All posts by jzb

[$] The mystery of the Mailman 2 CVEs

Post Syndicated from jzb original https://lwn.net/Articles/1019149/

Many eyebrows were raised recently when three vulnerabilities were announced
that allegedly impact GNU Mailman 2.1,
since many folks assumed that it was no longer being supported. That’s
not quite the case. Even though version 3 of
the GNU Mailman mailing-list manager has been available
since 2015, and version 2 was declared (mostly) end of life
(EOL) in 2020, there are still plenty of users and projects still
using version 2.1.x. There is, as it turns out, a big difference between
mostly EOL and actually EOL. For example: WebPros, the company behind the cPanel server and web-site-management
platform, still maintains a port of
Mailman 2.1.x
to Python 3 for its customers and was
quick to respond to reports of vulnerabilities. However, the
company and upstream Mailman project dispute that the CVEs are
valid.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1019457/

Security updates have been issued by Debian (glibc and libraw), Fedora (digikam, icecat, mingw-LibRaw, perl, perl-Devel-Cover, and perl-PAR-Packer), Red Hat (ghostscript, kernel, and kernel-rt), Slackware (mozilla), SUSE (augeas, firefox, and java-11-openjdk), and Ubuntu (binutils, libxml2, and nodejs).

OSI publishes election retrospective

Post Syndicated from jzb original https://lwn.net/Articles/1019215/

The Open Source Initiative (OSI) has quietly published
“takeaways” from its internal retrospective on the recent board
of directors election as an update
to the March blog
post
that announced the new members of the board. The election was
controversial, in part, due to poor communication and OSI changing the
election rules and disqualifying several candidates after the election
finished. LWN covered
the election and results in March. The update commits to improvements
in communication and candidate selection:

What this election exposed was the need for the organization to also
assess whether candidates were fully eligible to run and prepared to
be seated on the board before voting begins. This is something we will
add to the election timeline next year. While we have not finished
figuring out all of the requirements for that assessment, part of it
will be asking candidates to sign a Candidate Agreement at nomination
time. We also have some ideas on ways for potential candidates to have
more information even before submitting a nomination.

In a related note, there is a petition
asking OSI to publish the “complete, unaltered” results of the
board of directors election. Thanks to Josh Triplett for the tip on
the petition.

[$] Debian debates AI models and the DFSG

Post Syndicated from jzb original https://lwn.net/Articles/1018497/

The Debian project is discussing a General Resolution (GR) that
would, if approved, clarify that AI models must include training data
to be compliant with the Debian
Free Software Guidelines
(DFSG) and be distributed by Debian as
free software. While GR discussions are sometimes contentious, the
discussion around the proposal from Debian developer Mo Zhou has
been anything but—there seems to be
consensus that AI models are not DFSG-compliant if they lack training
data. There are, however, some questions about the exact language and
questions about the impact the GR will have on existing packages in
the Debian archive.

[$] Addressing UID/GID drift in rpm-ostree and bootc

Post Syndicated from jzb original https://lwn.net/Articles/1018082/

The Fedora Project is looking for solutions to an interesting
problem with its image-based editions and spins, such as the Atomic Desktops
or CoreOS, that are
created with rpm-ostree or bootc. If a package that
is part of a image-based version has a user or group created
dynamically on installation, and it owns files installed on the
system, the system may be subject to user ID (UID) and group ID (GID) “drift”
on updates. This “UID/GID drift” may come about when a new image with
updates is generated, and therefore files may have the wrong
ownership. This can have side-effects ranging from mildly inconvenient to
serious. No solutions have been adopted just yet, but there are a few
ideas on how to deal with the problem.

NLnet announces funding for 42 FOSS projects

Post Syndicated from jzb original https://lwn.net/Articles/1018621/

The NLnet Foundation has announced
the projects that have received funding from its October call
for grant proposals from the Next
Generation Internet (NGI) Zero Commons Fund
.

