All posts by jzb

F-Droid 2.0: A new chapter for Android freedom

Post Syndicated from jzb original https://lwn.net/Articles/1096444/

The F-Droid project has announced
the release of F-Droid 2.0, which is a complete redesign of the official
app. Notable changes in the release include making it easier to discover and
install applications, more useful app categories, improved search, and
much more.

For more than a decade, F-Droid has helped people discover and install free
and open source Android apps. F-Droid 2.0 builds on that foundation with a
modern interface, better app discovery, improved search, and a simpler
experience that works well, whether you’re new to F-Droid or have been using it
for years.

This isn’t just a visual refresh. The user experience was redesigned to
integrate smoothly with current Android patterns, like Material Design, while
keeping familiar F-Droid interactions in place. Key components were reworked and
rewritten using Kotlin Compose, the standard toolkit these days, creating a
foundation that will help us deliver improvements more quickly in the years
ahead.

Research into file-notification attacks on Linux

Post Syndicated from jzb original https://lwn.net/Articles/1096431/

Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, has announced the
release of research into file-notification attacks that would allow spying on
user activity on Android, Linux, macOS, and Windows. The group has published a paper with
details on the research as well as a web site
with demonstrations of the vulnerabilities.

On Linux, an attacker can use inotifywatch to
monitor a directory to conduct an inter-keystroke timing attack—even if
they do not have read access to the files within a directory. The group also
discovered a method to conduct a UI-redress
attack
(or “clickjacking” attack) on
KDE 5 and KDE 6 by monitoring /usr/bin/pkexec to detect when Polkit spawns an authentication
prompt. An attacker could draw a fake password window on top of the real window
to collect a user’s credentials.

Both of these flaws are still present today,
though the Linux kernel did partially mitigate the issue with a
fix
that was included in the 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.65,
and 6.18.3 kernels shipped in January. See the web site for more information and
a mitigation to prevent password-prompt windows from losing focus.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1096407/

Security updates have been issued by AlmaLinux (buildah, containernetworking-plugins, firefox, kernel, kernel-rt, openexr, perl-DBI, podman, postgresql, postgresql16, postgresql:15, runc, skopeo, and tar), Debian (libdatetime-timezone-perl, tzdata, xdg-dbus-proxy, and znc), Fedora (chromium, evolution, evolution-data-server, evolution-ews, kernel, libheif, mingw-pcre2, nginx-mod-modsecurity, unbound, and webkitgtk), Mageia (borgbackup, coreutils, firefox, nss, kbd, libnfs, libwebsockets, perl-URI, pipewire, and xdg-dbus-proxy), Oracle (apr-util, containernetworking-plugins, coreutils, curl, firefox, freerdp, gstreamer1-plugins-base, host-metering, libarchive, libtiff, libxml2, openexr, openssh, perl-DBI, podman, postgresql16, postgresql18-postgis, postgresql:15, rsyslog, runc, tar, and unbound), SUSE (apptainer, gimp, librepods, libX11-6, perl-Authen-SASL, podofo, python-WebOb, and python313-graphifyy), and Ubuntu (imagemagick, libgit2, moodle, network-manager, Open-iSNS, python-urllib3, sqlparse, and xdg-desktop-portal).

[$] Ideas on modernizing the open-source desktop

Post Syndicated from jzb original https://lwn.net/Articles/1095425/

Scott Jenson has been working on user interfaces (UIs) and user experience (UX)
for many years at Apple, Google, and other companies. Now, he’s trying to convince
open-source projects to experiment more and drive the desktop beyond the age-old “windows, icons, menus,
pointer
” (WIMP) model. At Akademy 2026, KDE’s annual developer
conference, he shared his complaints and ideas in a talk aimed
at convincing those in attendance to take the lead on desktop design.

Systemd v262 released

Post Syndicated from jzb original https://lwn.net/Articles/1096204/

Systemd v262 has been released. Some of the notable new features include the
ability to build systemd as a single statically linked binary for small
containers, support for the kernel coredump socket protocol introduced with
Linux 6.17, addition of OpenSSL 4 support, and many other changes. See
the release
notes
for a full list of changes.

Critical security vulnerabilities in the Radicle network protocol

Post Syndicated from jzb original https://lwn.net/Articles/1096200/

The Radicle peer-to-peer
code-collaboration project has disclosed
two critical vulnerabilities
in the network protocol used by Radicle
nodes. The first flaw is that the network protocol used by Radicle “does not
give the confidentiality it was expected to give
“, which allows anyone who
can observe the network between two nodes to read the data exchanged. The second
is that peer authentication is broken and allows impersonation, so an attacker
can spoof their Node ID and read private repositories they should not be able to
read.

