Feed lwn LWN.net

Favorite IconLWN.net

Link https://lwn.net/
Feed http://lwn.net/headlines/rss
Updated 2025-06-20 06:00
Conservancy Seeks Your Questions on GPL Enforcement
Software Freedom Conservancy has announceda long-term campaign to increase education and understanding aboutcommunity-driven GPL enforcement processes. "Conservancy invitesdevelopers and other Open Source and Free Software contributors to emailtheir questions on GPL enforcement to<enforcement-questions@sfconservancy.org>. Conservancy cannot promiseto answer every question; Conservancy will use the collected questions overthe coming months to provide more educational and informational materialsabout GPL enforcement, and in particular about Conservancy's GPL Compliance Project for Linux Developers."
Security advisories for Monday
Debian has updated fusionforge(code execution), postgresql-9.1(regression in previous update), and symfony (restriction bypass).Debian-LTS has updated ipsec-tools (denial of service), ruby1.9.1 (multiple vulnerabilities), and wordpress (multiple vulnerabilities).Fedora has updated gcab (F21:directory traversal), libtiff (F21: twovulnerabilities), netty (F22: HttpOnlycookie bypass), php-ZendFramework (F22:CRLF injection), python-django (F22:incorrect session flushing), suricata (F21:denial of service), torque (F22; F21; F20:denial of service), and zeromq (F22: security bypass).Gentoo has updated adobe-flash(multiple vulnerabilities) and phpmyadmin (multiple vulnerabilities).openSUSE has updated Chromium(13.2, 13.1: multiple vulnerabilities), parallel (13.2, 13.1: file overwrite), and mysql-connector-java (13.2, 13.1: information disclosure).SUSE has updated firefox(SLE11SP3: multiple vulnerabilities).
Kernel prepatch 4.1-rc6
The 4.1-rc6 kernel prepatch is out. Linussays that "things look normal."
Linux support for digital video broadcasting
Mauro Carvalho Chehab, the maintainer of the kernel's media subsystem, hasposted the first two in a series of articles on digital video broadcastingsupport in Linux. Part 1gives an overview of how the devices and protocols work, while part 2looks at digital TV network interface use. "Supporting embeddedDigital TV hardware is complex, considering that such hardware generallyhas multiple components that can be rewired in runtime to dynamicallychange the stream pipelines and provide flexibility for things likerecording a video stream, then tuning into another channel to see adifferent program. This article describes how the DVB pipelines are setupand the needs that should be addressed by the Linux Kernel."
Announcing GitTorrent: A Decentralized GitHub
At his blog, Chris Ball announces "GitTorrent," his new project designed to let developers host Git repositories on BitTorrent. The system takes advantage of Git's ability to run over arbitrary network protocols. "We ask for the commit we want and connect to a node with BitTorrent, but once connected we conduct this Smart Protocol negotiation in an overlay connection on top of the BitTorrent wire protocol, in what’s called a BitTorrent Extension. Then the remote node makes us a packfile and tells us the hash of that packfile, and then we start downloading that packfile from it and any other nodes who are seeding it using Standard BitTorrent. We can authenticate the packfile we receive, because after we uncompress it we know which Git commit our graph is supposed to end up at; if we don’t end up there, the other node lied to us, and we should try talking to someone else instead." The project is, obviously, a new one that still has important ground to cover—such as dealing with comments or pull requests—but there are interesting ideas to consider already.
Friday's security updates
Debian has updated virtualbox (privilege escalation).Debian-LTS has updated clamav (multiple vulnerabilities), postgresql-8.4 (multiple vulnerabilities), and tomcat6 (multiple vulnerabilities).
[$] LWN.net Weekly Edition for May 29, 2015
The LWN.net Weekly Edition for May 29, 2015 is available.
