All posts by jzb

[$] What’s new in APT 3.0

Post Syndicated from jzb original https://lwn.net/Articles/1017315/

Debian’s Advanced Package Tool (APT) is the suite of utilities that handle package
management on Debian and Debian-derived operating systems. APT recently received a
major upgrade to 3.0 just in time for inclusion in Debian 13
(“trixie”), which is planned for release sometime in 2025. The version bump is
warranted; the latest APT has user-interface improvements, switches to Sequoia to verify package
signatures, and includes solver3—a new solver that is designed to improve
how it evaluates and resolves package dependencies.

Catanzaro: Dangerous arbitrary file read vulnerability in Yelp

Post Syndicated from jzb original https://lwn.net/Articles/1017727/

GNOME contributor Michael Catanzaro has written a blog
post
about a noteworthy vulnerability in GNOME’s help browser, Yelp.

I don’t normally blog about particular CVEs, but Yelp CVE-2025-3155 is
noteworthy because it is quite severe, public for several weeks now,
and not yet fixed upstream. In short, help files can read your
filesystem and execute arbitrary JavaScript code, allowing an attacker
to exfiltrate any files your Unix user has access to.

The vulnerability was first reported on December 25, and it
was made public on March 26 after the 90-day-disclosure deadline
was reached. Patches
have been proposed to fix the issue. The bug reporter has published a writeup
demonstrating the attack
. Catanzaro asks that Linux vendors
please consider applying the provided patches even though they
have not yet been accepted upstream
“.

CISA extends funding to the CVE program (BleepingComputer)

Post Syndicated from jzb original https://lwn.net/Articles/1017704/

Sergiu Gatlan reports
that the US government has extended funding for the Common
Vulnerabilities and Exposures (CVE) program, following yesterday’s reports that funding
would run out as of April 16.

“The CVE Program is invaluable to cyber community and a priority of
CISA,” the U.S. cybersecurity agency told BleepingComputer. “Last
night, CISA executed the option period on the contract to ensure there
will be no lapse in critical CVE services. We appreciate our partners’
and stakeholders’ patience.”

The article also mentions the launch of a CVE Foundation, to
transition the CVE program to a dedicated foundation and eliminate
a single point of failure in the vulnerability management
ecosystem
“, as well as a European vulnerability
database
(EUVD) backed by the European Union Agency for
Cybersecurity (ENISA). Details on these initiatives are scant at the
moment, and it is unclear whether restoration of funding will have any
impact on these efforts.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1017670/

Security updates have been issued by AlmaLinux (gvisor-tap-vsock, kernel, and kernel-rt), Fedora (chromium, dnf, dotnet9.0, golang, lemonldap-ng, mariadb10.11, perl-Crypt-URandom-Token, perl-DBIx-Class-EncodedColumn, php-tcpdf, podman-tui, and trunk), Red Hat (java-17-openjdk and kernel), Slackware (mozilla), SUSE (apache2-mod_auth_openidc, cosign, etcd, expat, flannel, kernel, libsqlite3-0, libvarnishapi3, mozjs52, Multi-Linux Manager 4.3: Server, Multi-Linux Manager 5.0: Server, Proxy and Retail Server, pgadmin4, rekor, rsync, rubygem-bundler, and webkit2gtk3), and Ubuntu (7zip, Docker, and quickjs).

Fedora Linux 42 released (Fedora Magazine)

Post Syndicated from jzb original https://lwn.net/Articles/1017537/

The Fedora Project has announced
the release of Fedora Linux 42, with “what’s new” articles for Fedora Workstation
and Fedora KDE Plasma Desktop. There
is also a last-minute warning about the live media for the release:

We discovered a problem with the Live boot media at the last
minute, and since the release was already out of the airlock, we can’t
do much about it. It doesn’t damage anything, but is annoying: just
booting the Live media adds an unexpected entry to the UEFI boot
loader even when Fedora Linux 42 is not installed to the local
system.

This is primarily a concern when you are dual-booting with a
different operating system, or if you’re just running the Live image
and not intending to actually install.

