All posts by jzb

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1059638/

Security updates have been issued by AlmaLinux (grafana), Debian (gegl, inetutils, libvpx, nova, and python-django), Fedora (azure-cli, chromium, microcode_ctl, python-azure-core, python3.14, and roundcubemail), Red Hat (grafana and osbuild-composer), SUSE (apptainer, dnsdist, istioctl, libsoup, openCryptoki, python-nltk, python311, python313, rclone, and thunderbird), and Ubuntu (libvpx, linux-azure, linux-azure-5.4, linux-azure-fips, and linux-intel-iotg).

openSUSE governance proposal advances

Post Syndicated from jzb original https://lwn.net/Articles/1059511/

Douglas DeMaio has announced
that Jeff Mahoney’s new governance
proposal
for openSUSE, which was published in January,
is moving forward. The new structure would have three governance
bodies: a new technical steering committee (TSC), a community and
marketing committee (CMC), as well as the existing openSUSE
board.

The discussions during the meeting proposed that the Technical
Steering Committee should begin with five members with a chair elected
by the committee. The group would establish clear processes for
reviewing and approving technical changes, drawing inspiration from
Fedora’s FESCo model. Decisions for the TSC would use a voting system
of +1 to approve, 0 for neutral, or -1 to block. A proposal passes
without objection. A -1 vote would require a dedicated meeting, where
a majority of attendees would decide the outcome. Objections must
include a clear, documented rationale.

Discussions related to the Community and Marketing Committee would
focus on outreach, advocacy, and community growth. It could also serve
as an initial escalation point for disputes. If consensus cannot be
reached at that level, matters would advance to the Board.

[…] No timeline for final adoption was announced. Project
contributors will continue discussions through the GitLab repository
and future community meetings.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1059500/

Security updates have been issued by AlmaLinux (edk2, glibc, gnupg2, golang, grafana, nodejs:24, and php), Debian (gimp and kernel), Fedora (fvwm3), Mageia (microcode and vim), Oracle (edk2, glibc, kernel, nodejs:24, and php), Red Hat (python-s3transfer), SUSE (abseil-cpp, avahi, azure-cli-core, fontforge, go1.24, go1.25, golang-github-prometheus-prometheus, libpcap, libsoup2, libxml2-16, mupdf, nodejs22, openCryptoki, openjpeg2, patch, python-aiohttp, python-Brotli, python-pip, python311-asgiref, rust1.93, and traefik), and Ubuntu (inetutils, libssh, linux-gcp, linux-gke, linux-hwe-6.8, linux-lowlatency-hwe-6.8, linux-intel-iotg-5.15, linux-xilinx-zynqmp, linux-lowlatency, linux-nvidia-lowlatency, and trafficserver).

[$] LWN.net Weekly Edition for February 19, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1058474/

Inside this week’s LWN.net Weekly Edition:

  • Front: AI agent goes rogue; debuginfo; iocane; revocable resource-management patches; 7.0 merge window; AccECN; LLMs and security; Humanitarian OpenStreetMap Team.
  • Briefs: upki; Asahi Linux progress; DFSG processes; Fedora in Syria; Plasma 6.6.0; Vim 9.2; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

Fedora now available in Syria

Post Syndicated from jzb original https://lwn.net/Articles/1059342/

Justin Wheeler writes, on Fedora
Magazine, that Fedora is now available in Syria once again:

Last week, the Fedora Infrastructure Team lifted
the IP range block
on IP addresses in Syria. This action restores
download access to Fedora Linux deliverables, such as ISOs. It also
restores access from Syria to Fedora Linux RPM repositories, the
Fedora Account System, and Fedora build systems. Users can now access
the various applications and services that make up the Fedora
Project. This change follows a recent update to the Fedora Export
Control Policy. Today, anyone connecting to the public Internet from
Syria should once again be able to access Fedora.

[…] Opening the firewall to Syria took seconds. However, months of
conversations and hidden work occurred behind the scenes to make this
happen.

An update to the malicious crate notification policy (Rust Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1059338/

Adam Harvey, on behalf of the crates.io
team
has published a blog
post
to inform users of a change in their practice of publishing
information about malicious Rust crates:

The crates.io team will no longer publish a blog post each time a
malicious crate is detected or reported. In the vast majority of cases
to date, these notifications have involved crates that have no
evidence of real world usage, and we feel that publishing these blog
posts is generating noise, rather than signal.