LibreOffice Viewer for Android released
The Document Foundation has announced the availability of the LibreOfficeviewer for Android systems. And it's not just for viewing:"LibreOffice Viewer also offers basic editing capabilities, like modifying words in existing paragraphs and changing font styles such asbold and italics.Editing is still an experimental feature which has to be enabledseparately in the settings, and is not stable enough for missioncritical tasks."
A security study of Docker images
The folks at Banyan have looked into thesecurity state of the images stored on Docker Hub and published theirresults. "More than a third of all images have highpriority vulnerabilities and close to two-thirds have high or mediumpriority vulnerabilities. These statistics are especially troublesomebecause these images are also some of the most downloaded images (severalof them have hundreds of thousands of downloads)."
Security updates for Thursday
Arch Linux has updated curl(information leak).Debian-LTS has updated dulwich(code execution), eglibc (code execution),exactimage (denial of service), and libnokogiri-ruby (information disclosure from 2012).Fedora has updated ca-certificates (F20: CA update),hostapd (F21; F20: denial of service), java-1.8.0-openjdk (F20: insecure tmp fileuse), LibRaw (F21: denial of service), mingw-LibRaw (F21: denial of service), openslp (F20: two denial of service flaws, onefrom 2010, one from 2012), php (F21;F20: multiple vulnerabilities), postgresql (F22: three vulnerabilities), andrawtherapee (F22: denial of service).Mageia has updated fuse(privilege escalation), kernel-linus(denial of service), and kernel-tmb (denial of service).openSUSE has updated glibc,glibc-testsuite, glibc-utils, glibc.i686 (13.2, 13.1: two vulnerabilities).SUSE has updated firefox (SLE12:multiple vulnerabilities).
[$] SourceForge replacing GIMP Windows downloads
In 2013, we reported that SourceForge.net had started to redirectthe download links clicked on by some users, providing those users with aninstaller program that bundled in not just the software the user hadrequested, but a set of side-loaded "utilities" as well. The practiceraised the ire of many in the community, even though it was anoptional service that SourceForge offered to project owners. Mattersmay have changed recently, however, as the GIMP project discovered that"GIMP for Windows" downloads had suddenly become side-loadinginstallers—and that the project could no longer access the SourceForgeaccount that was used to distribute them.
This week's edition will be one day late
LWN staff celebrated the US Memorial Day holiday on Monday this week, sothe Weekly Edition will come out on the holiday schedule — one day laterthan usual. We will return to our normal schedule next week. Thank youall, as always, for supporting LWN.
White House sides with Oracle, tells Supreme Court APIs are copyrightable (ArsTechnica)
Ars Technica reportsthat the US Justice Department has sided with Oracle in its dispute withGoogle. "The dispute centers on Google copying names, declarations, and header lines of the Java APIs in Android. Oracle filed suit, and in 2012, a San Francisco federal judge sided with Google. The judge ruled that the code in question could not be copyrighted. Oracle prevailed on appeal, however. A federal appeals court ruled that the "declaring code and the structure, sequence, and organization of the API packages are entitled to copyright protection."Google maintained that the code at issue is not entitled to copyrightprotection because it constitutes a "method of operation" or "system" thatallows programs to communicate with one another." (Thanks to Martin Michlmayr)
Wednesday's security updates
Debian has updated ntfs-3g(incomplete fix in previous update).Debian-LTS has updated ntfs-3g(incomplete fix in previous update).Red Hat has updated kernel(RHEL6.4: privilege escalation) and qemu-kvm (RHEL6.5: code execution).Ubuntu has updated ntfs-3g(15.04: incomplete fix in previous update) and openldap (15.04, 14.10, 14.04, 12.04: denial of service).
Mourning Marco Pesenti Gritti
The GNOME community is mourning the loss of developer Marco Pesenti Gritti,who passed away on May 23. "He was the most passionate and dedicated hacker I knew, and I know he wasextremely respected in the GNOME community, for his work on Epiphany,Evince and Sugar among many others, just like he was at litl. Those whoknew him personally know he was also an awesome human being."
