All posts by jzb

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1072301/

Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), Mageia (firefox, nss, rootcerts, openvpn, thunderbird, and vim), Oracle (corosync, freeipmi, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, libpng, and mingw-libtiff), Slackware (kernel and mozilla), SUSE (build, product-composer, c-ares, cairo, copacetic, distribution, firefox, firefox-esr, frr, glibc, go1.25, google-cloud-sap-agent, iproute2, java-11-openj9, java-17-openj9, java-17-openjdk, java-1_8_0-openj9, java-21-openj9, java-21-openjdk, java-25-openjdk, kernel, libexif-devel, libpcp-devel, libtpms, libtree-sitter0_26, Mesa, micropython, mozjs128, nginx, opencc, openCryptoki, php-composer2, podman, postfix, python-pytest, python311-Django, python311-Django4, redis, semaphore, strongswan, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, tor, valkey, vim, and wireshark), and Ubuntu (linux-nvidia-tegra, linux-raspi, linux-raspi-5.4, and nasm).

More stable kernels with partial Dirty Frag fixes

Post Syndicated from jzb original https://lwn.net/Articles/1071483/

Greg Kroah-Hartman has released the 6.1.171, 5.15.205, and 5.10.255 stable kernels, quickly
followed by 6.1.172 and 5.15.206 kernels. This is another round
of stable kernels to provide fixes for one of the CVEs (CVE-2026-43284)
assigned following the Dirty
Frag
and Copy Fail 2
security disclosures. There is not, yet, a stable kernel with a fix
for CVE-2026-43500,
though a
patch
to fix the second half is in the works.

[$] Forgejo “carrot disclosure” raises security questions

Post Syndicated from jzb original https://lwn.net/Articles/1071499/

An unusual, some might say hostile, approach to disclosing an alleged
remote-code-execution (RCE) flaw in the Forgejo software-collaboration platform has
sparked a multifaceted conversation. A so-called
carrot disclosure” in April has raised questions about the
researcher’s methods of unveiling a security problem, Forgejo’s
security policies, and the project’s overall security posture.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1071859/

Security updates have been issued by AlmaLinux (libsoup and mingw-libtiff), Debian (apache2, chromium, lcms2, libreoffice, and prosody), Fedora (openssl and perl-Starman), Oracle (git-lfs, libsoup, and perl-XML-Parser), Slackware (libgpg, mozilla, and php), SUSE (389-ds, cairo, cf-cli, chromedriver, cri-tools, freeipmi, gnutls, grafana, java-11-openjdk, java-17-openjdk, jetty-minimal, libmariadbd-devel, librsvg, mesa, mozjs52, mutt, nix, opencryptoki, python-Django, python-django, python-pytest, rmt-server, thunderbird, traefik, webkit2gtk3, wireshark, and xen), and Ubuntu (civicrm, dpkg, htmlunit, lcms2, libpng1.6, linux, linux-*, linux-azure, linux-azure-fips, linux-raspi, linux-xilinx, lua5.1, nasm, opam, openexr, openjpeg2, owslib, postfix, postfixadmin, and vim).

Dirty Frag: a zero-day universal Linux LPE

Post Syndicated from jzb original https://lwn.net/Articles/1071719/

Hyunwoo Kim has announced
the Dirty
Frag
security flaw, a
local-privilege-escalation (LPE) vulnerability similar to the
recently disclosed Copy Fail
flaw:

Because the embargo has now been broken, no patches or CVEs exist for
these vulnerabilities. After consultation with the [email protected]
maintainers, and at the maintainers’ request, I am publicly releasing this
Dirty Frag document.

As with the previous Copy Fail vulnerability, Dirty Frag likewise allows
immediate root privilege escalation on all major distributions.

Kim, who discovered the flaw and had attempted a coordinated
disclosure set for May 12, has released the code for an exploit, as well as a example
script to remove the vulnerable modules. A full
write-up
, with the disclosure timeline, is also available. It’s
unknown at this time whether this is an example of parallel discovery
or how the third party was able to disclose it prior to the end of the
embargo. We will be following up as more information comes to light.

An update on KDE’s Union style engine

Post Syndicated from jzb original https://lwn.net/Articles/1071703/

Arjen Hiemstra has published
an article on the status of the Union project: a
single system to support all of KDE’s technologies used for styling
applications.

