All posts by jzb

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1087742/

Security updates have been issued by AlmaLinux (compat-libtiff3, fence-agents, firefox, freerdp, frr, gimp, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, kernel-rt, ldns, libgcrypt, libXfont2, nodejs:22, nodejs:24, p11-kit, pipewire, resource-agents, sg3_utils, thunderbird, and yelp), Debian (async-http-client, jq, kernel, linux-6.1, linux-6.12, redis, and udisks2), Fedora (abrt, chromium, coreutils, curl, freeipa, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, ImageMagick, kernel, libXfont2, php, python-gstreamer1, samba, tcpreplay, and trafficserver), Mageia (firefox, nss, rootcerts, python-django, and thunderbird), Oracle (freerdp, gimp, gpsd, kernel, kernel-uek, and osbuild-composer), Red Hat (buildah and container-tools:rhel8), Slackware (libXfont2 and p11-kit), and SUSE (amazon-ecs-init, azure-storage-azcopy, bind, bouncycastle, cockpit-repos, cockpit-subscriptions, dnsdist, ffmpeg-4, hawk-apiserver, nodejs22, nodejs24, OpenImageIO, openssl-1_1, openssl-3, perl-Mojo-JWT, php8, rsyslog, sssd, and wireshark).

Rust Coreutils 0.10 released

Post Syndicated from jzb original https://lwn.net/Articles/1087490/

Version
0.10
of the uutils project’s Rust Coreutils has been released. This
release focused on compatibility with the GNU Core Utilities suite,
with Rust Coreutils now passing 645 of 690 tests, up from 625 with version 0.9.0. Notable
changes in this release include addition of the mv --exchange
option, an OpenSSL backend for checksum utilities, applying SELinux labels at
creation when using mkdir, mkfifo, and mknod, as well
as a number of performance and security improvements.

The project has an
online playground that runs the
Rust Coreutils directly in the browser via WebAssembly for those who would like
to try the utilities without installing them. LWN covered the uutils project in
February 2025.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1087489/

Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).

[$] LWN.net Weekly Edition for August 6, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1086134/

Inside this week’s LWN.net Weekly Edition:

  • Front: Process-builder API; Fedora COI; FUSE io_uring buffer sizes; BPF network namespaces; FUSE plans; BPF libraries; directory creation system call.
  • Briefs: AISI hack; JFrog on CVEs; npm worm; AUR adoption; NetBSD 11.0; b4 0.16.0; C-Kermit 11; Rust LLM policy; Servo 0.4.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1087318/

Security updates have been issued by AlmaLinux (fence-agents, gstreamer1-plugins-good, kernel, kernel-rt, p11-kit, perl-Archive-Tar, perl-DBI, and thunderbird), Debian (aom, botan3, and kernel), Fedora (abrt, coreutils, doctl, kernel, open62541, perl, perl-Devel-Cover, perl-PAR-Packer, and polymake), Mageia (acl and php), Oracle (firefox, frr, kernel, libreswan, nodejs-nodemon, nodejs22, perl-Archive-Tar, php:7.4, php:8.2, rsync, and thunderbird), Red Hat (compat-libtiff3, libpq, libtiff, postgresql, postgresql16, postgresql18, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and postgresql:18), Slackware (stunnel), and SUSE (alloy, alsa, bind, chromedriver, corepack24, ffmpeg-4, golang-github-prometheus-prometheus, google-guest-agent, google-osconfig-agent, kubevirt, libgcrypt, libpng16, multipath-tools, netty, netty-tcnative, nodejs26, openssl-1_1, openssl-3, perl-HTTP-Tiny, perl-YAML-Syck, podman, python-sh, python-ujson, rsyslog, spice-vdagent, thrift, valkey, wpa_supplicant, and xen).