Jonathan Riddell forced out of Kubuntu
Scott Kitterman has posted aseries of emails around the the Ubuntu Community Council's decision toremove Jonathan Riddell as the leader of the Kubuntu project. He has alsostatedhis intent to leave the Ubuntu community. "I also wish to extendmy personal apology to the Kubuntu community for keeping this private foras long as we did. Generally, I don’t believe such an approach isconsistent with our values, but I supported keeping it private in the hopethat it would be easier to achieve a mutually beneficial resolution of thesituation privately. Now that it’s clear that is not going to happen, I(and others in the KC) could not in good faith keep this private."
Trouble with the May 22 PostgreSQL update
If you run PostgreSQL and have applied one of the updates that werereleased on May 22, it would be a good idea to read thispage about an unfortunate bug in those releases. In somecases, the problem can cause the server to fail to restart after a crash.There is a new release in the works; meanwhile, a workaround is available.
The Moose is loose: Linux-based worm turns routers into social network bots (Ars Technica)
Ars Technica takesa look at the latest malware threat. "A worm that targets cable and DSL modems, home routers, and other embedded computers is turning those devices into a proxy network for launching armies of fraudulent Instagram, Twitter, and Vine accounts as well as fake accounts on other social networks. The new worm can also hijack routers' DNS service to route requests to a malicious server, steal unencrypted social media cookies such as those used by Instagram, and then use those cookies to add "follows" to fraudulent accounts. This allows the worm to spread itself to embedded systems on the local network that use Linux-based operating systems.The malware, dubbed "Linux/Moose" by Olivier Bilodeau and Thomas Dupuy of the security firm ESET Canada Research, exploits routers open to connections from the Internet via Telnet by performing brute-force login attempts using default or common administrative credentials. Once connected, the worm installs itself on the targeted device."
Security advisories for Tuesday
Arch Linux has updated nbd (denial of service), pgbouncer (denial of service), postgresql (multiple vulnerabilities), webkitgtk (information disclosure), and webkitgtk2 (information disclosure).Debian has updated ipsec-tools (denial of service), nbd (denial of service), postgresql-9.1 (multiple vulnerabilities), postgresql-9.4 (multiple vulnerabilities), tiff (multiple vulnerabilities), and zendframework (multiple vulnerabilities).Debian-LTS has updated ntfs-3g (privilege escalation).Fedora has updated firefox (F22:multiple vulnerabilities), hostapd (F22:denial of service), java-1.8.0-openjdk(F22: file overwrites), kernel (F20: twovulnerabilities), libarchive (F21: denialof service), LibRaw (F22; F20: denial of service), mingw-LibRaw(F22; F22;F20: denial of service), openstack-glance (F22: access restrictionbypass), php (F22: multiplevulnerabilities), php-ZendFramework2 (F22:CRLF injection), phpMyAdmin (F22: twovulnerabilities), qemu (F22; F20: code execution), quassel (F22: denial of service), suricata (F22: denial of service), thunderbird (F22: multiple vulnerabilities),wordpress (F22: cross-site scripting), and xen (F22; F21; F20: privilege escalation).Mageia has updated chromium-browser-stable (multiple vulnerabilities) and kernel (memory corruption).openSUSE has updated coreutils(13.2: multiple vulnerabilities), firefox(13.2, 13.1: multiple vulnerabilities), libraw (13.2, 13.1: denial of service), LibVNCServer (13.2: code execution), quassel (13.2, 13.1: SQL injection), thunderbird (13.2, 13.1: multiple vulnerabilities), and wireshark (13.2; 13.1: multiple vulnerabilities).Red Hat has updated chromium-browser (RHEL6: multiple vulnerabilities).SUSE has updated KVM (SLES11SP2:code execution), MySQL (SLE11SP3: multiplevulnerabilities), and Xen (SLES11SP2; SLES11SP1; SLES10SP4: two vulnerabilities).Ubuntu has updated kernel (14.04:denial of service), linux-lts-trusty(12.04: denial of service), and postgresql-9.1,postgresql-9.3, postgresql-9.4 (15.04, 14.10, 14.04, 12.04: multiple vulnerabilities).
