All posts by jzb

OpenSSH 10.3 released

Post Syndicated from jzb original https://lwn.net/Articles/1065991/

OpenSSH 10.3
has been released. Among the many changes in this release are a
security fix to address late validation of metacharacters in user
names, removal of bug compatibility for SSH implementations that do
not support rekeying,
and a fix to ensure that scp clears setuid/setgid bits from downloaded
files when operating as root in legacy (-O) mode. See the
release announcement for a full list of new features, bug fixes, and
potentially incompatible changes.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1066084/

Security updates have been issued by AlmaLinux (python3.11, python3.12, squid, and thunderbird), Debian (gst-plugins-bad1.0 and gst-plugins-ugly1.0), Fedora (bpfman, crun, gnome-remote-desktop, polkit, python3.14, rust-rustls-webpki, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, and scap-security-guide), Oracle (freerdp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, kernel, libxslt, python3.11, python3.12, squid, and thunderbird), SUSE (389-ds, busybox, chromium, cosign, curl, docker-compose, exiv2, expat, firefox, freerdp, freerdp2, gstreamer-plugins-ugly, harfbuzz, heroic-games-launcher, ImageMagick, kea, keylime, libjxl, librsvg, libsodium, libsoup, net-snmp, net-tools, netty, nghttp2, poppler, postgresql13, postgresql16, postgresql17, postgresql18, protobuf, python-black, python-orjson, python-pyasn1, python-pyOpenSSL, python-tornado, python-tornado6, python311-nltk, thunderbird, tomcat10, tomcat11, vim, and xen), and Ubuntu (kernel, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi, linux-raspi, linux-raspi-realtime, rust-cargo-c, rust-tar, and undertow).

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1065814/

Security updates have been issued by AlmaLinux (freerdp, libxslt, python3.11, and python3.12), Debian (libpng1.6, lxd, netty, and python-tornado), Fedora (chunkah, cpp-httplib, firefox, freerdp, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, gstreamer1-vaapi, insight, python-gstreamer1, python3.14, rust, rust-cargo-rpmstatus, rust-cargo-vendor-filterer, rust-resctl-bench, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, and xen), Mageia (freeipmi, python-openssl, python-ply, ruby-rack, vim, and zlib), Oracle (firefox, freerdp, kernel, libpng, thunderbird, uek-kernel, and virt:ol and virt-devel:ol), Red Hat (golang), SUSE (bind, expat, fetchmail, ffmpeg-7, freerdp, gsl, incus, kernel, libjavamapscript, libjxl, libpng16-16, libpolkit-agent-1-0-127, net-snmp, net-tools, openexr, perl-XML-Parser, python-ldap, python-pyasn1, python-PyJWT, python311-requests, tailscale, thunderbird, tinyproxy, and ucode-intel), and Ubuntu (golang-golang-x-net-dev and ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2, ruby3.3).

[$] Objections to systemd age-attestation changes go overboard

Post Syndicated from jzb original https://lwn.net/Articles/1064706/

In early March, Dylan M. Taylor submitted a pull request to add a field
to store a user’s birth date in systemd’s JSON user records. This was done to allow
applications to store the date to facilitate compliance with age-attestation and
-verification laws. It was to be expected that some members of the community would
object; the actual response, however, has been shockingly hostile. Some of this has
been fueled by a misinformation campaign that has targeted the systemd project and
Taylor specifically, resulting in Taylor being doxxed and receiving death
threats. Such behavior is not just problematic; it is also deeply misguided given the
actual nature of the changes.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1065585/

Security updates have been issued by AlmaLinux (firefox, kernel, and kernel-rt), Debian (phpseclib and roundcube), Fedora (bind, bind-dyndb-ldap, dotnet8.0, dotnet9.0, firefox, freerdp, mingw-expat, musescore, nss, ntpd-rs, perl-YAML-Syck, php-phpseclib3, polkit, pyOpenSSL, python3.12, rust, rust-cargo-rpmstatus, rust-cargo-vendor-filterer, stgit, webkitgtk, and xen), SUSE (dovecot24, ImageMagick, jupyter-nbclassic, kernel, libjxl, libsuricata8_0_4, obs-service-recompress, obs-service-tar_scm, obs-service-set_version, openbao, perl-Crypt-URandom, plexus-utils, python-pyasn1, python-PyJWT, strongswan, traefik, traefik2, and webkit2gtk3), and Ubuntu (gst-plugins-base1.0, gst-plugins-good1.0, imagemagick, pillow, pyasn1, pyjwt, and roundcube).