[$] Fedora considers conflict-of-interest policy

Post Syndicated from jzb original https://lwn.net/Articles/1086488/

The Fedora
Council
is considering
a conflict-of-interest (COI) policy for its decision-making bodies,
such as the Fedora Engineering
Steering Committee
(FESCo), special-interest groups (SIGs), and
any other groups or individuals that report to the council and
are responsible for decisions that impact the Fedora project. The
current draft does not, however, apply to the council itself. The public
discussion
for the COI policy began on July 23 and seems to be
nearing completion, with the council set to discuss the topic again
during its meeting on August 13.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1087068/

Security updates have been issued by AlmaLinux (frr, ldns, mingw-glib2, and perl-Archive-Tar), Debian (ruby2.7), Fedora (borgbackup, nebula, python-nh3, rust-ammonia, and seamonkey), Mageia (librabbitmq, libvncserver, packages, perl, perl-GD, perl-Unicode-LineBreak, squid, and unbound), Oracle (compat-libtiff3, frr, gstreamer1-plugins-good, javapackages-tools:201801, libreswan, nodejs:22, nodejs:24, p11-kit, perl-Archive-Tar, perl-DBI, php, pki-deps:10.6, and python-tornado), and SUSE (aws-iam-authenticator, bind, containerd, gawk, google-cloud-sap-agent, ignition, ImageMagick, java-11-openjdk, libpng16, libssh, mcphost, nginx, openssh, openssl-1_1, perl-DBI, perl-HTTP-Date, perl-Net-DNS, python-urwid, python3-dulwich, python312, python313, python3, python313-pydantic, python313-sentry-sdk, rrdtool, s390-tools, samba, spice-vdagent, vim, and xen).

Twenty years of Pandoc

Post Syndicated from jzb original https://lwn.net/Articles/1086976/

John MacFarlane has published a lengthy
retrospective
to commemorate twenty years of the Pandoc document converter.

On August 3, 2006, I uploaded the first version of pandoc to my
website, releasing it under the free GPL license. Pandoc 0.1 consisted
of about 3000 lines of Haskell code, with no dependencies aside from
GHC’s standard library. It could convert Markdown, reStructuredText,
HTML, and LaTeX documents into any of these formats, plus RTF or S5. I
had no idea at the time that this would just be the first of over two
hundred releases over the next twenty years; that the project would
become the most
popular program written in Haskell
; that I would spend countless
hours on bug-fixes, improvement, and project management; that I would
collaborate with programmers in many other countries; that pandoc
would come to support over fifty document formats; that it would allow
automatic generation of citations and bibliographies; that it would
become integrated into academic writing tools like Quarto and Jupyter Notebook; that it would be
installed on millions of computers around the world.

How did this happen? I want to take advantage of pandoc’s birthday
to tell the story of the project, as best I can remember it.

NetBSD 11.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1086898/

The release of NetBSD 11.0, the 19th major version of the operating
system, has been announced. There are
many changes and enhancements since the 10.1 release, including a new
port to RISC-V, better support for Linux system calls in compat_linux(),
as well as improvements to the NPF
firewall.

As you are probably aware, the number of security issues found or
suspected everywhere has massively increased with the advent of AI
tools. As a consequence, we can’t publish a release without open
issues. Instead of delaying the release further to fix them (new ones
are being reported all the time), we’ve instead chosen to be
transparent about this.

See the full release
notes
for links to the binary distributions and links to the full
change logs.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1086897/

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, kernel, kernel-rt, openssh, osbuild-composer, perl-Archive-Tar, perl-DBI, perl:5.32, pipewire, python-pillow, qemu-kvm, unbound, and vim), Debian (chromium, incus, kernel, kissfft, libgd2, libmodbus, libssh, node-tar, php8.4, poppler, python-authlib, sslh, and starlette), Fedora (borgbackup, coturn, curl, exim, fuse-overlayfs, gh, GitPython, goaccess, lemonldap-ng, libgit2, nextcloud, nsd, php, postgresql16, python3.12, rabbitmq-server, rust-libgit2-sys, and xen), Mageia (bluez, firmware, kernel, kmod, wireless-regdb), Oracle (buildah, compat-libtiff3, dovecot, fence-agents, firefox, gimp, glibc, grafana, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, libgcrypt, libtiff, libXfont2, nodejs24, nodejs:22, nodejs:24, openssh, openssl, PackageKit, pipewire, python-pillow, rest, sssd, vim, and yelp), SUSE (bind, chromium, dnsdist, gdk-pixbuf-loader-libheif, gio-branding-upstream, google-guest-agent, govulncheck-vulndb, GraphicsMagick, ignition, ImageMagick, keybase-client, kronosnet, libblkid-devel, libntpc1, libpng16, nano, openssh, openssl-1_0_0, openssl-3, openvpn, PackageKit, perl-mojolicious, php8, python-nltk, python313-asteval, python313-certifi, python313-GitPython, python313-huggingface-hub, rsyslog, tomcat, tomcat10, tomcat11, traefik2, valkey, warewulf4, webkit2gtk3, and yq), and Ubuntu (linux-intel-iotg).

