All posts by jzb

[$] Fedora prepares for the end of AF_ALG

Post Syndicated from jzb original https://lwn.net/Articles/1088489/

The Linux kernel’s user-space interface
(AF_ALG)
to the Crypto
API
has been linked to a number of recent high-profile security problems,
including Copy Fail and successor
vulnerabilities. It was deprecated
earlier this year. Eric Biggers, and other kernel developers,
have been working to remove it
from the kernel
. With that in mind, the Fedora Project is planning to
restrict use of AF_ALG in the next Fedora release in the hopes of nudging
remaining users of the API to prepare for its eventual removal.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1089338/

Security updates have been issued by AlmaLinux (.NET 8.0, 389-ds:1.4, bind, haproxy, kernel, kernel-rt, libXfont2, nghttp2, and unbound), Debian (calibre, expat, ironic, and linux-6.12), Fedora (coturn, linux-firmware, php-phpseclib, and sqlite), Red Hat (fence-agents, osbuild-composer, pam, resource-agents, and sg3_utils), SUSE (ffmpeg, jetty-minimal, open-iscsi, python, python313-h2, python313-pysaml2, redis, redis7, rsync, sccache, texlive, and wasm-bindgen), and Ubuntu (engrampa, linux-aws-7.0, and linux-azure-fde-5.15).

Mark J. Wielaard receives Distinguished Service Award in Software Freedom

Post Syndicated from jzb original https://lwn.net/Articles/1089208/

The Software Freedom
Conservancy
has announced
that Mark J. Wielaard has been honored with the second annual
Distinguished Service Award in Software Freedom for his many years of
service to software freedom.

Mark is one of many key FOSS developers who has designed his career so
that his employers have funded much of his FOSS work. Nevertheless,
Mark continues his volunteer work after hours as a key contributor who
maintains Sourceware — the
oldest FOSS collaboration and developer infrastructure hosting site in
history.

In addition to his work on Sourceware, Wielaard is a member of the DWARF Debugging Standard Committee,
the maintainer for Valgrind and elfutils, as well as a contributor to
various other GNU projects.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1089205/

Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, bind, dracut, freerdp, gnome-remote-desktop, kernel, and nghttp2), Debian (apr-util, docker.io, ironic, neutron, postgresql-15, unzip, and util-linux), Fedora (chromium, jfrog-cli, jrnl, libgsasl, libsoup3, pdns, pdns-recursor, perl-Archive-Tar, php-pear-PHP-CodeSniffer, rust-bat, rust-git-delta, rust-git-interactive-rebase-tool, rust-lsd, rust-pretty-git-prompt, rust-tokei, and stunnel), Gentoo (haveged, HTTP-Daemon, nginx, NTFS-3G, Portage, PostgreSQL, and X.Org X server, XWayland), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, dhcpcd, dracut, grafana, iscsi-initiator-utils, kernel, nodejs:24, openssh, osbuild-composer, python-idna, ruby, and ruby4.0), Slackware (proftpd), and SUSE (7zip, afterburn, ansible-lint, bouncycastle, cargo-audit, cargo-c, chromedriver, chromium, containerized-data-importer, dnsdist, dracut-112, ffmpeg-9-libavcodec-devel, firefox, freetype2, git-cliff, glib2, go1.25, go1.26, google-guest-agent, google-osconfig-agent, gzip, himmelblau, java-1_8_0-openjdk, kernel, kernel-devel, kubeshark-cli, kubevirt1.9-continer-disk, libkrun, libXfont2, molecule, net-tools, nginx, nodejs22, nodejs24, open-iscsi, perl, pgadmin4, php-composer2, php8, python-httplib2, python-sh, python-ujson, python3-ansible-compat, python313-nltk, rrdtool, rsyslog, samba, spice-vdagent, sssd, webkit2gtk3, wireshark, and wpa_supplicant).

Python packaging council candidates announced

Post Syndicated from jzb original https://lwn.net/Articles/1088920/

The Python Software Foundation (PSF) has announced
the candidates
running for the Python packaging council that was approved by the Python steering council
in April
.