The work on Union’s Breeze implementation has progressed to the
point where it is very hard to distinguish whether or not you are
running the Union version. We have also tested with a bunch of
applications and made sure that any differences were fixed. So we are
at a stage where we need to get Union into the hands of more people,
both to get extra people testing whether there are any major issues,
but also to have interested people creating new styles.

This means that with the upcoming Plasma 6.7 release, we plan to
include Union. Discussion is currently ongoing whether we will enable
it by default, but even if not there will be a way to try it out.

See Hiemstra’s introductory
article on Union
, published in February 2025, for more about the
project and its creation. KDE 6.7 is expected to be released in mid-June.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1071700/

Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), Mageia (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, perl-Net-CIDR-Lite, perl-Starlet, perl-Starman, tcpflow, and virtualbox), Oracle (dovecot, fence-agents, freeipmi, image-builder, kernel, libcap, LibRaw, libsoup, openssh, osbuild-composer, python, python-tornado, python3, systemd, thunderbird, and tigervnc), SUSE (containerd, curl, erlang, flatpak, java-11-openjdk, java-21-openjdk, java-25-openjdk, liblxc-devel, libpng12, libthrift-0_23_0, openCryptoki, openexr, openssl-3, python3, python311-social-auth-core, rclone, skim, and thunderbird), and Ubuntu (apache2, coin3, editorconfig-core, insighttoolkit, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17, linux-hwe-6.17, linux-oracle, linux-realtime, linux-realtime-6.17, linux-azure, linux-azure-6.17, linux-oem-6.17, linux-azure-5.15, linux-gcp-6.8, nghttp2, python-dynaconf, slurm-wlm, swish-e, and webkit2gtk).

[$] LLM-driven security reports disrupt coordinated disclosure

Post Syndicated from jzb original https://lwn.net/Articles/1070698/

Predictions that LLM tools would cause a surge in reports of security vulnerabilities
have, unquestionably, borne out. As expected, maintainers are having to wade
through more security reports than ever before; in addition, LLM tools are
disrupting traditional-coordinated disclosure practices as well. The method of Copy Fail‘s disclosure, in particular, left
vendors, projects, and users scrambling. In addition, maintainers are seeing
parallel discovery of the same security flaws within the embargo window. Both
of these developments mean that coordinated security disclosures may become a
thing of the past.

Incus 7.0 LTS released

Post Syndicated from jzb original https://lwn.net/Articles/1071469/

Version
7.0
of the Incus container and
virtual-machine management system has been released. Notable changes in this
release include the inclusion of a low-level backup API, the addition
of basic S3 operations
directly in Incus to replace the now-unmaintained
MinIO project, as well as the removal of support for
cgroups v1 and xtables (iptables/ip6tables/ebtables). This is a
long-term-support (LTS) release, with support through June 2031.

The first 2 years will feature bug and security fixes as well as minor
usability improvements, delivered through occasional point releases
(7.0.x). After that initial two years, Incus 7.0 LTS will move to security only
maintenance for the remaining of its 5 years of support.

A total of 204 individuals contributed to Incus between the 6.0 LTS and 7.0
LTS releases with 45 contributing between the 6.23 and 7.0 LTS releases.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1071466/

Security updates have been issued by AlmaLinux (corosync, dovecot, image-builder, python-tornado, resource-agents, and systemd), Debian (openjdk-11, openjdk-17, and pyjwt), Fedora (pdns, pyOpenSSL, and squid), Slackware (hunspell), SUSE (alloy, avahi, bubblewrap, cmctl, coredns, curl, dpkg, firefox, golang-github-prometheus-prometheus, grafana, libpng12, PackageKit, sed, and xen), and Ubuntu (docker.io-app, nghttp2, python-django, and python-mako).

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1071324/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libcap, LibRaw, openssh, thunderbird, and tigervnc), Debian (libarchive and lxd), Fedora (chromium, insight, nodejs20, rust-sequoia-git, and uriparser), Mageia (kernel, kmod-virtualbox), Oracle (kernel, libcap, thunderbird, and uek-kernel), Red Hat (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, sudo, and systemd), Slackware (httpd), SUSE (freerdp, hauler, helm, himmelblau, kernel, libspectre, thunderbird, trivy, and xen), and Ubuntu (curl, exim4, and sed).