The selected projects all contribute, one way or another, to the
mission of the Commons Fund: reclaiming the public nature of the
internet. For example, there are people working on interesting open
hardware projects such as the tablet MNT Reform Touch
and the Solar
FemtoTX motherboard
— a collaborative effort to create an
ultra-low power motherboard that can run on solar power. LLM2FPGA aims to enable
running open source LLMs locally on programmable chips (“FPGAs”) using
a fully open-source toolchain. bcachefs
readies itself as the next generation filesystem for Linux, improving
performance, scalability and reliability when compared to legacy
filesystems.

In all, 42 projects have been selected for the NGI grants which are
between €5,000 and €50,000. See the announcement for the
full list of selected projects, and the current projects page
for other recent projects funded by NLnet.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1018589/

Security updates have been issued by AlmaLinux (bluez, expat, and postgresql:12), Fedora (chromium, golang, LibRaw, moodle, openiked, ruby, and trafficserver), Red Hat (bluez, expat, gnutls, libtasn1, libxslt, mod_auth_openidc, mod_auth_openidc:2.3, ruby:3.1, thunderbird, and xmlrpc-c), and Ubuntu (linux, linux-aws, linux-gcp, linux-hwe-6.11, linux-lowlatency, linux-lowlatency-hwe-6.11, linux-oem-6.11, linux-oracle, linux-raspi, linux-realtime, linux-azure, linux-azure-6.11, linux-gcp-6.8, and matrix-synapse).

RISC-V images for Fedora Linux 42

Post Syndicated from jzb original https://lwn.net/Articles/1018322/

The Fedora Project’s RISC-V
special-interest group
(SIG) has announced
the availability of Fedora Linux 42 images for supported
RISC-V boards
, as well as QEMU
and container images. The SIG is working toward making RISC-V a
primary architecture for Fedora, and has made significant progress in
the past year.

Our upstreaming work continues apace, and we want to acknowledge
that none of this progress would be possible without the incredible
collaboration from maintainers across the Fedora Project and
beyond. Thank you to everyone who reviewed, accepted, merged, and
built our patches. Your support makes this architecture possible.

We’re also excited about just how many packages build cleanly
without special treatment or overlay repositories that need to be
cared for. RISC-V is becoming just another architecture, and that’s
exactly how it should be.

[$] Owen Le Blanc: creator of the first Linux distribution

Post Syndicated from jzb original https://lwn.net/Articles/1017846/

Ask a Linux enthusiast who created the Linux kernel, and odds are they will have
no trouble naming Linus Torvalds—but many would be stumped if asked what the
first Linux distribution was, and who created it. Some might guess Slackware, or its predecessor, Softlanding Linux
System
(SLS); both were arguably more influential but arrived just a bit
later. The first honest-to-goodness distribution with a proper installer was MCC Interim Linux,
created by Owen Le Blanc, released publicly in early 1992. I recently
reached out to Le Blanc to learn more about his work on the distribution, what
he has been doing since, and his thoughts on Linux in 2025.

Tor Browser 14.5 released

Post Syndicated from jzb original https://lwn.net/Articles/1017923/

Version
14.5
of the Tor
Browser
has been released. Notable features in this release
include the addition of Connection Assist for the Android version of
the Tor Browser, and language support for Belarusian, Bulgarian, and
Portuguese for all versions of the browser.

Should Tor Browser fail to establish a direct connection to the Tor
network, Connection Assist will offer to find and try bridges for
you. But before this feature could be made available on Android, we
had to embark on a multi-year effort to refactor our tor integration
across each platform first. This project has now reached an important
milestone, and we’re proud to announce the release of Connection
Assist for Android today.

See the full
changelog
for all changes in this release, and the issues
page
for known problems.

