All posts by jzb

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1093765/

Security updates have been issued by AlmaLinux (apr-util and qt6-qt5compat), Debian (libevent and ruby-rack), Fedora (bluez, corosync, curl, dokuwiki, grpcurl, libevent, and rest), Oracle (gstreamer1-plugins-bad-free, perl-DBI, python-urllib3, qt5-qtbase, qt6-qt5compat, and thunderbird), Red Hat (osbuild-composer), SUSE (azure-storage-azcopy, chromedriver, corosync, ggml-devel, helm, kernel, libmariadb-devel, libzypp, zypper, opensc, php7, tomcat10, and waylyrics), and Ubuntu (apache2, beets, glibc, kissfft, libebml, linux-nvidia-6.17, php8.1, php8.3, php8.5, and python2.7, python3.4, python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.14).

Forgejo 16.0.4 and 15.0.8 address critical security vulnerability

Post Syndicated from jzb original https://lwn.net/Articles/1093671/

The Forgejo software-forge project has announced the
release of versions 16.0.4
and 15.0.8,
which fixes two security vulnerabilities. One is a critical flaw that would
allow remote-code execution (RCE):

When generating a new repository from a template repository, Forgejo clones the
template repository, removes the .git folder, performs variable template
expansion on files listed in .forgejo/template, and initializes a new git
repository. During this process, variable template expansion could be misused in
order to create a new .git folder, which git would adopt and incorporate during
its initialization of a new git repository. A malicious template repository
could be used to read arbitrary data from the Forgejo host, and to execute
arbitrary processes on the Forgejo host, as a remote code execution attack. To
address this issue, after variable expansion is completed, any existing .git
folder is removed from the directory before the git repository is initialized.

The project recommends upgrading to the latest version as soon as
possible.

[$] PostgreSQL 19’s “scary patch contest”

Post Syndicated from jzb original https://lwn.net/Articles/1092003/

PostgreSQL 19 was
expected to be released in September, in keeping with the database
project’s longstanding tradition of a major release every year. However,
some late-breaking concerns about several of the features slated for inclusion
has some developers worried about the quality of the release. On August 25, PostgreSQL
contributor Robert Haas sent
an email
with the subject “scary patch contest” about several patches
that have required an unusually large number of bug fixes leading up to the
release, which has raised questions about their readiness for a stable
release. One of the patches has been reverted, but several are still under heavy
revision, and an extra beta release has been slotted in to allow for additional
testing.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1093566/

Security updates have been issued by AlmaLinux (389-ds-base, ansible-core, buildah, expat, glib2, gpsd, gpsd-minimal, gzip, kernel, kernel-rt, opentelemetry-collector, osbuild-composer, perl-DBI, python-lxml, python3.12-lxml, qt5-qtbase, thunderbird, valkey, vim, and xz), Debian (pyasn1), Fedora (darktable, freeipa, freerdp2, gdk-pixbuf2, GitPython, libsoup3, openssl, perl-Net-DNS, rust-ppmd-rust, samba, and valkey), Mageia (ceph, firefox, nss, perl-DBI, thunderbird, and wget), Oracle (389-ds-base, buildah, expat, git-lfs, glib2, glibc, gpsd, gpsd-minimal, grafana-pcp, kernel, libssh, nginx, perl-GD, python3.14-cryptography, redis:7, skopeo, thunderbird, valkey, xmlrpc-c, and xz), Slackware (xz), SUSE (bzip2, cpio, curl, dracut, fuse-overlayfs, golang-github-vpenso-prometheus_slurm_exporter, helm, java-1_8_0-ibm, kbfs, kernel, kernel-devel, libopenslide-devel, libsoup, libssh2_org, libusb-1_0, libvirt, libzypp, zypper, mcphost, multipath-tools, NetworkManager, opensc, openssl-3, perl-Net-DNS, python-aiohttp, python-Authlib, python-pip, python-sqlparse, python313-dnspython, python313-idna, rpcbind, sssd, strongswan, systemd, tomcat11, ucode-intel, and wget), and Ubuntu (dotnet8, dotnet10, ffmpeg, flatpak, netty, and perl).

A decade of Rustls

Post Syndicated from jzb original https://lwn.net/Articles/1093391/

Joe Birr-Pixton has written a blog post
reflecting on a decade of the Rustls TLS-library project and looking ahead to
the upcoming 0.24 release and an eventual 1.0 release.

Rustls began with a
first commit
on May 2, 2016. Progress was quick: a month later, on June 5,
it could interoperate with most sites on the web. The first release, 0.1.0,
followed on August 27, 2016 – less than four months after the first commit.

[…] From the 0.1.0 release, the project moved through a long series of
releases over the following eight years, building out functionality, hardening
and refining the API. That sequence of release lines culminated in 0.23,
released on February 29, 2024.

The 0.23 release line has been a stable one: in the time since, it has
seen 43 non-breaking releases. That stability didn’t come with
stagnation. The 0.23 line delivered a wide range of important features,
including a FIPS-certified cryptography option, certificate compression,
Encrypted ClientHello, post-quantum cryptography, and performance
improvements.

