All posts by jzb

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1054992/

Security updates have been issued by AlmaLinux (cups, libpq, libsoup3, podman, and postgresql16), Debian (ffmpeg, gpsd, python-urllib3, and thunderbird), Fedora (chromium, foomuuri, forgejo, freerdp, harfbuzz, libtpms, musescore, python-biopython, and python3.12), Mageia (gimp, libpng, nodejs, and python-urllib3), and SUSE (alloy, avahi, bind, chromedriver, chromium, cpp-httplib, docker, erlang, fluidsynth, freerdp, go-sendxmpp, govulncheck-vulndb, kernel, libwireshark19, NetworkManager-applet-l2tp, python, python311-virtualenv, thunderbird, and zk).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1054683/

Security updates have been issued by AlmaLinux (gnupg2), Debian (firefox-esr), Oracle (cups, gnupg2, libpq, net-snmp, postgresql, postgresql:15, postgresql:16, transfig, and vsftpd), Red Hat (firefox), SUSE (apache2, curl, firefox, gpg2, hawk2, libcryptopp-devel, openCryptoki, python310, python311-urllib3, rke2, squid, and tomcat), and Ubuntu (cpp-httplib, git, python-apt, and simgear).

Running Debian on the OpenWrt One (Collabora Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1054519/

Sjoerd Simons has published
a blog post
about running Debian on the OpenWrt One
router hardware:

With openwrt-one-debian, you can now install and run a full Debian
system leveraging the OpenWrt One’s NVMe storage, enabling everything
from custom services and containers to development tools and
lightweight server workloads, all on open hardware.

This project provides a rust-based flasher to install Debian on the
OpenWrt One, opening the door to standard Debian tooling, packages,
and workflows. For developers and power users, it transforms the
OpenWrt One from a network appliance into a compact, general-purpose
Linux system.

See the GitHub
repository
for the code and latest build. LWN reviewed the device in
November 2024, and covered Denver
Gingerich’s talk at SCALE 22x about
the making of the router in March 2025.

A note for MXroute users

Post Syndicated from jzb original https://lwn.net/Articles/1054410/

We have recently noticed that email from LWN.net seems to be
blocked by MXroute. Unfortunately, the company also does not seem to
have a way for non-customers to report problems in mail delivery, so
we have no good way to get ourselves unblocked.

As a result, readers who have subscribed to an LWN mailing list
from a domain hosted with MXroute will probably not receive our
mailings. We have not yet unsubscribed addresses that are being
blocked by MXroute, but will soon if the problem persists. Please
accept our apologies for the inconvenience; it is unfortunate that it
is becoming so difficult to send legitimate email as a small
business.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1054408/

Security updates have been issued by Debian (chromium, gnupg2, and mongo-c-driver), Fedora (firefox, gpsd, linux-firmware, and seamonkey), Mageia (net-snmp), Oracle (kernel, podman, postgresql16, postgresql:13, postgresql:15, postgresql:16, and uek-kernel), Red Hat (libpq, net-snmp, and transfig), Slackware (libpng and mozilla), SUSE (avahi, bluez, capstone, curl, dpdk, firefox, firefox-esr, fluidsynth, glib2, kernel, kernel-devel, libmicrohttpd, libpcap, libpng16, libsoup, libsoup-3_0-0, libtasn1, libvirt, mcphost, openvswitch, ovmf, podman, poppler, python-tornado6, python311, qemu, rsync, and valkey), and Ubuntu (erlang, klibc, libpng1.6, and ruby-rack).

[$] LWN.net Weekly Edition for January 15, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1053201/

Inside this week’s LWN.net Weekly Edition:

  • Front: SFC v. VIZIO; GPLv2 requirements; Debian and GTK 2; OpenZL; kernel scheduler QoS; Rust concurrent data access; Asciinema.
  • Briefs: OpenSSL and Python; LSFMM+BPF 2026; Fedora elections; Gentoo retrospective; EU lawmaking; Git data model; Firefox 147; Radicle 1.6.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] Debian discusses removing GTK 2 for forky

Post Syndicated from jzb original https://lwn.net/Articles/1051006/

The Debian GNOME team would like to remove the GTK 2 graphics
toolkit, which has been unmaintained upstream for more than five
years, and ship Debian 14 (“forky”) without it. As one might
expect, however, there are those who would like to find a way to keep
it. Despite its age and declared obsolescence, quite a few Debian
packages still depend on GTK 2. Many of those applications are
unlikely to be updated, and users are not eager to give them
up. Discussion about how to handle this is ongoing; it seems likely
that Debian developers will find some way to continue supporting
applications that require GTK 2, but users may have to look
outside official Debian repositories.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1054167/

Security updates have been issued by AlmaLinux (sssd), Debian (linux-6.1 and python-parsl), Fedora (chezmoi, complyctl, composer, and firefox), Oracle (kernel), Red Hat (buildah, libpq, podman, postgresql, postgresql16, postgresql:13, postgresql:15, and postgresql:16), SUSE (avahi, curl, ffmpeg-4, ffmpeg-7, firefox, istioctl, k6, kubelogin, libmicrohttpd, libpcap-devel, libpng16, libtasn1-6-32bit, matio, ovmf, python-tornado6, python311-Authlib, and teleport), and Ubuntu (angular.js, python-urllib3, and webkit2gtk).