Fedora 22 released
The Fedora 22 release is out. "If this release had ahuman analogue, it'd be Fedora 21 after it'd been to college,landed a good job, and kept its New Year's Resolution to go to thegym on a regular basis. What we're saying is that Fedora 22 hasbuilt on the foundation we laid with Fedora 21 and the work tocreate distinct editions of Fedora focused on the desktop, server,and cloud (respectively). It's not radically different, but thereare a fair amount of new features coupled with features we'vealready introduced but have improved for Fedora 22." LWN's preview of Fedora 22 was published in theMay 21 Weekly Edition.
The end for Mandriva
An anonymous reader has pointed out that Mandriva iscurrently being liquidated (page in French). The company brought in€553,000 in 2013, but that is seemingly not enough to keep it going in2015. It is a sad end for a company that has been pursuing the desktopLinux dream since 1998.
Kernel prepatch 4.1-rc5
The fifth 4.1 prepatch is out for testing."So we're on schedule for a normal 4.1 release, if it wasn't for thefact that the timing looks like the next merge window would hit our yearlyfamily vacation. So we'll see how that turns out, I might end up delayingthe release just to avoid that (or just delay opening the mergewindow)."
[$] A tale of two data-corruption bugs
There have been two bugs causing filesystem corruption in the newsrecently. One of them, a bug in ext4, has gotten the bulk of theattention, despite the fact that it is an old bug that is hard to trigger.The other, however, is recent and able to cause data loss onfilesystems installed on a RAID 0 array. Both are interestingexamples of how things can go wrong, and, thus, merit a closer look.
Nocera: iio-sensor-proxy 1.0 is out!
At his blog, Bastien Nocera announcesthe 1.0 release of iio-sensor-proxy,a framework for accessing the various environmental sensors (e.g.,accelerometer, magnetometer, proximity, or ambient-light sensors) builtin to recent laptops. The proxy is a daemon that listens to theIndustrial I/O (IIO) subsystem and provides access to the sensorreadings over D-Bus. As of right now, support for ambient-lightsensors and accelerometers is working; other sensor types are indevelopment. The current API is based on those used by Android andiOS, but may be expanded in the future. "For future versions,we'll want to export the raw accelerometer readings, so thatapplications, including games, can make use of them, which might bringup security issues. SDL, Firefox, WebKit could all do with beingadapted, in the near future."
Friday's security updates
Arch Linux has updated chromium (multiple vulnerabilities).Debian has updated chromium-browser (multiple vulnerabilities), fuse (privilege escalation), and ntfs-3g (privilege escalation).SUSE has updated KVM (SLES11SP1: multiple vulnerabilities),SUSE Manager Server 1.7 (SLE11 SP2: multiple vulnerabilities), and Xen (SLE11 SP3: multiple vulnerabilities).Ubuntu has updated apport(two privilege escalation vulnerabilities), fuse (privilege escalation), ntfs-3g (privilege escalation), oxide-qt (14.04, 14.10, 15.04: multiple vulnerabilities), and python-dbusmock (14.04, 14.10, 15.04:code execution).
Announcing qboot, a minimal x86 firmware for QEMU
The announcement of Clear Containers (which guest author Arjan van de Ven described in an LWN article from this week) seems to have sparked some interesting work on QEMU that resulted in qboot: "a minimal x86 firmware that runs on QEMU and, together witha slimmed-down QEMU configuration, boots a virtual machine in 40milliseconds on an Ivy Bridge Core i7 processor." Paolo Bonzini announced the project (code is available at git://github.com/bonzini/qboot.git), which is quite new: "The first commit to qboot is more or less 24 hours old, so there isdefinitely more work to do, in particular to extract ACPI tables fromQEMU and present them to the guest. This is probably another day ofwork or so, and it will enable multiprocessor guests with little or noimpact on the boot times. SMBIOS information is also available from QEMU."
