.gateways.bsp.rpbatz_2.ar1.aarch64 | Not vulnerable | - |