All posts by jzb

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1071700/

Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), Mageia (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, perl-Net-CIDR-Lite, perl-Starlet, perl-Starman, tcpflow, and virtualbox), Oracle (dovecot, fence-agents, freeipmi, image-builder, kernel, libcap, LibRaw, libsoup, openssh, osbuild-composer, python, python-tornado, python3, systemd, thunderbird, and tigervnc), SUSE (containerd, curl, erlang, flatpak, java-11-openjdk, java-21-openjdk, java-25-openjdk, liblxc-devel, libpng12, libthrift-0_23_0, openCryptoki, openexr, openssl-3, python3, python311-social-auth-core, rclone, skim, and thunderbird), and Ubuntu (apache2, coin3, editorconfig-core, insighttoolkit, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17, linux-hwe-6.17, linux-oracle, linux-realtime, linux-realtime-6.17, linux-azure, linux-azure-6.17, linux-oem-6.17, linux-azure-5.15, linux-gcp-6.8, nghttp2, python-dynaconf, slurm-wlm, swish-e, and webkit2gtk).

[$] LLM-driven security reports disrupt coordinated disclosure

Post Syndicated from jzb original https://lwn.net/Articles/1070698/

Predictions that LLM tools would cause a surge in reports of security vulnerabilities
have, unquestionably, borne out. As expected, maintainers are having to wade
through more security reports than ever before; in addition, LLM tools are
disrupting traditional-coordinated disclosure practices as well. The method of Copy Fail‘s disclosure, in particular, left
vendors, projects, and users scrambling. In addition, maintainers are seeing
parallel discovery of the same security flaws within the embargo window. Both
of these developments mean that coordinated security disclosures may become a
thing of the past.

Incus 7.0 LTS released

Post Syndicated from jzb original https://lwn.net/Articles/1071469/

Version
7.0
of the Incus container and
virtual-machine management system has been released. Notable changes in this
release include the inclusion of a low-level backup API, the addition
of basic S3 operations
directly in Incus to replace the now-unmaintained
MinIO project, as well as the removal of support for
cgroups v1 and xtables (iptables/ip6tables/ebtables). This is a
long-term-support (LTS) release, with support through June 2031.

The first 2 years will feature bug and security fixes as well as minor
usability improvements, delivered through occasional point releases
(7.0.x). After that initial two years, Incus 7.0 LTS will move to security only
maintenance for the remaining of its 5 years of support.

A total of 204 individuals contributed to Incus between the 6.0 LTS and 7.0
LTS releases with 45 contributing between the 6.23 and 7.0 LTS releases.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1071466/

Security updates have been issued by AlmaLinux (corosync, dovecot, image-builder, python-tornado, resource-agents, and systemd), Debian (openjdk-11, openjdk-17, and pyjwt), Fedora (pdns, pyOpenSSL, and squid), Slackware (hunspell), SUSE (alloy, avahi, bubblewrap, cmctl, coredns, curl, dpkg, firefox, golang-github-prometheus-prometheus, grafana, libpng12, PackageKit, sed, and xen), and Ubuntu (docker.io-app, nghttp2, python-django, and python-mako).

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1071324/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libcap, LibRaw, openssh, thunderbird, and tigervnc), Debian (libarchive and lxd), Fedora (chromium, insight, nodejs20, rust-sequoia-git, and uriparser), Mageia (kernel, kmod-virtualbox), Oracle (kernel, libcap, thunderbird, and uek-kernel), Red Hat (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, sudo, and systemd), Slackware (httpd), SUSE (freerdp, hauler, helm, himmelblau, kernel, libspectre, thunderbird, trivy, and xen), and Ubuntu (curl, exim4, and sed).

[$] Bug-monitoring expectations and Fedora GNOME packages

Post Syndicated from jzb original https://lwn.net/Articles/1070006/

For a number of years, users submitting bugs reports against GNOME packages in Fedora have
received an auto-reply saying that the reports were not actively
monitored; users were encouraged to file bugs with GNOME upstream instead. However,
that practice seems to be in conflict with the Fedora Engineering Steering
Committee
(FESCo) policy
that package maintainers “deal with reported bugs in a timely manner“. On
April 28, FESCo discussed the disconnect between practice and policy; so far,
it has only opted to tweak the wording of the automatic response.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1071167/