We will always publish a RustSec
advisory when a crate is removed for containing malware. You can
subscribe to the RustSec
advisory RSS feed
to receive updates.

Crates that contain malware and are seeing real usage or
exploitation will still get both a blog post and a RustSec
advisory. We may also notify via additional communication channels
(such as social media) if we feel it is warranted.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1059333/

Security updates have been issued by Debian (ceph, gimp, gnutls28, and libpng1.6), Fedora (freerdp, libpng, libssh, mingw-libpng, mingw-libsoup, mingw-python3, pgadmin4, python-pillow, thunderbird, and vim), Mageia (postgresql15), Red Hat (python-urllib3), SUSE (cdi-apiserver-container, cdi-cloner-container, cdi- controller-container, cdi-importer-container, cdi-operator-container, cdi- uploadproxy-container, cdi-uploadserver-container, cont, frr, gpg2, kubernetes, kubernetes-old, libsodium, libsoup-2_4-1, libssh, libtasn1, libxml2, nodejs22, openCryptoki, openssl-3, and python311-pip), and Ubuntu (frr, linux-aws, linux-aws-6.8, linux-gkeop, linux-nvidia, linux-nvidia-6.8, linux-oracle, linux-oracle-6.8, linux-aws-fips, linux-fips, linux-gcp-5.15, linux-kvm, linux-oracle, linux-oracle-5.15, linux-gcp-fips, linux-nvidia, linux-nvidia-tegra-igx, linux-oem-6.17, linux-realtime, linux-raspi-realtime, nova, and pillow).

[$] Do androids dream of accepted pull requests?

Post Syndicated from jzb original https://lwn.net/Articles/1058643/

Various forms of tools, colloquially known as “AI”, have been
rapidly pervading all aspects of open-source development. Many
developers are embracing LLM tools for code creation and review. Some
project maintainers complain about suffering from a deluge of slop-laden pull
requests, as well as fabricated bug and security
reports
. Too many projects are reeling from scraperbot attacks that
effectively DDoS important infrastructure. But an AI bot flaming an
open-source maintainer was not on our bingo card for 2026; that seemed
a bit too far-fetched. However, it appears that is just what happened
recently after a project rejected a bot-driven pull request.

Plasma 6.6.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1059187/

Version
6.6.0
of KDE’s Plasma desktop environment has been
released. Notable additions in this release include the ability to
create global themes for Plasma, an “extract text” feature in the Spectacle screenshot
utility, accessibility improvements, and a new on-screen keyboard. See
the changelog
for a full list of new features, enhancements, and bug fixes.

The release is dedicated to the memory of Björn Balazs, a KDE
contributor who passed away in September 2025. “Björn’s drive to
help people achieve the privacy and control over technology that he
believed they deserved is the stuff FLOSS legends are made of.

An update on upki

Post Syndicated from jzb original https://lwn.net/Articles/1059184/

In December 2025, Canonical announced a plan to
develop a universal Public Key Infrastructure called upki. Jon Seager has published
an update
about the project with instructions on trying it
out.

In the few weeks since we announced upki, the core revocation engine
has been established and is now functional, the CRLite mirroring tool
is working and a production deployment in Canonical’s datacentres is
ongoing. We’re now preparing for an alpha release and remain on track
for an opt-in preview for Ubuntu 26.04 LTS.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1059176/

Security updates have been issued by AlmaLinux (gimp, go-toolset:rhel8, and golang), Debian (roundcube), Fedora (gnupg2, libpng, and rsync), Mageia (dcmtk and usbmuxd), Oracle (gcc-toolset-14-binutils, gimp, gnupg2, go-toolset:ol8, golang, kernel, and openssl), Slackware (libssh, lrzip, and mozilla), SUSE (abseil-cpp, chromium, curl, elemental-toolkit, elemental-operator, expat, freerdp, iperf, libnvidia-container, libsoup, libxml2, net-snmp, openCryptoki, openssl-3, patch, protobuf, python-urllib3, python-xmltodict, python311, screen, systemd, and util-linux), and Ubuntu (alsa-lib, gnutls28, and linux-aws, linux-oracle).