LibreOffice Base survey results

Post Syndicated from jzb original https://lwn.net/Articles/1093388/

Heiko Tietze has published
a blog post
summarizing the results of a recent
survey
about the use of LibreOffice’s database application, Base. 455 people
participated in the survey, including more than 330 who use Base on Linux, with
use cases ranging from maintaining records of personal media such as CDs or DVDs
to use enterprise-resource planning (ERP) and finance. Of course, users had many
ideas how to improve the application:

The majority asks for improvements to the user interface with less
clutter and a more attractive design. The workflow and user experience should
become either simplified or more powerful, depending on the expertise and the
scenario. For example, an elaborate search function is something that
many people expect. […]

Almost the same number of answers requests bug fixes, improvements to
stability, and better performance. Issues with queries, forms, and reports were
mentioned equally often. In this regard, many replies suggest to remove the Java
dependencies.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1093342/

Security updates have been issued by AlmaLinux (expat, glib2, microcode_ctl, mrtg, pam, redis, thunderbird, and valkey), Debian (fort-validator, gst-plugins-base1.0, kernel, and slurm-wlm), Fedora (complyctl, libevent, openvpn, and tar), Mageia (dovecot and spice-vdagent), Red Hat (ignition, opentelemetry-collector, and osbuild-composer), SUSE (amazon-ssm-agent, aws-nitro-enclaves-cli, bzip2, cadvisor, chromium, curl, distribution-registry, emacs, freeciv, fuse-overlayfs, gh, google-guest-agent, GraphicsMagick, hauler, insighttoolkit-devel, java-17-openjdk, libidn, libusb-1_0, libvirt, libvncserver, libzypp, zypper, lkl, lxd, multipath-tools, NetworkManager, perl-Net-DNS, perl-URI, python, python-authlib, python-sqlparse, python-tornado, python3, rpcbind, supergfxctl, systemd, terraform-provider-null, ucode-intel, wget, wireshark, and xen), and Ubuntu (curl, ffmpeg, glibc, hsqldb1.8.0, imagemagick, perl, and vim).

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1093144/

Security updates have been issued by AlmaLinux (expat, git-lfs, grafana-pcp, kernel-rt, python3.14-cryptography, redis:6, skopeo, and xmlrpc-c), Debian (jbig2dec and strongswan), Fedora (baresip, chirp, chromium, corosync, emacs, GitPython, libre, libsoup3, nsd, perl-Net-OAuth, and perl-XML-Bare), Mageia (apache-mod_auth_openidc, exiv2, freerdp, python-pyasn1, and tor), Red Hat (buildah, cockpit-image-builder, container-tools:rhel8, containernetworking-plugins, delve, linux-sgx, osbuild-composer, pcs, and runc), SUSE (amazon-cloudwatch-agent, aws-nitro-enclaves-cli, bzip2, c-ares, curl, dracut, emacs, fuse-overlayfs, gegl, GraphicsMagick, httpcomponents-client, java-1_8_0-openjdk, java-25-openjdk, lcms2, libidn, libusb-1_0, LibVNCServer, microcode_ctl, multipath-tools, NetworkManager, nghttp2, openexr, openssl-1_1, openssl-3, perl-URI, php-composer2, postgresql15, postgresql17, postgresql18, python-GitPython, python-tornado6, python313-pip, redis, redis7, ucode-intel, wget, and wireshark), and Ubuntu (gzip and php7.0).

[$] CERN’s migration path from CentOS Linux to Debian

Post Syndicated from jzb original https://lwn.net/Articles/1092512/

The European Laboratory for Particle Physics, usually just called CERN, is not only the birthplace of
the World Wide Web
, it is home to the Large Hadron
Collider
(LHC), the world’s largest and highest-energy particle
accelerator
. As such, its computing environment is both truly unique and of
great interest to people outside of CERN who hope to find lessons applicable to
their own computing needs. The upcoming migration of some of CERN’s systems from
CentOS Linux to Debian, which was the topic of a talk at the recent MiniDebConf Winterthur 2026,
is of particular interest.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1092911/

Security updates have been issued by AlmaLinux (buildah, freerdp, gegl04, go-fdo-client, grafana, grafana-pcp, kernel, and pipewire), Debian (aom, chromium, libde265, libssh2, thunderbird, and tryton-server), Fedora (chromium, composer, cosmic-greeter, gegl04, greetd, ibus-table, jss, libheif, lightdm, lxdm, memcached, perl-DBD-Pg, plasma-login-manager, rust-webbrowser, sddm, selinux-policy, slitherer, and tkimg), Mageia (expat, mingw-expat, mbedtls, microcode, python-linkify-it-py, and tomcat), Oracle (buildah, container-tools:ol8, dbus-broker, freerdp, go-toolset:ol8, grafana-pcp, kernel, kernel-uek, nodejs24, php, and pipewire), Slackware (libpcap, libxml2, mozilla-firefox, mozilla-thunderbird, and util-linux), SUSE (bson-devel, busybox, bzip2, c-ares, cpio, cups-filters, dracut, ffmpeg-7, ffmpeg-8, file-roller, firefox, firefox-esr, glances-common, grafana, hauler, helm, helm3, java-17-openjdk, java-21-openjdk, lcms2, libcupsfilters, libheif, libmsgpack-c2, libsoup, libsoup2, libusb-1_0, libvirt, LibVNCServer, mcphost, ollama, opencode, openssl-1_1, openssl-3, php-composer2, podman, postgresql15, postgresql17, postgresql18, python, python-aiohttp, python-h2, python-sqlparse, python310, rpcbind, sssd, thunderbird, trivy, ucode-intel, and webkit2gtk3), and Ubuntu (linux, linux-aws, linux-aws-7.0, linux-gcp, linux-gke, linux-hwe-7.0, linux-realtime, linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial, linux, linux-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-raspi, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-realtime, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-gcp-7.0, linux-oem-7.0, minetest, and miniupnpd).