Arch Linux disables AUR package adoption

Post Syndicated from jzb original https://lwn.net/Articles/1086489/

The Arch Linux DevOps team has announced
that adoption of orphaned packages in the Arch User Repository (AUR)
has been disabled due to “the current influx of malicious package
adoptions and follow-up commits made via the AUR
“. Michael Taggart
has posted a brief analysis of the malware being added to a long
list of packages
in this round of attacks. The payload appears
to be
an remote-access trojan (RAT) that takes commands over the
Tor network and attempts to upload a wide range of user data.

The project had suspended
new account registration
in June. That followed a campaign in which an
attacker or attackers created new accounts to adopt orphaned packages
and push malicious updates to them that would install malware on user
systems. AUR registration was reopened
on July 13 after the DevOps team added some minor, and apparently
ineffective, restrictions on creating new accounts.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1086487/

Security updates have been issued by AlmaLinux (kernel, nodejs-nodemon, nodejs22, nodejs24, openssh, and vim), Debian (gsasl and ruby-rack), Fedora (dokuwiki, lego, libnbd, nasm, pack, unbound, and valkey), Mageia (389-ds-base, libxfont2, nghttp2, and perl-DBI), SUSE (apptainer, bind, ffmpeg-7, freerdp, google-osconfig-agent, graphicsmagick, helm, ImageMagick, java-17-openjdk, java-25-openjdk, keybase-client, kubernetes1.34-apiserver, kubernetes1.35-apiserver, kubernetes1.36-apiserver, kubevirt1.8-container-disk, libarchive, logcli, net-tools, openssl-3, PackageKit, perl-Net-DNS, prometheus-ha_cluster_exporter, python-dulwich, python-sqlparse, python-urwid, python3-pyOpenSSL, python313, python3, runc, s2n, tomcat, tomcat10, tomcat11, and valkey), and Ubuntu (libinput, linux-intel-iot-realtime, linux-intel-iotg-5.15, openssl, python2.7, python3.5, and ruby-sinatra).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1086225/

Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libtiff, libXfont2, nodejs:22, nodejs:24, and rest), Debian (expat and nss), Fedora (libssh, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, nodejs24, perl-HTTP-Date, proftpd, squid, unbound, and wordpress), Oracle (c-ares, edk2, freerdp, go-fdo-server, libreswan, mariadb-connector-c, and nginx), SUSE (alloy, apache-commons-lang3, google-guice, maven, maven-resolver, xmvn, apache-sshd, apptainer, avahi, distribution, glib2, go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21, gstreamer-plugins-bad, helm, ImageMagick, java-17-openjdk, java-25-openjdk, liboqs, oqs-provider, libssh, nginx, nm-configurator, nmap, openssl-3, openvpn, PackageKit, perl, perl-DBI, perl-HTTP-Date, perl-XML-Bare, python-msgpack-python, python-sh, python-ujson, python-urllib3, runc, samba, sssd, wget, wpa_supplicant, and xen), and Ubuntu (linux-nvidia, linux-nvidia-7.0 and linux-nvidia-6.17).

[$] LWN.net Weekly Edition for July 30, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1084315/

Inside this week’s LWN.net Weekly Edition:

  • Front: Hazard pointers; DFSG team; Swap devices; Netkit and BPF; BPF inlined functions; Fedora GRUB; gccrs.
  • Briefs: RIP Dan Williams; Debian LLM resolution; Fedora 45 process; Codeberg LLM policy; GCC LLM policy; GNU Binutils 2.47; GNU C Library 2.44; Wayfire 0.11; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] Fedora approves a smaller GRUB

Post Syndicated from jzb original https://lwn.net/Articles/1085609/

Leo Sandoval and Marta Lewandowska have put forward a change
proposal
for Fedora 45, which is expected in October, to
provide a separate, slimmed-down version of GRUB for a niche use
case. The new package would be in addition to the main GRUB package
and would not replace it for the majority of Fedora users. The idea
met with some resistance from Fedora contributors who thought that it
would be better to use systemd-boot,
or another modern bootloader, rather than trying to wrangle GRUB into
a suitable state for the use case. The Fedora Engineering Steering
Council (FESCo), however, voted
to accept the change
on July 7.