[$] What’s new in APT 3.0

Post Syndicated from jzb original https://lwn.net/Articles/1017315/

Debian’s Advanced Package Tool (APT) is the suite of utilities that handle package
management on Debian and Debian-derived operating systems. APT recently received a
major upgrade to 3.0 just in time for inclusion in Debian 13
(“trixie”), which is planned for release sometime in 2025. The version bump is
warranted; the latest APT has user-interface improvements, switches to Sequoia to verify package
signatures, and includes solver3—a new solver that is designed to improve
how it evaluates and resolves package dependencies.

Catanzaro: Dangerous arbitrary file read vulnerability in Yelp

Post Syndicated from jzb original https://lwn.net/Articles/1017727/

GNOME contributor Michael Catanzaro has written a blog
post
about a noteworthy vulnerability in GNOME’s help browser, Yelp.

I don’t normally blog about particular CVEs, but Yelp CVE-2025-3155 is
noteworthy because it is quite severe, public for several weeks now,
and not yet fixed upstream. In short, help files can read your
filesystem and execute arbitrary JavaScript code, allowing an attacker
to exfiltrate any files your Unix user has access to.

The vulnerability was first reported on December 25, and it
was made public on March 26 after the 90-day-disclosure deadline
was reached. Patches
have been proposed to fix the issue. The bug reporter has published a writeup
demonstrating the attack
. Catanzaro asks that Linux vendors
“please consider applying the provided patches even though they
have not yet been accepted upstream
“.

CISA extends funding to the CVE program (BleepingComputer)

Post Syndicated from jzb original https://lwn.net/Articles/1017704/

Sergiu Gatlan reports
that the US government has extended funding for the Common
Vulnerabilities and Exposures (CVE) program, following yesterday’s reports that funding
would run out as of April 16.

“The CVE Program is invaluable to cyber community and a priority of
CISA,” the U.S. cybersecurity agency told BleepingComputer. “Last
night, CISA executed the option period on the contract to ensure there
will be no lapse in critical CVE services. We appreciate our partners’
and stakeholders’ patience.”

The article also mentions the launch of a CVE Foundation, to
transition the CVE program to a dedicated foundation and eliminate
“a single point of failure in the vulnerability management
ecosystem
“, as well as a European vulnerability
database
(EUVD) backed by the European Union Agency for
Cybersecurity (ENISA). Details on these initiatives are scant at the
moment, and it is unclear whether restoration of funding will have any
impact on these efforts.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1017670/

Security updates have been issued by AlmaLinux (gvisor-tap-vsock, kernel, and kernel-rt), Fedora (chromium, dnf, dotnet9.0, golang, lemonldap-ng, mariadb10.11, perl-Crypt-URandom-Token, perl-DBIx-Class-EncodedColumn, php-tcpdf, podman-tui, and trunk), Red Hat (java-17-openjdk and kernel), Slackware (mozilla), SUSE (apache2-mod_auth_openidc, cosign, etcd, expat, flannel, kernel, libsqlite3-0, libvarnishapi3, mozjs52, Multi-Linux Manager 4.3: Server, Multi-Linux Manager 5.0: Server, Proxy and Retail Server, pgadmin4, rekor, rsync, rubygem-bundler, and webkit2gtk3), and Ubuntu (7zip, Docker, and quickjs).

Fedora Linux 42 released (Fedora Magazine)

Post Syndicated from jzb original https://lwn.net/Articles/1017537/

The Fedora Project has announced
the release of Fedora Linux 42, with “what’s new” articles for Fedora Workstation
and Fedora KDE Plasma Desktop. There
is also a last-minute warning about the live media for the release:

We discovered a problem with the Live boot media at the last
minute, and since the release was already out of the airlock, we can’t
do much about it. It doesn’t damage anything, but is annoying: just
booting the Live media adds an unexpected entry to the UEFI boot
loader even when Fedora Linux 42 is not installed to the local
system.

This is primarily a concern when you are dual-booting with a
different operating system, or if you’re just running the Live image
and not intending to actually install.

See the release
notes
for more information, and LWN’s coverage of
Fedora 42.