See the release
notes
for more information, and LWN’s coverage of
Fedora 42.

Hardening the Firefox frontend

Post Syndicated from jzb original https://lwn.net/Articles/1016978/

Tom Schuster, Frederik Braun, and Christoph Kerschbaumer have
published an article
on the Firefox Security team’s Attack & Defense
blog that explains recent work to harden Firefox’s frontend code.

We have rewritten over 600 JavaScript event handlers to mitigate XSS
and other injection attacks in the main Firefox user interface. This
mitigation will ship in Firefox 138. However, blocking the execution
of scripts in the parent process is not the end – we will expand this
technique to other contexts in the near future. There is still more
work to do as the UI requires JavaScript APIs with a high level of
privileges. However: We still eliminated a whole class of attacks,
significantly raising the bar for attackers to exploit Firefox.

[$] Debian Project Leader election 2025 edition

Post Syndicated from jzb original https://lwn.net/Articles/1016107/

Four candidates have stepped up to run in the 2025 Debian Project
Leader
(DPL) election. Andreas
Tille
, who is in his first term as DPL, is running again. Sruthi
Chandran
, Gianfranco
Costamagna
, and Julian Andres
Klode
are the other candidates running for a chance to serve a
term as DPL. The campaigning phase ended on April 5, and Debian
members began voting on April 6. Voting ends on
April 19. This year, the campaign period has been lively and
sometimes contentious, touching on problems with Debian team
delegations and finances.

OpenSSH 10.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1016924/

OpenSSH
10.0
has been released. Support for the DSA signature algorithm,
which was disabled by default beginning in 2015, has been
removed. Other notable changes include using the post-quantum algorithm mlkem768x25519-sha256
for key agreement by default, support for systemd-style socket
activation in Portable OpenSSH, and moving code for user
authentication from the sshd-session binary to the new
ssh-auth binary:

Splitting this code into a separate binary ensures that the crucial
pre-authentication attack surface has an entirely disjoint address
space from the code used for the rest of the connection. It also
yields a small runtime memory saving as the authentication code will
be unloaded after the authentication phase completes. This change
should be largely invisible to users, though some log messages may now
come from “sshd-auth” instead of “sshd-session”. Downstream
distributors of OpenSSH will need to package the sshd-auth binary.

The release notes also warn that “software that naively matches
versions using patterns like “OpenSSH_1*”
” may be confused by the
new version number.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1016923/

Security updates have been issued by Debian (lemonldap-ng, libbssolv-perl, and phpmyadmin), Fedora (augeas, mariadb10.11, and thunderbird), Oracle (gimp, libxslt, python3.11, python3.12, tomcat, and xorg-x11-server), Red Hat (expat, grafana, opentelemetry-collector, and webkit2gtk3), SUSE (azure-cli-core, doomsday, kernel, and poppler), and Ubuntu (dotnet8, dotnet9, erlang, and poppler).

FreeDOS 1.4 released

Post Syndicated from jzb original https://lwn.net/Articles/1016849/

Version
1.4
of FreeDOS has been
released. This is the first stable release since 2022, and
includes improvements to the Fdisk hard-disk-management program, and
reliability updates for the mTCP set of TCP/IP applications for
DOS.

This version was much smoother because Jerome Shidel, our
distribution manager, had an idea after FreeDOS 1.3 that we could have
a rolling test release that collected all of the changes that people
make over time. Previous to this, each new FreeDOS distribution (like
1.0, 1.1, 1.2, and 1.3) required bundling up packages into a “release
candidate,” and we would go through several iterations of updating the
release candidates.

Jerome’s method of building the FreeDOS distribution made it easier
to automate a test release, which we decided to update every month. As
the test releases accumulated enough changes to warrant a release, we
could then make the next test release a “release candidate” which
would iterate to the next version of the FreeDOS distribution. Since
2022, we’ve released monthly test releases. Thanks Jerome!

LWN covered FreeDOS
last year for its 30th anniversary.