SystemRescue 13.00 released

Post Syndicated from jzb original https://lwn.net/Articles/1065480/

SystemRescue 13.00 has been released. The
SystemRescue distribution is a live boot system-rescue toolkit, based
on Arch Linux, for repairing systems in the event of a crash. This
release includes the 6.18.20 LTS kernel, updates bcachefs tools and
kernel module to 1.37.3, and many
upgraded packages
. See the step-by-step guide for
instructions on performing common operations such as recovering files,
creating disk clones, and resetting lost passwords.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1065419/

Security updates have been issued by AlmaLinux (freerdp, golang, and ncurses), Debian (asterisk, bind9, gst-plugins-base1.0, gst-plugins-ugly1.0, gvfs, incus, libxml-parser-perl, nodejs, php-phpseclib, php-phpseclib3, phpseclib, and strongswan), Fedora (bcftools, bind, bind-dyndb-ldap, chromium, dotnet10.0, dotnet8.0, dotnet9.0, giflib, htslib, libsoup3, libtasn1, maturin, mingw-expat, mingw-freetype, mongo-c-driver, perl-XML-Parser, php-phpseclib, php-phpseclib3, pypy, pypy3.10, pypy3.11, python-cryptography, python-fastar, python-ply, python-pycparser, python-uv-build, python3.11, python3.12, python3.13, python3.6, roundcubemail, rubygem-json, rust-ambient-id, rust-astral-reqwest-middleware, rust-astral-reqwest-retry, rust-astral-tokio-tar, rust-astral_async_http_range_reader, rust-cargo-c, rust-ingredients, rust-native-tls, rust-nix, rust-openssl-probe, rust-openssl-probe0.1, rust-pty-process, rust-reqsign, rust-reqsign-aliyun-oss, rust-reqsign-aws-v4, rust-reqsign-azure-storage, rust-reqsign-command-execute-tokio, rust-reqsign-core, rust-reqsign-file-read-tokio, rust-reqsign-google, rust-reqsign-http-send-reqwest, rust-reqsign-huaweicloud-obs, rust-reqsign-tencent-cos, rust-rustls-native-certs, rust-sequoia-chameleon-gnupg, rust-tar, rust-webpki-root-certs, rustup, samtools, suricata, uv, and vim), Mageia (cmake, libpng, nodejs, python-ujson, and strongswan), Red Hat (python3 and python3.9), SUSE (389-ds, amazon-cloudwatch-agent, capstone, chromium, containerd, cosign, curl, docker-compose, docker-stable, exiv2, expat, firefox, freeipmi, freerdp, gimp, glusterfs, govulncheck-vulndb, gstreamer-plugins-ugly, jupyter-bqplot-jupyterlab, jupyter-jupyterlab-templates, jupyter-matplotlib, kea, kernel, libsodium, libtpms-devel, LibVNCServer, nghttp2, nginx, poppler, python-dynaconf, python-ldap, python-nltk, python-orjson, python-pyasn1, python-pydicom, python-PyJWT, python-pyopenssl, python-tornado6, python311, python311-cbor2, python311-deepdiff, python311-intake, python311-jsonpath-ng, python311-lmdb, python311-oci-sdk, python312, rclone, redis, salt, tomcat11, v2ray-core, and vim), and Ubuntu (linux-ibm-5.4).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1065015/

Security updates have been issued by AlmaLinux (389-ds:1.4, gnutls, mysql:8.0, mysql:8.4, nginx, nginx:1.24, opencryptoki, python3, vim, and virt:rhel and virt-devel:rhel), Debian (firefox-esr, ruby-rack, and thunderbird), Fedora (fontforge, headscale, kryoptic, libopenmpt, pyOpenSSL, python-cryptography, rubygem-json, rust-asn1, rust-asn1_derive, rust-cryptoki, rust-cryptoki-sys, rust-wycheproof, vim, and vtk), Oracle (freerdp, golang, mysql:8.0, and ncurses), Red Hat (osbuild-composer), Slackware (libpng and tigervnc), SUSE (chromium, frr, kea, kernel, nghttp2, pgvector, python-deepdiff, python-pyasn1, python-tornado6, python-urllib3, python3, python310, ruby2.5, salt, sqlite3, systemd, tomcat, vim, and xen), and Ubuntu (libcryptx-perl).

The forge is our new home (Fedora Community Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1064809/

Tomáš Hrčka has announced
that the Forgejo-based Fedora Forge is now a
fully operational collaborative-development platform; it is ready for
use by the larger Fedora community, which means the homegrown Pagure platform’s days are numbered:

While pagure.io has been a vital part of our community for many
years, the time has come to retire our homegrown forge and transition
to this powerful new tool.

