All posts by jzb

[$] The tenth OpenPGP email summit

Post Syndicated from jzb original https://lwn.net/Articles/1072870/

The OpenPGP Email Summit is
an annual meeting for those who work on encrypted email and related
topics. The tenth
installment
of this meeting took place in March 2026 and the minutes
have now been published. As usual, a wide range of topics were
discussed. Highlights included support for post-quantum cryptography
(PQC) with multiple actors planning rollouts within this year, a
promising new approach for making email signatures ubiquitous with the
plan of making OpenPGP signed email a default, a new draft that brings
reliable deletion (or “forward secrecy”) features to OpenPGP, as well
as a plan for transferring ownership of the OpenPGP.org domain.

[$] openSUSE “terms of site” raise complaints about age restrictions

Post Syndicated from jzb original https://lwn.net/Articles/1072689/

Many people in the Linux community began using the operating system—and
contributing to open source—at a tender age, often well before
their 16th birthday. Thus, a recent change in openSUSE’s terms of site (ToS)
that required users of the project’s web site to be “at least 16
years of age or the age of majority
” in their jurisdiction has
raised objections. The terms have since been modified, though users
must still have parental approval to create accounts if they are
younger than 16.

pgBackRest will continue

Post Syndicated from jzb original https://lwn.net/Articles/1073470/

In April, David Steele, maintainer of the popular pgBackRest backup and restore project for
PostgreSQL, announced that he had archived
the project
and it would no longer be maintained due to lack of
sponsorship. On May 18, he announced
that a number of sponsors have stepped forward to ensure its continued
development:

Over the last few weeks, a coalition of sponsors has come together
to fund ongoing development. Their support means the project is no
longer reliant on a single sponsor, giving pgBackRest the stability it
needs for the long term.

[…] I’m looking forward to getting back to work. There are
features and optimizations in the pipeline that I’m excited to share
in upcoming releases. Thank you to our sponsors for making this
possible, and thank you to the community for your patience and support
during this transition.

Thanks to Paul Wise for the tip.

Seven new stable kernels with patches for CVE-2026-46333

Post Syndicated from jzb original https://lwn.net/Articles/1073060/

Greg Kroah-Hartman has announced the 7.0.8, 6.18.31, 6.12.89, 6.6.139, 6.1.173, 5.15.207, and 5.10.256 stable kernels. These kernels
contain a patch for CVE-2026-46333
a vulnerability reported
by the Qualys Security Advisory team
, though Jann Horn proposed
a patch
in 2020. The vulnerability has a proof-of-concept
exploit
published already. Some of the kernels have additional
patches for other bugs; as always, users are advised to upgrade.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1073059/

Security updates have been issued by Debian (ffmpeg, gsasl, nodejs, postgresql-15, postgresql-17, python3.9, and thunderbird), Fedora (expat, firefox, freerdp, GitPython, kernel, php, rust-podman-sequoia, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-sop, rust-sequoia-sq, and rust-sequoia-sqv), Mageia (awstats, libreoffice, perl-HTTP-Tiny, and tomcat), Oracle (corosync, freerdp, gimp, git-lfs, glib2, jq, kernel, krb5, libsoup3, libtiff, openexr, thunderbird, uek-kernel, and yggdrasil), Red Hat (podman and skopeo), SUSE (amazon-ssm-agent, avahi, c-ares, cairo, containerd, cpp-httplib, dnsmasq, dovecot24, ffmpeg-4, firefox, helm, ImageMagick, iproute2, kernel, krb5, libtpms, ongres-scram, ongres-stringprep, plexus-testing, maven, maven-doxia, mojo-parent, sisu, openCryptoki, openssh, perl-Text-CSV_XS, php8, python-lxml, python-Twisted-doc, python311-click, python311-GitPython, rclone, regclient, and syncthing), and Ubuntu (avahi).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1072838/

Security updates have been issued by AlmaLinux (gimp, jq, and yggdrasil), Debian (nghttp2 and thunderbird), Fedora (chromium, firefox, freerdp, GitPython, kernel, kernel-headers, krb5, nano, nix, nodejs20, php, python-click, python-django5, SDL2_image, and xen), Mageia (dnsmasq, flatpak, kernel, kmod-virtualbox, kernel-linus, perl-Net-CIDR-Lite, perl-XML-LibXML, and redis), SUSE (dnsmasq, firefox, jupyter-jupyterlab, kernel, krb5, libvinylapi3, log4j, Mesa, mozjs60, NetworkManager, OpenImageIO, python-Mako, python-Pillow, and python39), and Ubuntu (dnsmasq and nginx).