Asahi Linux now supports M3-series Macs

Post Syndicated from jzb original https://lwn.net/Articles/1092768/

The Asahi Linux project has announced that support
for Apple’s M3-series chips has been added to the Asahi installer.

Linux support for M3 series SoCs and the machines powered by them is now in a
state where almost everything supported on the M1 and M2 series
machines just works. This includes the webcam, internal microphones, USB (up to
the hardware limit of USB 3 10 Gb/s), hardware accelerated video decoding
including support for AV1, WiFi, Bluetooth, and much more! The
only major exceptions remain full DCP support and the GPU, which we will have
more news on in the coming
months
. Do not expect performant or power-efficient 3D acceleration
right now.

See the blog post for other current limitations of M3 support.

Grml 2026.09 released

Post Syndicated from jzb original https://lwn.net/Articles/1092660/

Version
2026.09
, code-named
“Hättiwaritätti”, of the Debian-based Grml live Linux distribution for system
administrators has been released. It is based on packages from the upcoming
Debian 14 (“forky”) release. Notable changes include an update to the Linux
7.1.8 kernel, support for booting from exfat-formatted USB devices, and an
update to GNU Screen 5.0.1.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1092659/

Security updates have been issued by Debian (chromium, firefox-esr, and pcre2), Fedora (cockpit, expat, freeipa, kbd, kernel, mrtg, python-pip, and valkey), Mageia (libopenmpt and python-gitpython), Oracle (dbus-broker, freerdp, gegl, gegl04, gimp:2.8, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, gzip, image-builder, iperf3, kernel, libssh, libxml2, microcode_ctl, nodejs:22, nodejs:24, openssl-fips-provider, pam, php:7.4, php:8.2, tar, and wget), SUSE (apache2-mod_auth_openidc, apptainer, busybox, cpio, cups-filters, curl, dracut, ffmpeg, file-roller, glibc, grafana, kubevirt, virt-pr-helper-container, lcms2, libtree-sitter0_26, libvirt, postgresql14, postgresql15, postgresql16, postgresql18, suseconnect-ng, terraform-provider-susepubliccloud, and yast2-users), and Ubuntu (FFmpeg, gnupg2, librabbitmq, libssh2, openssh, and spice-vdagent).

Audacity 4.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1092439/

Version
4.0
of the Audacity audio editor has been released. Notable changes in this
release include a rewritten interface using Qt, ability to save user-interface
layouts as “Workspaces”, improvements in working with audio clips, and a new
.aup4 project format.

The release is not fully feature-compatible with the Audacity 3.x
series; see the compatibility
notes
for a list of missing features.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1092419/

Security updates have been issued by AlmaLinux (freerdp, go-fdo-server, golang-github-openprinting-ipp-usb, kernel, kernel-rt, nodejs:24, perl-DBI, and php), Debian (firefox-esr, libapache2-mod-auth-openidc, and libass), Fedora (dracut, exiv2, firefox, freerdp, gvfs, mingw-expat, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-openexr, nss, proftpd, and syncthing), Mageia (apr-util, bubblewrap, libalsa2, libarchive, perl-Net-OAuth, perl-Text-CSV_XS, perl-XML-Bare, and perl-YAML-Syck), Oracle (freerdp, gimp, golang, iperf3, nginx:1.24, nodejs:22, nodejs:24, pipewire, wget, xmlrpc-c, and xorg-x11-server-Xwayland), SUSE (apache2-mod_auth_openidc, apptainer, apr-util, bzip2, c-ares, cosign, dhcpcd, dovecot22, emacs, erlang, gegl, gopass, gzip, httpcomponents-client, incus, kernel-devel, libgpg-error, libsoup2, mozillafirefox, mozilla-nss, mozilla-nspr,, MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen, nodejs20, orthanc, orthanc-authorization, orthanc-postgresql,, postgresql14, python-cryptography, python-msgpack, quagga, snpguest, snphost, texlive, tuxguitar, udisks2, vim, wget, and yast2-users), and Ubuntu (apr-util, biosig, linux, linux-aws, linux-azure, linux-azure-fips, linux-fips,
linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm,
linux-oracle, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux-aws-5.15, linux-gcp-5.15, linux-oracle-5.4, sssd, and tika).