The final cutover is planned for Flock to Fedora 2026. We strongly
encourage teams to migrate their projects well before the conference
to ensure a smooth transition. The pagure.io migration is only the
first step in a broader infrastructure modernization effort. By the
2027 Fedora 46 release, we plan to retire all remaining Pagure
instances across the project, including the package source
repositories on src.fedoraproject.org. Getting familiar with Fedora
Forge now will help ensure your team is ready as the rest of the
Fedora ecosystem transitions.

There is a migration
guide
for Fedora community members that own projects hosted on
Pagure and need to move to the new forge.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1064761/

Security updates have been issued by Debian (awstats, firefox-esr, and nss), Fedora (chromium, dotnet10.0, dotnet8.0, dotnet9.0, freerdp, and wireshark), Mageia (graphicsmagick and xen), Oracle (mysql:8.4 and nginx), Red Hat (podman), Slackware (bind and tigervnc), SUSE (azure-storage-azcopy, firefox-esr, giflib, glances-common, govulncheck-vulndb, grafana, kernel, libpng16, libsoup, mumble, net-snmp, perl-Crypt-URandom, pgvector-devel, pnpm, postgresql17, Prometheus, protobuf, python-cbor2, python-Jinja2, python-simpleeval, python311-dynaconf, python311-pydicom, python313-PyMuPDF, salt, snpguest, systemd, and vim), and Ubuntu (bind9, linux-azure, linux-azure, linux-azure-6.17, linux-azure-6.8, and mbedtls).

[$] LWN.net Weekly Edition for March 26, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1063660/

Inside this week’s LWN.net Weekly Edition:

  • Front: Security collaboration; Manjaro governance; kernel development tools; PHP licensing; kernel direct map patches; sleepable BPF.
  • Briefs: LiteLLM compromise; Tor in Taiwan; b4 v0.15.0; 24-hour sideloading; Agama 19; Firefox 149.0; GNOME 50; Krita 5.3.0 and 6.0.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

Setting up a Tor Relay at National Taiwan Normal University (Tor Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1064671/

The Tor Blog has an interesting article
about the non-technical side of setting up a Tor Relay. It documents how a
computer science student at National Taiwan Normal University worked with the
university system to set up a relay and provides a template for future
attempts:

In Taiwan, anonymous networks do not lack technical documentation or
ideological support. The real scarcity is experience from actually working
through the real institutional system once. Especially in an environment where
academic networks are highly centralized and outbound connectivity is tightly
controlled, distributed anonymous infrastructure like Tor Relays is inherently
difficult to sustain.

This implementation at National Taiwan Normal University was not meant to
provide a final answer for anonymous networks. It was a concrete attempt made
within real-world institutions. It may not immediately improve the performance
or security of anonymous networks, and it was not intended to become a directly
reproducible standard process. What it did achieve was leaving behind a clearly
visible path of practice—one that can be understood, referenced, and built
upon.

LibreQoS v2.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1064669/

Version
2.0
of the LibreQoS traffic-management and network operations
platform has been released.

This release makes LibreQoS easier to operate, easier to understand,
and much more useful for day-to-day network work. Now users can see
more of what is happening across the network, troubleshoot subscriber
issues with better tools, and work from a much stronger local
WebUI.

This release includes many capabilities that reflect ideas and
direction long championed by our late colleague, Dave Täht.

Dave’s work helped shape the understanding of bufferbloat and the
importance of latency under load across the networking community. His
influence continues to guide both LibreQoS and the broader effort to
improve Internet quality.

The project has also announced
the release of the LibreQoS Bufferbloat Test
v2
, also dedicated to Täht. It runs in a user’s browser to look at
latency under load, jitter, loss, and what those things mean for
the kinds of traffic people actually care about: browsing, streaming,
video calls, audio calls, backups, and gaming
“.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1064634/

Security updates have been issued by Debian (chromium), Fedora (chromium, containernetworking-plugins, musescore, and python-multipart), Mageia (perl-XML-Parser, roundcubemail, trilead-ssh2, vim, and webkit2), Oracle (389-ds:1.4, gimp:2.8, glibc, gnutls, kernel, libarchive, nginx:1.24, opencryptoki, python3, uek-kernel, vim, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (delve, osbuild-composer, and skopeo), Slackware (mozilla), SUSE (dpkg, go1.26-openssl, gstreamer-plugins-ugly, kernel, libssh, ovmf, python-pyasn1, python-tornado6, python311, salt, sqlite3, and systemd), and Ubuntu (linux-aws-fips, linux-azure, linux-azure-fips, linux-fips, linux-gcp-fips, linux-iot, linux-kvm, pjproject, and redis).