[$] Friction in Fedora over AI developer desktop initiative

Post Syndicated from jzb original https://lwn.net/Articles/1071949/

A push by Red Hat employees to create a Fedora “AI Developer
Desktop” with support for out-of-tree kernel drivers and AI toolkits
has been met with objections from some long-time members of the Fedora
community. After more than a month of sometimes heated discussion, the
Fedora
Council
had voted
to approve the initiative; however, a last-minute change to vote against the
proposal by council member Justin Wheeler has (at least temporarily)
sent it back to the drawing board.

Yet another Dirty Frag type vulnerability: Fragnesia

Post Syndicated from jzb original https://lwn.net/Articles/1072647/

Sam James has sent an announcement
to the OSS Security mailing list about another
local-privilege-escalation (LPE) exploit in the same class as Dirty Frag, called
“Fragnesia”. From the disclosure:

This is a separate bug in the ESP/XFRM from dirtyfrag which has received its own patch. However, it is in the same surface and the mitigation is the same as for dirtyfrag.

It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to
achieve arbitrary byte writes into the kernel page cache of read-only
files, without requiring any race condition.

James noted that there is a patch
in the works, but it has not yet been pulled into Linus Torvalds’s
tree nor into any of the stable kernels. A proof
of concept exploit
is also available.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1072596/

Security updates have been issued by AlmaLinux (corosync, freerdp, git-lfs, glib2, jq, kernel-rt, krb5, libpng, libtiff, openexr, and thunderbird), Debian (exim4), Mageia (apache, perl-Gazelle, php, and sed), Slackware (expat), SUSE (assimp-devel, go1.26, libQt6Svg6, python-jupyterlab, raylib, thunderbird, tor, and trivy), and Ubuntu (exim4).

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1072498/

Security updates have been issued by AlmaLinux (freerdp, glib2, libsoup3, and openexr), Debian (dnsmasq, p7zip, p7zip-rar, python-authlib, and rails), Fedora (chromium, firefox, httpd, and nss), SUSE (java-25-openj9, krb5, libmodsecurity3, and mcphost), and Ubuntu (imagemagick, linux, linux-aws, linux-aws-fips, linux-aws-hwe, linux-azure-4.15, linux-fips, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-hwe, linux-kvm, linux-oracle, linux-azure, linux-azure-fips, linux-oracle, linux-azure-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and linux-raspi).

Stenberg: Mythos finds a curl vulnerability

Post Syndicated from jzb original https://lwn.net/Articles/1072325/

Daniel Stenberg has published a lengthy
article
on his thoughts on Anthropic’s Mythos, which the company
decided was too dangerous for wide public release.

My personal conclusion can however not end up with anything else
than that the big hype around this model so far was primarily
marketing. I see no evidence that this setup finds issues to any
particular higher or more advanced degree than the other tools have
done before Mythos. Maybe this model is a little bit better, but even
if it is, it is not better to a degree that seems to make a
significant dent in code analyzing.

This is just one source code repository and maybe it is much better
on other things. I can only tell and comment on what it found
here.

But allow me to highlight and reiterate what I have said before: AI
powered code analyzers are significantly better at finding security
flaws and mistakes in source code than any traditional code analyzers
did in the past. All modern AI models are good at this now. Anyone
with time and some experimental spirits can find security problems
now. The high
quality chaos
is real.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1072301/

Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), Mageia (firefox, nss, rootcerts, openvpn, thunderbird, and vim), Oracle (corosync, freeipmi, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, libpng, and mingw-libtiff), Slackware (kernel and mozilla), SUSE (build, product-composer, c-ares, cairo, copacetic, distribution, firefox, firefox-esr, frr, glibc, go1.25, google-cloud-sap-agent, iproute2, java-11-openj9, java-17-openj9, java-17-openjdk, java-1_8_0-openj9, java-21-openj9, java-21-openjdk, java-25-openjdk, kernel, libexif-devel, libpcp-devel, libtpms, libtree-sitter0_26, Mesa, micropython, mozjs128, nginx, opencc, openCryptoki, php-composer2, podman, postfix, python-pytest, python311-Django, python311-Django4, redis, semaphore, strongswan, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, tor, valkey, vim, and wireshark), and Ubuntu (linux-nvidia-tegra, linux-raspi, linux-raspi-5.4, and nasm).