[$] Open source security in spite of AI

Post Syndicated from jzb original https://lwn.net/Articles/1058266/

The curl project has found AI-powered tools to be a mixed bag when
it comes to security reports. At FOSDEM 2026, curl creator and
lead developer Daniel Stenberg used his keynote session to discuss his
experience receiving a slew of low-quality reports and, at the same
time, realizing that large language model (LLM) tools can sometimes
find flaws that other tools have missed.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1058989/

Security updates have been issued by Debian (chromium, pdns-recursor, python-django, and wireshark), Fedora (gnutls, linux-sgx, mingw-expat, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, p11-kit, python-aiohttp, vim, and xen), Red Hat (kernel, kernel-rt, python-s3transfer, python-urllib3, and resource-agents), SUSE (aaa_base, abseil-cpp, build-20260202, cargo-auditable, cargo-c, chromedriver, cockpit, cockpit-packages, cockpit-subscriptions, curl, elemental-toolkit, elemental-operator, gnome-remote-desktop, go1.24, go1.25, gpg2, haproxy, himmelblau, htmldoc, ImageMagick, iperf, java-1_8_0-openjdk, kernel, krb5, kubevirt, libowncloudsync-devel, libpng16-16, libsodium, libsoup, libsoup2, micropython, net-snmp, opencryptoki, openjfx, openssl1, ovmf, postgresql14, postgresql15, postgresql16, protobuf, python-aiohttp, python-brotli, python-maturin, python-pip, python-urllib3, python310, python311, python-rpm-macros, python311-cryptography, python314, screen, systemd, u-boot, util-linux, and vim), and Ubuntu (dotnet8, dotnet10, expat, freerdp2, freerdp3, and python-aiohttp).

New delegation for Debian’s data protection team

Post Syndicated from jzb original https://lwn.net/Articles/1058663/

Debian Project Leader (DPL) Andreas Tille has announced
a new delegation for Debian’s data projection team:

Following the end of the previous delegation, Debian was left
without an active Data Protection team. This situation has
understandably drawn external attention and highlighted the importance
of having a clearly identified point of contact for data protection
matters within the project.

I am therefore very pleased to announce that new volunteers have
stepped forward, allowing us to re-establish the Debian Data
Protection team with a fresh delegation.

Tille had put out a call for
volunteers
in January after all previous members of the team had
stepped down. He has appointed Aigars Mahinovs, Andrew M.A. Cater,
Bart Martens, Emmanuel Arias, Gunnar Wolf, Kiran S Kunjumon, and Salvo
Tomaselli as the new members of the team. The team provides a central
coordination and advisory function around Debian’s data handling,
retention, dealing with deletion requests, and more.

[$] Open-source mapping for disaster response

Post Syndicated from jzb original https://lwn.net/Articles/1057691/

At FOSDEM 2026 Petya
Kangalova, a senior tech partnership and engagement manager for the Humanitarian OpenStreetMap
Team
(HOT) spoke about how
the project helps people map their surroundings to assist in
disaster response and humanitarian aid. The project has
developed a stack of technology to help volunteers collectively map an
area and add in local knowledge metadata. “One of the core things
that we believe is that when we speak about disaster response or
people having access to data is that they really need accessible
technology that’s free and open for anyone to use
.”

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1058642/

Security updates have been issued by AlmaLinux (firefox, gcc-toolset-14-binutils, nodejs:20, nodejs:22, nodejs:24, php:7.4, and python3.12), Debian (haproxy, nginx, postgresql-15, and postgresql-17), Fedora (libssh), Oracle (glib2, libsoup, nodejs:20, nodejs:22, and php:7.4), SUSE (assimp, gnutls, helm, kernel, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t, libmunge2, libsodium, libsoup, micropython, munge, openCryptoki, python-azure-core, rust-keylime, rustup, sccache, snpguest, tcpreplay, xorg-x11-server, xrdp, and zabbix), and Ubuntu (dnsdist, dotnet8, dotnet9, dotnet10, haproxy, libpng1.6, linux-aws-5.15, linux-azure, linux-azure-fips, linux-oracle, linux-oracle-5.4, munge, nginx, and node-dottie).