[$] Bug-monitoring expectations and Fedora GNOME packages

Post Syndicated from jzb original https://lwn.net/Articles/1070006/

For a number of years, users submitting bugs reports against GNOME packages in Fedora have
received an auto-reply saying that the reports were not actively
monitored; users were encouraged to file bugs with GNOME upstream instead. However,
that practice seems to be in conflict with the Fedora Engineering Steering
Committee
(FESCo) policy
that package maintainers “deal with reported bugs in a timely manner“. On
April 28, FESCo discussed the disconnect between practice and policy; so far,
it has only opted to tweak the wording of the automatic response.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1071167/

Security updates have been issued by AlmaLinux (kernel, libcap, libtiff, sudo, and thunderbird), Debian (dovecot, imagemagick, incus, kernel, libexif, linux-6.1, openjdk-25, pyasn1, python-aiohttp, and thunderbird), Fedora (chromium, firefox, GitPython, glibc, insight, krb5, nano, nss, openssh, openvpn, perl-CryptX, python3.14, rust-openssl, rust-openssl-sys, rust-sequoia-git, and xen), Oracle (dtrace, fence-agents, grafana-pcp, libcap, libtiff, sudo, and xorg-x11-server-Xwayland), Red Hat (buildah, fence-agents, firefox, java-11-openjdk with Extended Lifecycle Support, LibRaw, nodejs24, nodejs:24, openssh, python-pyasn1, resource-agents, thunderbird, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), Slackware (mozilla), and SUSE (avahi, curl, freeipmi, freerdp, google-guest-agent, google-osconfig-agent, gvim, helm, himmelblau, java-1_8_0-openjdk, kernel, krb5-appl-clients, libsodium, libssh, libtiff-devel-32bit, ntfs-3g_ntfsprogs, openCryptoki, openexr, ovmf, PackageKit, python-jwcrypto, python-Mako, python-PyNaCl, python311, python311-pypdf, sed, trivy, and vim).

Eden: NHS goes to war against open source

Post Syndicated from jzb original https://lwn.net/Articles/1070864/

Terence Eden reports
that the UK’s National
Health Service
(NHS) is preparing to close almost all of its open-source repositories as a
response to LLM tools, such as Anthropic’s Mythos, becoming more
sophisticated at finding security vulnerabilities. He does not, to put
it mildly, agree with the decision:

The majority of code repos
published by the NHS
are not meaningfully affected by any advance
in security scanning. They’re mostly data sets, internal tools,
guidance, research tools, front-end design and the like. There is
nothing in them which could realistically lead to a security
incident.

When I was working at NHSX during the pandemic, we were so
confident of the safety and necessity of open source, we made sure the
Covid Contact Tracing app was open sourced the minute it was available
to the public
. That was a nationally mandated app, installed on
millions of phones, subject to intense scrutiny from hostile powers –
and yet, despite publishing the code, architecture and documentation,
the open source code caused zero security
incidents.

Furthermore, this new guidance is in direct contradiction to the
UK’s Tech
Code of Practice point 3 “Be open and use open source”
which
insists on code being open.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1070848/

Security updates have been issued by AlmaLinux (fence-agents), Debian (chromium, dovecot, and kernel), Fedora (chromium, dotnet10.0, dotnet8.0, dotnet9.0, emacs, glow, jfrog-cli, openbao, pyp2spec, python3.6, rust-rustls-webpki, vhs, and xen), Oracle (grafana, grafana-pcp, PackageKit, sudo, vim, and xorg-x11-server), Red Hat (rhc), SUSE (avahi, bouncycastle, chromium, container-suseconnect, firewalld, gdk-pixbuf, grafana, java-25-openjdk, kernel, libixml11, libmozjs-140-0, libpng12-0, libsodium, libssh, mariadb, Mesa, ntfs-3g_ntfsprogs, openCryptoki, openexr, packagekit, prometheus-postgres_exporter, python-jwcrypto, python-mako, python-Pygments, python-pynacl, python311, python311-pyOpenSSL, python315, radare2, sed, and vim), and Ubuntu (kmod and zulucrypt).

GCC 16.1 released

Post Syndicated from jzb original https://lwn.net/Articles/1070649/

Version
16.1
of the GNU Compiler Collection (GCC) has been
released.

The C++ frontend now defaults to the GNU C++20 dialect and the corresponding
parts of the standard library are no longer experimental. Several
C++26 features receive experimental support, including Reflection
(-freflection), Contracts, expansion statements and std::simd.

Other changes include the introduction of an experimental compiler
frontend for the Algol68 language,
ability to output GCC diagnostics in HTML form, and more.