More stable kernels with partial Dirty Frag fixes

Post Syndicated from jzb original https://lwn.net/Articles/1071483/

Greg Kroah-Hartman has released the 6.1.171, 5.15.205, and 5.10.255 stable kernels, quickly
followed by 6.1.172 and 5.15.206 kernels. This is another round
of stable kernels to provide fixes for one of the CVEs (CVE-2026-43284)
assigned following the Dirty
Frag
and Copy Fail 2
security disclosures. There is not, yet, a stable kernel with a fix
for CVE-2026-43500,
though a
patch
to fix the second half is in the works.

[$] Forgejo “carrot disclosure” raises security questions

Post Syndicated from jzb original https://lwn.net/Articles/1071499/

An unusual, some might say hostile, approach to disclosing an alleged
remote-code-execution (RCE) flaw in the Forgejo software-collaboration platform has
sparked a multifaceted conversation. A so-called
“carrot disclosure” in April has raised questions about the
researcher’s methods of unveiling a security problem, Forgejo’s
security policies, and the project’s overall security posture.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1071859/

Security updates have been issued by AlmaLinux (libsoup and mingw-libtiff), Debian (apache2, chromium, lcms2, libreoffice, and prosody), Fedora (openssl and perl-Starman), Oracle (git-lfs, libsoup, and perl-XML-Parser), Slackware (libgpg, mozilla, and php), SUSE (389-ds, cairo, cf-cli, chromedriver, cri-tools, freeipmi, gnutls, grafana, java-11-openjdk, java-17-openjdk, jetty-minimal, libmariadbd-devel, librsvg, mesa, mozjs52, mutt, nix, opencryptoki, python-Django, python-django, python-pytest, rmt-server, thunderbird, traefik, webkit2gtk3, wireshark, and xen), and Ubuntu (civicrm, dpkg, htmlunit, lcms2, libpng1.6, linux, linux-*, linux-azure, linux-azure-fips, linux-raspi, linux-xilinx, lua5.1, nasm, opam, openexr, openjpeg2, owslib, postfix, postfixadmin, and vim).

Dirty Frag: a zero-day universal Linux LPE

Post Syndicated from jzb original https://lwn.net/Articles/1071719/

Hyunwoo Kim has announced
the Dirty
Frag
security flaw, a
local-privilege-escalation (LPE) vulnerability similar to the
recently disclosed Copy Fail
flaw:

Because the embargo has now been broken, no patches or CVEs exist for
these vulnerabilities. After consultation with the [email protected]
maintainers, and at the maintainers’ request, I am publicly releasing this
Dirty Frag document.

As with the previous Copy Fail vulnerability, Dirty Frag likewise allows
immediate root privilege escalation on all major distributions.

Kim, who discovered the flaw and had attempted a coordinated
disclosure set for May 12, has released the code for an exploit, as well as a example
script to remove the vulnerable modules. A full
write-up
, with the disclosure timeline, is also available. It’s
unknown at this time whether this is an example of parallel discovery
or how the third party was able to disclose it prior to the end of the
embargo. We will be following up as more information comes to light.

An update on KDE’s Union style engine

Post Syndicated from jzb original https://lwn.net/Articles/1071703/

Arjen Hiemstra has published
an article on the status of the Union project: a
single system to support all of KDE’s technologies used for styling
applications.

The work on Union’s Breeze implementation has progressed to the
point where it is very hard to distinguish whether or not you are
running the Union version. We have also tested with a bunch of
applications and made sure that any differences were fixed. So we are
at a stage where we need to get Union into the hands of more people,
both to get extra people testing whether there are any major issues,
but also to have interested people creating new styles.

This means that with the upcoming Plasma 6.7 release, we plan to
include Union. Discussion is currently ongoing whether we will enable
it by default, but even if not there will be a way to try it out.

See Hiemstra’s introductory
article on Union
, published in February 2025, for more about the
project and its creation. KDE 6.7 is expected to be released in mid-June.