This inaugural election fills all five seats on the PPC. The two candidates
receiving the highest number of votes shall be designated Cohort A with a two
year term, and the three candidates receiving the next highest number of votes
shall be designated Cohort B with a one year term.

In future elections, each cohort will be elected for a full two-year term in
alternating years, so that roughly half of the PPC turns over each cycle.

There are 17 candidates running for the five open seats. PSF voting-eligible
members must affirm
their intention to vote
in this election by August 25. Voting begins on
September 1, and ends on September 15.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1088919/

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, bind, bind9.16, and dracut), Debian (apr-util, chromium, postgresql-17, python-httplib2, unzip, and zip), Fedora (erlang-cowboy, erlang-cowlib, flatpak, and libnfs), Gentoo (Apache HTTPD, Bubblewrap, Dnsmasq, Exim, Flatpak, libinput, and rsync), Mageia (dhcpcd, qemu, and roundcubemail), Oracle (.NET 8.0, .NET 9.0, bind, bind9.16, freerdp, glib2, gnome-remote-desktop, grafana, gstreamer1-plugins-good, isns-utils, java-17-openjdk, kernel, libpng, libXfont2, nghttp2, perl-DBI:1.641, python-idna, python3.9, and xorg-x11-server), Slackware (rsync), SUSE (bouncycastle, chromium, dnsdist, dracut, java-1_8_0-ibm, kernel, libXfont2, nodejs22, nodejs24, php8, python-httplib2, rrdtool, rsyslog, samba, and wireshark), and Ubuntu (linux, linux-aws, linux-kvm, linux-aws-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-azure, linux-gcp, linux-hwe, linux-oracle, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia-tegra,
linux-oracle, linux-nvidia-tegra-igx, linux-oem-7.0, linux-oracle, and node-axios).

rsync 3.5.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1088759/

Version
3.5.0
of rsync has been released with a huge
number of security fixes
:

This release fixes 33 security issues found during a focused audit of
rsync’s path handling and daemon protocol, a companion daemon-protocol
fuzzing pass, and reports from external researchers -⁠-⁠ plus several
robustness hardenings. CVE IDs were assigned by VulnCheck (CNA); the
precise “introduced in” version ranges accompany each advisory, and
many are much narrower than “everything before 3.5.0”. Every fix ships
with a regression test in the test suite that fails on the unfixed
tree.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1088715/

Security updates have been issued by AlmaLinux (abrt, dhcpcd, edk2, freerdp, gegl04, grafana, gstreamer1-plugins-good, iscsi-initiator-utils, isns-utils, kernel, kernel-rt, keylime, libarchive, libyang, nodejs-nodemon, opencryptoki, osbuild-composer, pacemaker, postgresql-jdbc, postgresql18, python-idna, python3.9, udisks2, valkey, vim, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), Debian (flatpak, lemonldap-ng, neutron, python-django, spip, xdg-dbus-proxy, and xorg-server), Fedora (apr-util, cri-o1.34, libcupsfilters, linux-firmware, sqlite, and vaultwarden), Gentoo (FreeType), Oracle (dovecot, evince, fence-agents, gnutls, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, isns-utils, java-1.8.0-openjdk, kernel, libarchive, osbuild-composer, pipewire, postgresql, ruby, ruby:3.3, sudo, and udisks2), Red Hat (bind, bind9.16, gnome-remote-desktop, grafana, opentelemetry-collector, python-pillow, python3, python3.12, python3.14, python3.9, and rhc), SUSE (chromium, clusterctl, dracut, gd, git-cliff, gleam, govulncheck-vulndb, graphicsmagick, gzip, kernel, kubevirt, libheif, librest0_7, nodejs22, nodejs24, openssh, openvpn, python3, python313-scikit-learn, rpm, stunnel, and zk), and Ubuntu (kernel, libgit2, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-6.8,
linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-fips,
linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gke, linux-gkeop,
linux-ibm, linux-ibm-6.8, linux-nvidia, linux-nvidia-6.8,
linux-nvidia-lowlatency, linux-realtime, linux-realtime-6.8, linux-xilinx, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-fde,
linux-azure-fips, linux-gkeop, linux-ibm, linux-ibm-5.15,
linux-intel-iot-realtime, linux-intel-iotg, linux-intel-iotg-5.15,
linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15,
linux-oracle-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-fips, linux-azure-4.15, linux-azure-fips,
linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux, linux-aws, linux-azure, linux-azure-fde, linux-ibm, linux-oracle,
linux-raspi, linux-realtime, linux-azure, linux-azure-6.17, linux-gcp-6.17, linux-hwe-6.17, linux-oem-6.17,
linux-realtime-6.17, node-follow-redirects, and yelp).