In practice, the two flaws are most useful when they can be exploited
together: an attacker on the path sees the Node IDs at both ends of a
connection, and both are normally on the allow-list. That attacker can read
whatever is exchanged while they watch, and can then use a Node ID they saw to
fetch the whole repository on demand. The realistic threat is anyone on the path
between your node and node it syncs with, and no setting or allow-list protects
against them.

We are publishing this before the security update is available. You can act
on it today, and no fix we release later can undo an exposure that has already
happened.

See the post for workarounds that can be used today; a major update that will
be backward-incompatible is underway.

Critical WordPress RCE vulnerability announced

Post Syndicated from jzb original https://lwn.net/Articles/1096195/

A critical
vulnerability
has been discovered in WordPress‘s get_page_template()
function for page-template resolution that could allow remote-code execution
(RCE) by an unauthenticated attacker, in some limited circumstances. The project
has provided an update for the most recent branch of WordPress, as well as
backports of the fix for branches back to 4.7. See the
vulnerability report for the conditions required for an RCE attack to be successful.

The vulnerability also
affects
the ClassicPress fork of
WordPress, though a security update has not been provided for that project
yet. LWN covered ClassicPress in
2024. Users of either content-management system should update soon.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1096191/

Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10.0, dotnet8.0, dotnet9.0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5.15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7.0, linux-azure-fde-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-oracle, linux-oracle-6.8, linux-raspi, openssh, and sudo).

[$] Testing compat_linux on NetBSD with the Linux Test Project

Post Syndicated from jzb original https://lwn.net/Articles/1094310/

NetBSD has long had support for
running Linux binaries via its kernel-level compat_linux
feature, but test coverage for it was less complete than some might
hope. In order to provide better testing for compat_linux,
Google Summer of Code (GSoC) participant Henrique Brito opted to work
on enabling the Linux Test
Project (LTP)
test suite to compile and run on NetBSD. At EuroBSDCon 2026, Brito’s
mentor, Stephen Borrill, provided a report on the project, and the
status of LTP on NetBSD. The work has already resulted in some minor
fixes, and a good list of additional problems to solve.

Vondra: PostgreSQL development activity

Post Syndicated from jzb original https://lwn.net/Articles/1094470/

PostgreSQL contributor Tomas Vondra has published a blog
post
looking at development activity in the project, with data from the late
1990s to today.

We’re doing ~50 commits per week, give or take. In ~2010 we were doing maybe
25/week, and the trend seems to be a slow and consistent growth. The monthly
average makes the trend a bit easier to spot. Which is good, although there’s a
lot of other important details (size of commits, are they new features or fixes,
…).

It however nicely aligns with the number of active committers, which also
grew ~2x between 2010 and today. So maybe that’s working as expected.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1094469/

Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip), Red Hat (grafana and image-builder), SUSE (389-ds, acl, attr, apache2-mod_auth_openidc, apr-util, aws-nitro-enclaves-cli, bzip2, c-ares, clamav, cpio, curl, dhcpcd, dovecot23, dovecot24, dracut, emacs, fuse-overlayfs, go1.25-openssl, go1.26-openssl, google-cloud-sap-agent, google-osconfig-agent, govulncheck-vulndb, gstreamer-devtools, gzip, helm, java-17-openjdk, java-21-openjdk, java-25-openjdk, jq, libBasicUsageEnvironment2, libgpg-error, libidn, librest, libusb-1_0, libvirt, LibVNCServer, libzypp, zypper, lkl, mcphost, MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen, MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen, MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen, msgpack-c, multipath-tools, NetworkManager, openexr, openssl-3, perl-Protocol-HTTP2, perl-URI, php-composer2, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python-aiohttp, python-cryptography, python-h2, python-ruff, python-sqlparse, python311, python312, python39.SUSE_SLE-15-SP3_Update, rav1e, rpcbind, sssd, systemd, tomcat, tomcat11, ucode-intel, udisks2, vim, and wicked2nm), and Ubuntu (cgit, dracut, freeciv, konsole, libinput, linux-azure, linux-nvidia-7.0, nginx, vips, and yelp).

GNU Core Utilities 9.12 released

Post Syndicated from jzb original https://lwn.net/Articles/1094312/

Pádraig Brady has announced
GNU Core Utilities (coreutils) version 9.12. “There have been 288 commits by
16 people in the 21 weeks since 9.11
“. New features include an -A
option for uname
which labels all output, as well as adding awareness of the failfs and nullfs filesystem types to stat
and tail.