Security advisories for Thursday
Debian has updated libmodule-signature-perl (multiple vulnerabilities).Debian-LTS has updated dnsmasq(information disclosure).Fedora has updated wordpress (F21; F20:three vulnerabilities).Oracle has updated docker (OL7; OL6: multiple vulnerabilities).Red Hat has updated java-1.5.0-ibm (RHEL5&6: multiple vulnerabilities, one from 2005)and java-1.7.1-ibm (RHEL6&7: multiple vulnerabilities, onefrom 2005).SUSE has updated gstreamer-0_10-plugins-bad (SLE11SP3: codeexecution) and xen (SLE12: multiple vulnerabilities).
[$] LWN.net Weekly Edition for May 21, 2015
The LWN.net Weekly Edition for May 21, 2015 is available.
Security advisories for Wednesday
Debian has updated icedove(multiple vulnerabilities), proftpd-dfsg(unauthenticated copying of files), and zendframework (multiple vulnerabilities).Fedora has updated dovecot (F21; F20:denial of service), firefox (F20: multiplevulnerabilities), libtasn1 (F21: denial ofservice), php-ZendFramework2 (F21;F20: CRLF injection), and thunderbird (F20: multiple vulnerabilities).Ubuntu has updated kernel (14.10; 14.04;12.04: multiple vulnerabilities), linux-lts-trusty (12.04: multiplevulnerabilities), linux-lts-utopic (14.04:multiple vulnerabilities), and linux-ti-omap4 (12.04: two vulnerabilities).
[$] PostgreSQL: the good, the bad, and the ugly
The PostgreSQL development community is working toward the 9.5 release,currently planned for the third quarter of this year. Development activityis at peak levels as the planned feature freeze for this release approaches.While this activity is resulting in the merging of some interestingfunctionality, including the long-awaited "upsert" feature,it is also revealing some fault lines within the community. The fact that PostgreSQLlacks the review resources needed to keep up with its natural rate ofchange has been understood for years; many other projects suffer from thesame problem. But the pressures on PostgreSQL seem to be becoming moreacute, leading to concerns about fairness in the community and thedurability of the project's cherished reputation for high-quality software.
20 years of Qt
Lars Knoll marks the20th anniversary of the Qt toolkit on the Qt blog. "From thebeginning, Qt has been released with both open source and commerciallicensing options. Over the years, we have worked on expanding this model,and nowadays, Qt is actually developed as an open source project. In thissense Qt is actually in a rather unique position, having a strong ecosystemwith passionate people, as well as a commercial entity behind it, whichbacks up and funds most of the development."
How to Make Money from Open Source Platforms (Linux.com)
Over at Linux.com, John Mark Walker examineswhy companies aren't making money on pure open source ventures. "It is not that there is no money in selling open source software, but rather that the business models have shifted. Whereas, under the old proprietary world, a larger percentage of money went to pure software vendors, now that money has spread among a larger spectrum of companies and industries; lots of people get paid to work on or with open source software, but an increasing number of them don’t work for software vendors, per se. In addition to looking in all the wrong places, the current investment model is suspicious of an open source approach. The vast majority of venture capitalists, especially in Silicon Valley, are very risk averse and shy away from open source products that, in their view, will not give as large a return on their investment. In order to secure the funding required to scale a company, investors will frequently require that the startup company include proprietary bits as tools to increase revenue and margins. These two factors - diffusion of revenue and risk-averse investors - combine to both give a false impression and, in part due to the false impression, prevent pure open source software vendors from getting funding."