[$] LWN.net Weekly Edition for August 13, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1087432/

Inside this week’s LWN.net Weekly Edition:

  • Front: BPF and binfmt_misc; CrossPoint ebook firmware; KVM planes; BPF formal verification; shadow-utils; new storage-code testing features.
  • Briefs: Django releases; GNOME shell; LightDM 1.33.0; QEMU 11.1; uutils 0.10; Software Stewardship Lab; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] A look at CrossPoint e-reader firmware

Post Syndicated from jzb original https://lwn.net/Articles/1087635/

There are a number of small,
inexpensive, low-powered e-reader or e-paper devices
that have promise as
ebook readers with one minor problem: the firmware they ship with does not
realize their full potential. To solve that problem, the CrossPoint Reader project looks to
provide replacement firmware that offers necessary features, better performance,
and a more pleasant reading experience. On August 7, the project released version
1.5.0
, which opens large EPUBs more quickly, provides
offline dictionary lookups, and has reworked settings for changing layout and
font options. The release also improves support for right-to-left text as well
as Chinese, Japanese, and
Korean
(CJK) text rendering.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1088476/

Security updates have been issued by AlmaLinux (fence-agents, firefox, frr10, gstreamer1-plugins-good, iscsi-initiator-utils, isns-utils, kernel, kernel-rt, perl-DBI:1.641, postgresql, postgresql:12, and resource-agents), Debian (libgd2, openjdk-25, php7.4, php8.2, and postfix), Fedora (clamav, domoticz, and libidn), Red Hat (delve, edk2, firefox, go-fdo-client, go-fdo-server, grafana, host-metering, ignition, kernel, kernel package, kernel-rt, ldns, libarchive, mariadb10.11, mariadb:10.11, multiple packages, rhc, rhc-worker-playbook, rhc-worker-script, sssd, thunderbird, yggdrasil, and yggdrasil-worker-package-manager), Slackware (expat and openssh), and SUSE (avahi, chromedriver, erlang26, gawk, glib2, go-sendxmpp, google-guest-agent, google-osconfig-agent, gpg2, gstreamer-plugins-bad, gstreamer-plugins-base, helm, ignition, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-openj9, java-21-openj9, java-25-openj9, libarchive, libkrun, libpcp-devel, libpng16, libssh, libssh2_org, multipath-tools, net-tools, nmap, openssl-1_1, openssl-3, pcp, perl, python-pip, python-pyasn1, python-urllib3, python3-pip, python313-Django5, runc, samba, snpguest, spice-vdagent, sssd, unbound, wget, wild, wpa_supplicant, xmlrpc-c, and zpaqfranz).

Bernard: GNOME Shell design dreams

Post Syndicated from jzb original https://lwn.net/Articles/1088238/

GNOME contributor Tobias Bernard has published
a blog post
that details some of the design team’s ideas for the
GNOME Shell over the long term:

Some of these we have relatively complete plans for, others are
more vague ideas that need more research and prototyping. As always,
getting things like these implemented depends on developer capacity
and interest (and sometimes funding).