[$] Taking notes with Joplin

Post Syndicated from jzb original https://lwn.net/Articles/1016400/

Joplin is an open-source
note-taking application designed to handle taking many kinds of notes,
whether it is managing code snippets, writing documentation, jotting
down lecture notes, or drafting a novel. Joplin has Markdown support,
a plugin system for extensibility, and accepts multimedia content,
allowing users to attach images, videos, and audio files to their
notes. It can provide synchronization of content across devices using
end-to-end encryption, or users can opt to stick to local storage
only. Joplin even offers a command-line
version
for terminal-based usage. Joplin
3.2
, the most recent feature release, brought long-awaited
multi-window support, multi-column layouts, enhanced accessibility,
and theme detection.

[$] Catching up with calibre

Post Syndicated from jzb original https://lwn.net/Articles/1015226/

Saying that calibre is
ebook-management software undersells the application by a fair
margin. Calibre is an open-source Swiss Army knife for ebooks that can
be used for everything from creating ebooks, converting ebooks from
obscure formats to modern formats like EPUB, to serving up an ebook
library over the web. The most recent major release, calibre 8.0,
brings a better text-to-speech engine, a tool for creating audio
overlays when authoring ebooks, support for profiles in the ebook
viewer, and more.

Thunderbird plans “Thundermail” email and other services

Post Syndicated from jzb original https://lwn.net/Articles/1016219/

Ryan Sipes has announced
efforts to expand Thunderbird’s offerings with web services to
enhance the experience of using Thunderbird“.

The Why for offering these services is simple. Thunderbird loses users
each day to rich ecosystems that are both clients and services, such
as Gmail and Office365. These ecosystems have both hard vendor
lock-ins (through interoperability issues with 3rd-pary clients) and
soft lock-ins (through convenience and integration between their
clients and services). It is our goal to eventually have a similar
offering so that a 100% open source, freedom-respecting alternative
ecosystem is available for those who want it.

The planned services include hosted email, appointment scheduling,
a revival of Firefox Send,
and (of course) an AI assistant based on a partnership with Flower AI. The AI features will
always be optional for use by people who want them“. Sipes is
managing director of product for Thunderbird’s parent organization, MZLA
Technologies Corporation
. LWN covered his
GUADEC 2024 keynote last July.

Introducing Fedora Project Leader Jef Spaleta

Post Syndicated from jzb original https://lwn.net/Articles/1016217/

Outgoing Fedora Project Leader (FPL) Matthew Miller has announced
his successor, Jef Spaleta.

Some of you may remember Jef’s passionate voice in the early Fedora
community. He got involved all the way back in the days of fedora.us,
before Red Hat got involved. Jef served on the Fedora Board from July
2007 through the end of 2008. This was the critical time after Fedora
Extras and Fedora Core merged into one Fedora Linux where, with the
launch of the “Features” process, Fedora became a truly community-led
project.

Spaleta will be joining Red Hat full time in May and Miller will be
formally handing off FPL duties at the Flock conference in
June.

PorteuX 2.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1016216/

Version
2.0
of PorteuX, a distribution based on Slackware Linux, has been
released. This release adds the ability to test experimental Wayland
sessions for the Cinnamon, LXQt, and Xfce desktops. PorteuX 2.0
updates the Linux kernel to 6.14 and includes many package updates and
bug fixes. Users have the choice of PorteuX stable or its rolling release
called current. See the install.txt
for instructions on installing PorteuX to disk.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1016205/

Security updates have been issued by Debian (firefox-esr, jetty9, openjpeg2, and tomcat9), Fedora (dokuwiki, firefox, php-kissifrot-php-ixr, php-phpseclib3, and rust-zincati), Red Hat (kernel and pki-core), Slackware (mozilla), SUSE (apparmor, atop, docker, docker-stable, firefox, govulncheck-vulndb, libmodsecurity3, openvpn, upx, and warewulf4), and Ubuntu (inspircd, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-ibm,
linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oem-6.8, linux-oracle,
linux-oracle-6.8, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure-6.8, linux-hwe-6.8, linux-raspi, linux-realtime, nginx, phpseclib, and vim).