Tuesday's security updates
CentOS has updated thunderbird (C6; C5: multiple vulnerabilities).Debian has updated kfreebsd-9 (denial of service) and xen (code execution).Debian-LTS has updated commons-httpclient (multiple vulnerabilities) and ruby1.8 (man-in-the-middle attack).Mageia has updated avidemux (multiple vulnerabilities), firefox, thunderbird, sqlite3 (multiple vulnerabilities), moodle (multiple vulnerabilities), php (multiple vulnerabilities), phpmyadmin (two vulnerabilities), and xbmc (denial of service).openSUSE has updated clamav(13.2, 13.1: multiple vulnerabilities), docker (13.2: multiple vulnerabilities), andflash-player (13.2, 13.1: multiple vulnerabilities).Oracle has updated thunderbird (OL7; OL6: multiple vulnerabilities).Scientific Linux has updated thunderbird (SL5,6,7: multiple vulnerabilities).Ubuntu has updated thunderbird(15.04, 14.10, 14.04, 12.04: multiple vulnerabilities).
Goodbye, Pi. Hello, C.H.I.P. (Linux Journal)
Linux Journal takes alook at the C.H.I.P. mini-computer, an open software and hardwaredevice that comes with a Debian-based OS. "The official public release is scheduled for next year, but crowdfunding backers will be able to land a "Kernel Hacker" package this September. This package is aimed at Linux developers who want to help to contribute to kernel modifications for the C.H.I.P. before its final release."
Kernel prepatch 4.1-rc4
Linus has released the 4.1-rc4 kernelprepatch, saying: "So here it is, last-minute fix and all. The -rc4patch is a bit bigger than the previous ones, but that seems to be mainlydue to normal random timing - just the fluctuation of when submaintainertrees get pushed."
Stable kernel updates
New stable kernels 4.0.4, 3.14.43, and 3.10.79 have been released. All of themcontain important fixes throughout the tree.
Security advisories for Monday
Arch Linux has updated thunderbird (multiple vulnerabilities).CentOS has updated thunderbird(C7: multiple vulnerabilities).Debian has updated libmodule-signature-perl (multiple vulnerabilities).Debian-LTS has updated dpkg (integrity-verification bypass), nbd (denial of service), and tiff (multiple vulnerabilities).Fedora has updated java-1.8.0-openjdk (F21: unspecifiedvulnerability), NetworkManager (F21: denialof service), phpMyAdmin (F21; F20: two vulnerabilities), qemu (F21: code execution), and t1utils (F21; F20: multiple vulnerabilities).Mageia has updated ruby-rest-client (two vulnerabilities) and virtualbox (code execution).openSUSE has updated flash-player(11.4: multiple vulnerabilities), qemu (13.2; 13.1:code execution), and firefox (11.4: multiple vulnerabilities).Red Hat has updated thunderbird(RHEL5,6,7: multiple vulnerabilities).Slackware has updated thunderbird (multiple vulnerabilities).SUSE has updated KVM (SLE11SP3:code execution), qemu (SLE12: two vulnerabilities), and spice (SLE12; SLESDK12: denial of service).
[$] An introduction to Clear Containers
Guest author Arjan van de Ven writes: "Containers are hot. Everyoneloves them. Developers love the ease of creating a "bundle" of somethingthat users can consume; DevOps and information-technology departments lovethe ease of management and deployment." A group at Intel is workingon a new approach to containers called "ClearContainers"; click below (subscribers only) for an introduction to howthese containers work.
Hardening Hypervisors Against VENOM-Style Attacks (Xen Project Blog)
The Xen Project looks at a mechanism to mitigate vulnerabilities like VENOM that attack emulation layers in QEMU. "The good news is it’s easy to mitigate all present and future QEMU bugs, which the recent Xen Security Advisory emphasized as well. Stubdomains can nip the whole class of vulnerabilities exposed by QEMU in the bud by moving QEMU into a de-privileged domain of its own. Instead of having QEMU run as root in dom0, a stubdomain has access only to the VM it is providing emulation for. Thus, an escape through QEMU will only land an attacker in a stubdomain, without access to critical resources. Furthermore, QEMU in a stubdomain runs on MiniOS, so an attacker would only have a very limited environment to run code in (as in return-to-libc/ROP-style), having exactly the same level of privilege as in the domain where the attack started. Nothing is to be gained for a lot of work, effectively making the system as secure as it would be if only PV drivers were used." The Red Hat Security Blog also noted this kind of mitigation for VENOM-style attacks.