Security updates have been issued by AlmaLinux (kernel, libcap, libtiff, sudo, and thunderbird), Debian (dovecot, imagemagick, incus, kernel, libexif, linux-6.1, openjdk-25, pyasn1, python-aiohttp, and thunderbird), Fedora (chromium, firefox, GitPython, glibc, insight, krb5, nano, nss, openssh, openvpn, perl-CryptX, python3.14, rust-openssl, rust-openssl-sys, rust-sequoia-git, and xen), Oracle (dtrace, fence-agents, grafana-pcp, libcap, libtiff, sudo, and xorg-x11-server-Xwayland), Red Hat (buildah, fence-agents, firefox, java-11-openjdk with Extended Lifecycle Support, LibRaw, nodejs24, nodejs:24, openssh, python-pyasn1, resource-agents, thunderbird, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), Slackware (mozilla), and SUSE (avahi, curl, freeipmi, freerdp, google-guest-agent, google-osconfig-agent, gvim, helm, himmelblau, java-1_8_0-openjdk, kernel, krb5-appl-clients, libsodium, libssh, libtiff-devel-32bit, ntfs-3g_ntfsprogs, openCryptoki, openexr, ovmf, PackageKit, python-jwcrypto, python-Mako, python-PyNaCl, python311, python311-pypdf, sed, trivy, and vim).

Eden: NHS goes to war against open source

Post Syndicated from jzb original https://lwn.net/Articles/1070864/

Terence Eden reports
that the UK’s National
Health Service
(NHS) is preparing to close almost all of its open-source repositories as a
response to LLM tools, such as Anthropic’s Mythos, becoming more
sophisticated at finding security vulnerabilities. He does not, to put
it mildly, agree with the decision:

The majority of code repos
published by the NHS
are not meaningfully affected by any advance
in security scanning. They’re mostly data sets, internal tools,
guidance, research tools, front-end design and the like. There is
nothing in them which could realistically lead to a security
incident.

When I was working at NHSX during the pandemic, we were so
confident of the safety and necessity of open source, we made sure the
Covid Contact Tracing app was open sourced the minute it was available
to the public
. That was a nationally mandated app, installed on
millions of phones, subject to intense scrutiny from hostile powers –
and yet, despite publishing the code, architecture and documentation,
the open source code caused zero security
incidents.

Furthermore, this new guidance is in direct contradiction to the
UK’s Tech
Code of Practice point 3 “Be open and use open source”
which
insists on code being open.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1070848/

Security updates have been issued by AlmaLinux (fence-agents), Debian (chromium, dovecot, and kernel), Fedora (chromium, dotnet10.0, dotnet8.0, dotnet9.0, emacs, glow, jfrog-cli, openbao, pyp2spec, python3.6, rust-rustls-webpki, vhs, and xen), Oracle (grafana, grafana-pcp, PackageKit, sudo, vim, and xorg-x11-server), Red Hat (rhc), SUSE (avahi, bouncycastle, chromium, container-suseconnect, firewalld, gdk-pixbuf, grafana, java-25-openjdk, kernel, libixml11, libmozjs-140-0, libpng12-0, libsodium, libssh, mariadb, Mesa, ntfs-3g_ntfsprogs, openCryptoki, openexr, packagekit, prometheus-postgres_exporter, python-jwcrypto, python-mako, python-Pygments, python-pynacl, python311, python311-pyOpenSSL, python315, radare2, sed, and vim), and Ubuntu (kmod and zulucrypt).

GCC 16.1 released

Post Syndicated from jzb original https://lwn.net/Articles/1070649/

Version
16.1
of the GNU Compiler Collection (GCC) has been
released.

The C++ frontend now defaults to the GNU C++20 dialect and the corresponding
parts of the standard library are no longer experimental. Several
C++26 features receive experimental support, including Reflection
(-freflection), Contracts, expansion statements and std::simd.

Other changes include the introduction of an experimental compiler
frontend for the Algol68 language,
ability to output GCC diagnostics in HTML form, and more.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1070640/

Security updates have been issued by AlmaLinux (buildah, firefox, gdk-pixbuf2, giflib, grafana, java-1.8.0-openjdk, java-21-openjdk, LibRaw, OpenEXR, PackageKit, pcs, python3.11, python3.12, python3.9, sudo, tigervnc, vim, xorg-x11-server, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Debian (calibre, firefox-esr, and openjdk-17), Fedora (asterisk, binaryen, buildah, dokuwiki, lemonldap-ng, libexif, libgcrypt, miniupnpd, openvpn, podman, python3.9, rust-rpm-sequoia, skopeo, and xdg-dbus-proxy), Red Hat (buildah, gdk-pixbuf2, and nodejs:20), SUSE (dnsdist, libheif, openCryptoki, polkit, sed, and xen), and Ubuntu (linux-bluefield, python-marshmallow, and roundcube).

Security review of Plasma Login Manager (SUSE Security Team Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1070434/

SUSE’s Security Team has published a detailed
blog post
on their recent review of the Plasma
Login Manager
version 6.6.2,
which was forked from the SDDM display
manager
.

While most of the code remains the
same
, the new upstream added a privileged
D-Bus helper
called
plasmaloginauthhelper, which suffers from defense-in-depth
security issues
.

[…] Based on the high severity of the defense-in-depth issues
shown in this report, our assessment is that there is effectively no
separation between root and the plasmalogin service user account.

