All posts by corbet

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/948010/

Security updates have been issued by Debian (axis, nghttp2, node-babel7, and tomcat9), Fedora (curl and ghostscript), Oracle (bind, kernel-container, mariadb:10.5, and python3.11), Red Hat (.NET 7.0, go-toolset, golang, and go-toolset:rhel8), SUSE (kernel, libcue, libxml2, python-Django, and python-gevent), and Ubuntu (curl, ghostscript, iperf3, libcue, python2.7, quagga, and samba).

[$] The 2023 Image-Based Linux Summit

Post Syndicated from corbet original https://lwn.net/Articles/946526/

Following up from last year’s first Image-Based
Linux Summit
), a second meeting was held in Berlin on September 12th,
2023, the day before All Systems Go!
2023
, at the Microsoft office. The goal of these summits is to find
common ground among stakeholders from various engineering groups around the
topic of image-based Linux distributions, communicate progress, and attempt
to build a strategy to tackle shared problems together. The organizers —
Luca Boccassi, Lennart Poettering, and Christian Brauner — welcomed
participants from the UAPI Group,
which draws developers from a long list of companies with an interest in
this area, and spent the full day discussing a variety of topics. Full
minutes
have been published on the UAPI Group’s web site.

Security updates for Monday

Post Syndicated from corbet original https://lwn.net/Articles/947891/

Security updates have been issued by Debian (batik, poppler, and tomcat9), Fedora (chromium, composer, curl, emacs, ghostscript, libwebp, libXpm, netatalk, nghttp2, python-asgiref, python-django, and webkitgtk), Mageia (curl and libX11), Oracle (bind, busybox, firefox, and kernel), Red Hat (curl, dotnet6.0, dotnet7.0, and nginx), SUSE (chromium, cni, cni-plugins, grub2, netatalk, opensc, opera, and wireshark), and Ubuntu (iperf3).

[$] Recent improvements in GCC diagnostics

Post Syndicated from corbet original https://lwn.net/Articles/946733/

The primary job of a compiler is to translate source code into a binary
form that can be run by a computer. Increasingly, though, developers want
more from their tools, compilers included. Since the compiler must
understand the code it is being asked to translate, it is in a good
position to provide information about how that code will execute — and
where things might go wrong. At the 2023 GNU Tools Cauldron,
David Malcolm talked about recent work to improve the diagnostic output
from the GCC compiler.

OpenWrt 23.05.0 released

Post Syndicated from corbet original https://lwn.net/Articles/947727/

Version
23.05.0
of the OpenWrt distribution has been released: “OpenWrt
23.05 supports over 1790 devices. Support for over 200 new devices was
added in addition to the device support by OpenWrt 22.03
“. Along with
new device support, this release features a switch to the mbedtls
cryptographic library, the ability to include utilities written in Rust, an
updated toolchain, and more.

Security updates for Friday

Post Syndicated from corbet original https://lwn.net/Articles/947710/

Security updates have been issued by Debian (chromium, tomcat9, and webkit2gtk), Fedora (cacti, cacti-spine, grafana-pcp, libcue, mbedtls, samba, and vim), Oracle (kernel, libvpx, and thunderbird), Red Hat (bind and galera, mariadb), SUSE (exiv2, go1.20, go1.21, and kernel), and Ubuntu (ffmpeg).

Civil Infrastructure Platform to maintain 6.1 for 10 years

Post Syndicated from corbet original https://lwn.net/Articles/947606/

The Civil Infrastructure Platform project has announced
that it will be maintaining the 6.1 kernel for a minimum of ten years past
its initial release (and, thus, through 2032).

CIP kernels are maintained like regular long-term-stable (LTS)
kernels, and developers of the CIP kernel are also involved in LTS
kernel review and testing. While regular LTS kernels are moving
back to 2 years maintenance, CIP kernels are set up for 10
years. In order to enable this extended lifetime, CIP kernels are
scoped-down in actively supported kernel features and target
architecture. At the same time, CIP kernels accept non-invasive
backports from newer mainline kernels that enable new hardware.

[$] Finer-grained BPF tokens

Post Syndicated from corbet original https://lwn.net/Articles/947173/

Programs running in the BPF machine can, depending on how they are
attached, perform a number of privileged operations; the ability to load
and run those programs, thus, must be a privileged operation in its own
right. Almost since the beginning of the extended-BPF era, developers have
struggled to find a way to allow users to run the programs they need
without giving away more privilege than is necessary. Earlier this year,
the idea of a BPF token ran into some
opposition from security-oriented developers. Andrii Nakryiko has since
returned with an
updated patch set
that significantly increases the granularity of the
privileges that can be conferred with a BPF token.

Security updates for Thursday

Post Syndicated from corbet original https://lwn.net/Articles/947570/

Security updates have been issued by Debian (libcue, org-mode, python3.7, and samba), Fedora (libcue, oneVPL, oneVPL-intel-gpu, and xen), Mageia (glibc), Oracle (glibc, kernel, libssh2, libvpx, nodejs, and python-reportlab), Slackware (libcaca), SUSE (gsl, ImageMagick, kernel, opensc, python-urllib3, qemu, rage-encryption, samba, and xen), and Ubuntu (curl and samba).

Security updates for Wednesday

Post Syndicated from corbet original https://lwn.net/Articles/947409/

Security updates have been issued by Debian (curl, mediawiki, tomcat10, and tomcat9), Fedora (libcaca, oneVPL, oneVPL-intel-gpu, and tracker-miners), Gentoo (curl), Mageia (cups and firefox, thunderbird), Red Hat (curl, kernel, kernel-rt, kpatch-patch, libqb, libssh2, linux-firmware, python-reportlab, tar, and the virt:rhel module), Slackware (curl, libcue, libnotify, nghttp2, and samba), SUSE (conmon, curl, glibc, kernel, php-composer2, python-reportlab, samba, and shadow), and Ubuntu (curl, dotnet6, dotnet7, firefox, libx11, samba, tiff, and webkit2gtk).

A remote code execution vulnerability in GNOME

Post Syndicated from corbet original https://lwn.net/Articles/947236/

The GitHub blog describes
a vulnerability in the libcue library
(which is used by the GNOME
desktop) that can be exploited by a remote attacker to run code on a
desktop system if the target can be convinced to click on a malicious link.

The video shows me clicking a link in a webpage, which causes a cue
sheet to be downloaded. Because the file is saved to ~/Downloads,
it is then automatically scanned by tracker-miners. And because it
has a .cue filename extension, tracker-miners uses libcue to parse
the file. The file exploits the vulnerability in libcue to gain
code execution and pop a calculator.

Security updates for Tuesday

Post Syndicated from corbet original https://lwn.net/Articles/947233/

Security updates have been issued by Fedora (chromium, firefox, and kernel), Gentoo (less and libcue), Red Hat (bind, libvpx, nodejs, and python3), Scientific Linux (firefox and thunderbird), SUSE (conmon, go1.20, go1.21, shadow, and thunderbird), and Ubuntu (libcue, ring, and ruby-kramdown).

[$] Rethinking multi-grain timestamps

Post Syndicated from corbet original https://lwn.net/Articles/946394/

One of the significant features added to the mainline kernel during the 6.6
merge window was multi-grain timestamps, which allow the kernel to
selectively store file modification times with higher resolution without
hurting performance. Unfortunately, this feature also caused some
surprising regressions, and was quickly ushered back out of the kernel as a
result. It is instructive to look at how this feature went wrong, and how
the developers involved plan to move forward from here.