Rust 1.0 released
Version1.0 of the Rust language has been released. "The 1.0 release marks the end of that churn. This release is the official beginning of our commitment to stability, and as such it offers a firm foundation for building applications and libraries. From this point forward, breaking changes are largely out of scope (some minor caveats apply, such as compiler bugs).That said, releasing 1.0 doesn’t mean that the Rust language is “done”. We have many improvements in store. In fact, the Nightly builds of Rust already demonstrate improvements to compile times (with more to come) and includes work on new APIs and language features, like std::fs and associated constants."
Friday's security updates
Arch Linux has updated wireshark-cli (multiple vulnerabilities), wireshark-gtk (multiple vulnerabilities), and wireshark-qt (multiple vulnerabilities).SUSE has updated flash-player (SLE12: multiple vulnerabilities).
3 big lessons I learned from running an open source company (Opensource.com)
Over at Opensource.com, Lucidworks co-founder and CTO Grant Ingersoll writes about lessons he has learned from running an open-source company. "You might ask, 'Why not open source it all and just provide support?' It's a fair question and one I think every company that open sources code struggles to answer, unless they are a data company (e.g., LinkedIn, Facebook), a consulting company, or a critical part of everyone's infrastructure (e.g., operating systems) and can live off of support alone. Many companies start by open sourcing to gain adoption and then add commercial features (and get accused of selling out), whereas others start commercial and then open source. Internally, the sales side almost always wants "something extra" that they can hang their quota on, while the engineers often want it all open because they know they can take their work with them."
Thursday's security updates
Arch Linux has updated qemu (codeexecution).CentOS has updated firefox (C5:multiple vulnerabilities), kernel (C7: codeexecution), kvm (C5: code execution),qemu-kvm (C7; C6: code execution), and xen (C5: code execution).Debian has updated iceweasel(multiple vulnerabilities) and qemu(multiple vulnerabilities).Debian-LTS has updated icu (multiple vulnerabilitiessome from 2013).Fedora has updated ca-certificates (F21: certificate changes), firefox (F21: multiple vulnerabilities), gnutls (F21: signature algorithm verificationbotch), libssh (F21: denial of service),and thunderbird (F21: two vulnerabilities).Mageia has updated darktable(denial of service), kernel-linus (threevulnerabilities), kernel-tmb (multiple vulnerabilities), libraw (denial of service), qemu (code execution), rawtherapee (denial of service), ufraw and dcraw (denial of service), and wireshark (three dissector vulnerabilities).Oracle has updated firefox (OL6:multiple vulnerabilities), kvm (OL5: denial of service),qemu-kvm (OL7; OL6: code execution), kernel (OL7; OL6; OL6; OL5: multiple vulnerabilities),and xen (OL5: code execution).Scientific Linux has updated firefox (SL7,SL6,SL5: multiple vulnerabilities), kernel (SL7: code execution), kexec-tools (SL7: arbitrary file overwrite),pcs (SL7; SL6: privilege escalation), qemu-kvm(SL7; SL6:code execution), tomcat (SL7: HTTP requestsmuggling), and tomcat6 (SL6: HTTP request smuggling).SUSE has updated kvm (SLE11SP3:denial of service).Ubuntu has updated firefox (multiple vulnerabilities)and qemu, qemu-kvm (three vulnerabilities).
[$] LWN.net Weekly Edition for May 14, 2015
The LWN.net Weekly Edition for May 14, 2015 is available.
Linux 3.19.y-ckt extended stable support
Kamal Mostafa has announced that Canonical's kernel team will pick upstable maintenance of the 3.19 kernel series, until July 2016.