At this time there is no bugfix available by upstream, but a
security fix is planned for the next Plasma release on May 12. We have
not been involved in upstream’s bugfix process so far and have no
knowledge about the approach that will be taken to address the issues
from this report.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1070428/

Security updates have been issued by AlmaLinux (firefox, gdk-pixbuf2, java-17-openjdk, libxml2, python3, python3.11, python3.12, sudo, and webkit2gtk3), Debian (dnsdist, node-tar, pdns, pdns-recursor, and policykit-1), Fedora (chromium, edk2, and vim), Oracle (firefox, gdk-pixbuf2, go-toolset:rhel8, libpng12, LibRaw, libxml2, python, python3, python3.11, python3.12, python3.12-wheel, vim, webkit2gtk3, xorg-x11-server, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, delve, git-lfs, go-rpm-macros, grafana, grafana-pcp, osbuild-composer, and rhc), SUSE (bouncycastle, clamav, container-suseconnect, dovecot22, erlang, firefox, fontforge, freerdp2, ghostscript, giflib, gnome-remote-desktop, go1.25, go1.26, google-guest-agent, haproxy, ignition, ImageMagick, kernel, libcap, libpng16, libraw, librsvg, mariadb, openexr, pocketbase, protobuf, python-Pillow, python-requests, qemu, rust1.94, sudo, tomcat, tomcat10, tomcat11, webkit2gtk3, and xen), and Ubuntu (dotnet10, dovecot, linux-nvidia-lowlatency, node-follow-redirects, openssh, packagekit, python-cryptography, python-tornado, ruby-rack-session, ujson, and wheel).

Remembering Seth Nickell

Post Syndicated from jzb original https://lwn.net/Articles/1070213/

LWN has received the sad news that Seth Nickell passed away, on
April 16, from his father, Eric Nickell:

Many of you knew Seth from his work in the GNOME Usability Project, but his
roots in that community trace back to his high school years. As a father of
a high school junior, I remember being terrified when he flashed the hard
drive of a computer he purchased for himself with this weird “Linux” thing.
And I was a bit awed by the college application essay he wrote about open
source and Linus Torvalds.

It was his interest in packet radio that drew him into working with
the Linux AX.25 HOWTO
as a high schooler, and from there to his focus on making the Linux
desktop work for everyone.

The family plans to share news of a memorial at a later time. He
will be deeply missed.

Fedora Linux 44 has been released

Post Syndicated from jzb original https://lwn.net/Articles/1070198/

The Fedora Project has announced
the release of Fedora Linux 44. There are “what’s new”
articles for Fedora
Workstation
, Fedora
KDE Plasma Desktop
, and Fedora
Atomic Desktops
. The Fedora Asahi Remix for Apple Silicon Macs,
based on Fedora 44, is also
available
. See the Fedora Spins page for a full list of alternative desktop options.

Fedora Linux 44 Workstation ships with the latest GNOME release,
GNOME 50. This comes with a long list of refinements to your desktop,
including everything from accessibility to color management and remote
desktop. Many of the applications that are installed by default on
Fedora Workstation have also seen improvements, from Document Viewer
to File Manager and Calendar. To learn more about these and other
changes, you can read the GNOME 50 release notes.

KDE Plasma Desktop: If you are a KDE user, you should also notice a
couple of very obvious changes. Fedora KDE Plasma Desktop 44 is based
on the latest Plasma 6.6, which includes the new Plasma Login Manager
and Plasma Setup to provide a more cohesive and integrated experience
from the moment the computer is powered on for the first time. The
installation process has been simplified, enabling you to easily set
up Fedora KDE Plasma Desktop for a computer for a friend or a loved
one.

The release
notes
include important changes between Fedora 43 and
Fedora 44 for desktop users, developers, and system administrators.

[$] Strawberry is ripe for managing music collections

Post Syndicated from jzb original https://lwn.net/Articles/1069368/

There are dozens of music-player applications for Linux; the options range
from bare-bones programs that only play local files to full-blown
music-management projects with a full suite of tools for managing (and playing)
a music collection. Strawberry
is in the latter category; it has a bumper crop of features, including smart
playlists, support for editing music metadata tags, the ability to organize music
files, and more.

In Memoriam: Tomáš Kalibera

Post Syndicated from jzb original https://lwn.net/Articles/1070185/

We have received the sad news that Tomáš Kalibera, a member of the
R Project core team, has
passed away
after a short illness
.

A friend who knew him well wrote to me: he was very happy, and
his work fulfilled him
. That is, perhaps, the best thing one can
say about a life in open source — that the work mattered, that it
reached millions, and that the person who did it found meaning in it.

Kalibera was mentioned in this 2019 article about C
programs passing strings to Fortran subroutines. He will be greatly
missed.