While each of these ideas may require additional discussion,
prototyping, and testing, we (the design team) have collected them all
together here to share our longer-term vision and to give each idea
more visibility.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1088226/

Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ffmpeg-4, freerdp, gd, gitoxide, kak-lsp, kernel-devel, librest-1_0-0, libsdb2_5_0, libssh2_org, nodejs22, PackageKit, perl, perl-Date-Manip, python-ujson, python3-sqlparse, python311, python312, python313-pymongo, ruby2.5, runc, suseconnect-ng, thunderbird, vlang, webkit2gtk3, and weechat), and Ubuntu (imagemagick and systemd).

Django moves to an annual release cycle

Post Syndicated from jzb original https://lwn.net/Articles/1088059/

The Django Python web-framework
project has announced
that it has accepted an annual
release cycle proposal
. This means that the project is moving from a somewhat
complicated schedule
that interspersed short-lived feature releases and
long-term-support (LTS) releases to a simpler annual cycle where each release is
supported for three years.

Every feature release gets three years of support: one year of mainstream
bugfixes, then two years of security and data-loss fixes. The “LTS” label is
retired — every feature release now carries that same, unique commitment.

No more LTS gap: no racing a deadline to jump two years of changes at
once. Upgrade one year at a time, whenever suits you within the support
window. Three versions are supported at any time, giving third-party packages a
clear, rolling target.

This will take effect with the upcoming Django 2028 release, expected in
January 2028.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1088057/

Security updates have been issued by AlmaLinux (firefox, gpsd-minimal, kernel, libarchive, libgcrypt, and LibRaw), Debian (bind9, ca-certificates, chromium, dnsdist, icinga2, kitty, libheif, openjdk-21, pdns, pdns-recursor, thunderbird, and xen), Fedora (bird, erlang, kernel, mingw-glib2, nghttp2, p11-kit, perl, perl-Devel-Cover, perl-PAR-Packer, pgadmin4, polymake, python-nh3, python-wsgidav, python3.12, rabbitmq-server, rust-ammonia, seamonkey, and udisks2), Mageia (python-starlette), Oracle (gnutls, kernel, and LibRaw), Red Hat (container-tools:rhel8), Slackware (wpa_supplicant), and SUSE (azure-storage-azcopy, bouncycastle, ffmpeg-4, fuse-overlayfs, gleam, gstreamer-plugins-bad, libssh2-1, libssh2_org, libwireshark19, libXfont2-2, perl-Mojo-JWT, perl-Mojolicious, podman, python310, python313-Django4, and tekton-cli).

[$] Changes in shadow-utils password-expiration features

Post Syndicated from jzb original https://lwn.net/Articles/1086949/

The shadow-utils
project provides the tools that handle /etc/shadow,
/etc/passwd, and other related databases; in
general, manages users and groups on many Linux systems. While most
software releases are notable for what is added, the recent shadow-utils 4.20.0
release is most noteworthy for what has been removed. Specifically,
several utilities and functionality related to periodic password
expiry, which were deprecated in the December 2025 4.19.0
release, have been removed as planned. It is still possible to manage
some aspects of password aging with shadow-utils, but organizations
that depend on such features should start planning for their complete
removal within a few years.

LightDM lives: version 1.33.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1087759/

Version
1.33.0
of the LightDM
display manager has been released. This is the first
release in four years
: the project had been sponsored by Canonical
but was effectively
unmaintained
in recent years. It has been transferred
to a new community repository
and is now maintained by Joshua
Peisach and Neal Gompa.

The new release includes Qt6 support, code optimizations, and a
list of other fixes that had been in limbo pending a new release.

Stable kernel releases for Friday with a single bug fix

Post Syndicated from jzb original https://lwn.net/Articles/1087743/

Greg Kroah-Hartman has announced the release of the 6.12.102, 6.6.150, 6.1.182, 5.15.215, 5.10.264 stable kernels. This round of
stable kernel releases contains a fix for a single bug, found
by Thomas Lamprecht
, that affected several of the kernels released yesterday in
response to a security
vulnerability
(CVE-2026-68480)
that could allow data leakage through speculative execution.

The 6.12.102 release adds the backported security fix for CVE-2026-68480 to the 6.12
series. As always, users are advised to upgrade.