Stable kernel updates
Greg Kroah-Hartman has released stable kernels 4.0.3, 3.14.42, and 3.10.78. All of them contain important fixes.
[$] CoreOS Fest and the world of containers, part 1
It's been a Linux container bonanza in San Francisco recently, and thatincludes a series of events and announcements from multiple startups andcloud hosts. It seems like everyone is fighting for a piece of what theyhope will be a new multi-billion-dollar market. This included Container Camp on April 17 and CoreOS Fest on May 5th and 6th, with DockerCon to come near the end ofJune. While there is a lot of hype, the current container gold rush hasyielded more than a few benefits for users — and caused technologicaldevelopment so rapid it is hard to keep up with.Subscribers can click below for a report by guest author Josh Berkus fromthis week's edition.
Security advisories for Wednesday
Arch Linux has updated firefox (multiple vulnerabilities) and tomcat6 (denial of service).CentOS has updated firefox (C7; C6:multiple vulnerabilities), kexec-tools (C7:file overwrites), pcs (C7; C6: privilege escalation), tomcat (C7: HTTP request smuggling), and tomcat6 (C6: HTTP request smuggling).Debian has updated quassel (SQL injection).Fedora has updated clamav (F20:multiple vulnerabilities), dpkg (F21; F20: twovulnerabilities), kernel (F21: twovulnerabilities), texlive (F21: predictablefilenames), and wpa_supplicant (F20: code execution).Gentoo has updated ettercap (multiple vulnerabilities).Mageia has updated dnsmasq(information disclosure), flash-player-plugin (multiple vulnerabilities), hostapd (denial of service), netcf (denial of service), pam (two vulnerabilities), and testdisk (multiple vulnerabilities).Oracle has updated firefox (OL7; OL5:multiple vulnerabilities), kernel (OL7: twovulnerabilities), kexec-tools (OL7: fileoverwrites), tomcat (OL7: HTTP requestsmuggling), and tomcat6 (OL6: HTTP request smuggling).Red Hat has updated firefox(RHEL5,6,7: multiple vulnerabilities), flash-plugin (RHEL5,6: multiplevulnerabilities), java-1.6.0-ibm (RHEL5,6:multiple vulnerabilities), java-1.7.0-ibm(RHEL5: multiple vulnerabilities), kernel(RHEL7: privilege escalation), kernel-rt (RHEL7; RHEMRG2.5:privilege escalation), kexec-tools (RHEL7:file overwrites), kvm (RHEL5: codeexecution), pcs (RHEL7; RHEL6: privilege escalation), qemu-kvm(RHEL7; RHEL6: code execution), qemu-kvm-rhev (RHEL7, RHEL6,RHEL OSP4,5,6: code execution), tomcat(RHEL7: HTTP request smuggling), tomcat6(RHEL6: HTTP request smuggling), and xen(RHEL5: code execution).Scientific Linux has updated kvm(SL5: code execution) and xen (SL5: code execution).Slackware has updated mozilla (multiple vulnerabilities).SUSE has updated php5 (SLE12:multiple vulnerabilities).
[$] Trading off safety and performance in the kernel
The kernel community ordinarily tries to avoid letting users get into aposition where the integrity of their data might be compromised. There areexceptions, though; consider, for example, the ability to explicitly flushimportant data to disk (or more importantly, to avoid flushing at any giventime). Buffering I/O in this manner can significantly improve disk writeI/O throughput, but if application developers are careless, the result canbe data loss should the system go down at an inopportune time. Recentlythere have been a couple of proposed performance-oriented changes that havetested the community's willingness to let users put themselves into danger.<p>Click below (subscribers only) for the full story from this week's KernelPage.
Firefox 38.0
Mozilla has released Firefox 38.0. This version features new tab-basedpreferences and Ruby annotation support. Also, it will be the base for thenext ESR release. The releasenotes contain more information.
...201202203204205206207208209210