There are many bug fixes in this release as well, including one for a bug “present
in ‘the beginning’
” that caused some utilities to fail when traversing
hierarchies if files are being removed in parallel.

[$] Lessons learned as the Debian Project Leader

Post Syndicated from jzb original https://lwn.net/Articles/1093381/

What is it like to be a Debian Project Leader (DPL), or a former one?
According to Andreas Tille, who stepped down this year after two consecutive
terms as DPL, you’d have to be one to know. At the recent MiniDebConf in Winterthur,
Switzerland
, Tille spoke about what he learned while serving as DPL, some of
the initiatives he led, mistakes that he made, and his thoughts on the general resolution (GR) on large
language model (LLM) usage in Debian
.

Emacs arbitrary code execution flaw

Post Syndicated from jzb original https://lwn.net/Articles/1094224/

Sean Whitton has announced
that the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) was
incomplete. Bas Alberts discovered that viewing or editing untrusted files in
modes other than Emacs’s Lisp mode can also result in arbitrary code
execution.

This problem affects all Emacs versions affected by CVE-2024-53920.
This means Emacs 24 and newer, and possibly also older versions.

A minimal fix, attached, is queued up for release with Emacs 31.2.
We (the Emacs upstream maintainers) don’t expect to backport the fix to
older Emacs releases ourselves.

LWN covered the original
vulnerability in December 2024.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1094211/

Security updates have been issued by AlmaLinux (389-ds-base, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, kernel, libkcapi, nginx, nodejs:22, nodejs:24, osbuild-composer, perl-YAML-Syck, postgresql16-postgis, ruby, ruby4.0, ruby:3.3, and vim), Debian (jbig2dec, kamailio, nginx, spip, and xorg-server), Fedora (baresip, bind, bluez, bubblewrap, chirp, chromium, cockpit, composer, corosync, darktable, dokuwiki, elixir, exiv2, expat, firefox, freerdp, freerdp2, gdk-pixbuf2, gegl04, golang-x-perf, grpcurl, kernel, kernel-headers, libevent, libmongocrypt, libpcap, libre, libsoup3, memcached, mingw-expat, mingw-openexr, mongo-c-driver, mrtg, nagios-plugins, nsd, nss, openssl, openvpn, PackageKit, pdns-recursor, perl-Net-OAuth, perl-XML-Bare, php-pecl-mongodb2, python-asteval, python-pip, rclone, rest, rust-hickory-net, rust-hickory-proto, rust-hickory-resolver, rust-ppmd-rust, rust-webbrowser, srt, syncthing, tar, tkimg, and valkey), Gentoo (Chromium, Google Chrome, Microsoft Edge, Opera, Vivaldi and Ruby), Mageia (bind, ffmpeg, glibc, java-17-openjdk, java-21-openjdk, librabbitmq, perl-Catalyst-Plugin-Static-Simple, perl-Imager, tor, and xz), Oracle (389-ds:1.4, ansible-core, apr-util, coreutils, freerdp, git-lfs, glib2, gstreamer1-plugins-base, gzip, httpd:2.4, image-builder, java-21-openjdk, kernel, mrtg, nginx, osbuild-composer, perl-DBI, postgresql16-postgis, python-lxml, python3.12-lxml, redis:6, and vim), SUSE (389-ds, ansible-core, ansible-creator, azure-storage-azcopy, cargo-audit, chromedriver, chromium, clamav, containerized-data-importer1.65, containerized-data-importer1.66, curl, dracut, ffmpeg-4, google-guest-agent, google-osconfig-agent, helm, java-1_8_0-ibm, jupyter-nbconvert, kernel, libpng16, libusb-1_0, libvirt, multipath-tools, NetworkManager, opensc, openssl-3, perl-Authen-SASL, perl-HTML-FormHandler, perl-Mojolicious, perl-Protocol-HTTP2, python-jwcrypto, python-sqlparse, python-tornado6, python313-geopy, python313-modelscope, python313-modelscope-hub, python313-pypdf, python315, rpcbind, sshamble, strongswan, tomcat, ucode-intel, and wget), and Ubuntu (civetweb, ffmpeg, and urwid).

More than 9,000 patches total in the seven stable kernels for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1093985/

Greg Kroah-Hartman has announced the 7.2.6,
6.18.52, 6.12.110, 6.6.157, 6.1.188,
5.15.221, 5.10.270 stable kernels.

According to
Kroah-Hartman
, this batch may set a record for the number of patches with
more than 9,000 in total between them. There are more than 1,800
patches
in 7.2.6 alone. Users of these kernels are, of course, advised to
upgrade.