Firefox 147 released

Post Syndicated from jzb original https://lwn.net/Articles/1053995/

Version
147.0
of the Firefox web browser has been released. Notable
changes in this release include support for the XDG Base
Directory specification
, enabling local
network access restrictions
for users with enhanced
tracking protection
(ETP) set to “Strict”, and a fix that improves
Firefox’s rendering with GNOME on fractionally scaled
displays. Firefox 147 also includes a number of security
fixes
, including several sandbox-escape vulnerabilities.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1053988/

Security updates have been issued by AlmaLinux (mariadb10.11, mariadb:10.11, mariadb:10.3, mariadb:10.5, and tar), Debian (net-snmp), Fedora (coturn, NetworkManager-l2tp, openssh, and tuxanci), Mageia (libtasn1), Oracle (buildah, cups, httpd, kernel, libpq, libsoup, libsoup3, mariadb:10.11, mariadb:10.3, openssl, and podman), SUSE (cpp-httplib, ImageMagick, libtasn1, python-cbor2, util-linux, valkey, and wget2), and Ubuntu (google-guest-agent, linux-iot, and python-urllib3).

[$] Asciinema: making movies at the command-line

Post Syndicated from jzb original https://lwn.net/Articles/1053355/

In open-source circles there are many situations, such as bug
reports, demos, and tutorials, when one might want to provide a
play-by-play of a session in one’s terminal. The asciinema project provides a set of
tools to do just that. Its tools let users record, edit, and share
terminal sessions in a text-based format that has quite a few
advantages compared to making and sharing videos of terminal sessions. For
example, it is easy to use, offers the ability to search text from
recorded sessions, and allows users to copy and paste directly from
the recording.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1053820/

Security updates have been issued by Debian (chromium and sogo), Fedora (chromium, foomuuri, libpng, libsodium, mariadb10.11, musescore, nginx, python-pdfminer, python-urllib3, python3.12, seamonkey, wasmedge, and wget2), Mageia (curl, libpcap, sodium, wget2, and zlib), Slackware (lcms2), SUSE (chromedriver, chromium, noopenh264, coredns, curl, dcmtk, fontforge, gdk-pixbuf-loader-libheif, gimp, kernel, libheif, libpng16, libsoup-2_4-1, libvirt, mariadb, php8, poppler, python-filelock, python-tornado6, python311-aiohttp, qemu, sssd, and traefik), and Ubuntu (libheif, libtasn1-6, linux-azure-nvidia, linux-kvm, linux-raspi, linux-raspi-realtime, and php7.2, php7.4, php8.1, php8.3, php8.4).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1053492/

Security updates have been issued by Debian (pdfminer and vlc), Red Hat (kernel, kernel-rt, and microcode_ctl), Slackware (libtasn1), SUSE (apptainer, curl, ImageMagick, libpcap, libvirt, libwget4, php8, podman, python311-cbor2, qemu, and rsync), and Ubuntu (gnupg, gnupg2, gpsd, libsodium, and python-tornado).

Gentoo looks back on 2025

Post Syndicated from jzb original https://lwn.net/Articles/1053289/

Gentoo Linux has published a 2025
project retrospective
that looks at how the community has evolved,
changes to the distribution, infrastructure, and finances for the
Gentoo Foundation.

Gentoo currently consists of 31663 ebuilds for 19174 different
packages. For amd64 (x86-64), there are 89 GBytes of binary packages
available on the mirrors. Gentoo each week builds 154 distinct installation stages for
different processor architectures and system configurations, with an
overwhelming part of these fully up-to-date.

The number of commits to the main ::gentoo
repository has remained at an overall high level in 2025, with a
slight decrease from 123942 to 112927. The number of commits by
external contributors was 9396, now across 377 unique external
authors.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1053277/

Security updates have been issued by AlmaLinux (gcc-toolset-14-binutils, gcc-toolset-15-binutils, httpd, kernel, libpng, mariadb, mingw-libpng, poppler, python3.12, and ruby:3.3), Debian (foomuuri and libsodium), Fedora (python-pdfminer and wget2), Oracle (audiofile, bind, gcc-toolset-15-binutils, libpng, mariadb, mariadb10.11, mariadb:10.11, mariadb:10.5, mingw-libpng, poppler, and python3.12), Red Hat (git-lfs, kernel, libpng, libpq, mariadb:10.3, osbuild-composer, postgresql, postgresql:13, and postgresql:15), Slackware (curl), SUSE (c-ares-devel, capstone, curl, gpsd, ImageMagick, libpcap, log4j, python311-filelock, and python314), and Ubuntu (libcaca, libxslt, and net-snmp).