Security updates have been issued by Debian (php7.4, redis, snapd, twisted, webkit2gtk, and wpewebkit), Fedora (cyrus-imapd, nodejs, phpMyAdmin, polkit, snapd, webkit2gtk3, and xen), Gentoo (chromium), openSUSE (jaw, kubevirt, virt-api-container,, opera, polkit, and sphinx), Red Hat (ruby:2.6), Slackware (expat), and SUSE (kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container and polkit).
The 5.17-rc5 kernel prepatch is out fortesting. "Things continue to look pretty much normal. There arefixes all over the place, but no more than usual for this time of therelease".
People are attracted to free software for a number of reasons, includingprice, overall quality, community support, and available features. But,for many of us, the value of free software is to be found in its ability to allow us toactually own and maintain control over our systems. Antifeatures in freesoftware tend not to last long, and free drivers can often unlock capabilities of thehardware that its vendors may not have seen fit to make available. Intel'supcoming "software defined silicon" (SDSi) mechanism may reduce that control,though, by taking away access to hardware features from anybody who has notpaid the requisite fees.
Qualys has discloseda vulnerability in the snap-confine component of Ubuntu's Snappackaging system. "Successful exploitation of this vulnerabilityallows any unprivileged user to gain root privileges on the vulnerablehost". Affected systems with untrusted users should probably beupgraded forthwith.
Linus Torvalds releasedthe 4.4 kernel on January 10, 2016 and promptly left the building forthe greener fields of 4.5. This kernel was finished from his point ofview, but it was just beginning its life in the wider world, and became thefirst long-term-stable release to be supported for more than two years.Indeed, the 4.4 release became one of the longest-supported and most widelyused releases in the history of the kernel project (so far); it wasdeployed in vast numbers of Android devices, among other places. The final 4.4 stablerelease took place on February 3, over six years after 4.4 was"finished"; it is time to take a look at what happened to 4.4 in itsstable life.
Security updates have been issued by Debian (drupal7), Fedora (kernel, lua, vim, and xrdp), openSUSE (firejail, json-c, kafka, webkit2gtk3, and xorg-x11-server), Oracle (bind, firefox, ruby:2.5, ruby:2.6, and thunderbird), Red Hat (ruby:2.5 and ruby:2.6), SUSE (apache2, glibc, json-c, libvirt, webkit2gtk3, xen, and xorg-x11-server), and Ubuntu (linux-raspi, linux-raspi-5.4).
Blocking in the kernel's random-number generator (RNG)—causing a process towait for "enough"entropy to generate strong random numbers—has always been controversial. It has also led tovarious kinds of problems over the years, from timeouts and delays causedby misuse in user-spaceprograms to deadlocks and other problems in the bootprocess. That behavior has undergone a number of changes over the last fewyears and it looks possible that the last vestige of the difference betweenmerely "good" and "cryptographic-strength" random numbers may go away in someupcoming kernel version.
Longtime Unix developer Lorinda Cherry passed away recently; among otherthings, she was the creator of the dc and bc utilitiesstill in use today. See thisposting from Douglas McIlroy for many more details on her life.
Both Firefox and Chrome are racing toward releasing version 100 in the nearfuture, and developers for both browsers are worriedthat web sites with naive code to parse the version number out of theuser-agent string will break.
The5.16.10,5.15.24,5.10.101,5.4.180,4.19.230,4.14.267, and4.9.302stable kernel updates are available. As usual, each contains another setof important fixes.
Security updates have been issued by CentOS (firefox and thunderbird), Debian (librecad, libxstream-java, and zsh), Fedora (expat, util-linux, varnish-modules, xterm, and zsh), Mageia (Intel-nonfree, kernel, kernel-linus, and microcode), openSUSE (zabbix), Red Hat (kernel, kpatch-patch, Red Hat Virtualization Host, and thunderbird), Scientific Linux (thunderbird), and Ubuntu (cryptsetup).
Over on the Bootlin blog, Michael Opdenacker has an introduction to using device tree overlays to support changes to the standard device tree definition for a particular system-on-chip (SoC). This allows users to add new hardware or modify the hardware configuration for their system relatively easily—and without recompiling the kernel or the full device tree source files.
Sometimes, a kernel-patch series comes with an exciting, sexy title. Othertimes, the mailing lists are full of patches with titles like "remoteper-cpu lists drain support". For many, the patches associated withthat title will be just as dry as the title itself. But, for those who areinterested in such things — a group that includes many LWN readers —this short patch series from Nicolas Saenz Julienne gives someinsight into just what is required to make the kernel's page allocator asfast — and as robust — as developers can make it.
Security updates have been issued by Debian (h2database), Fedora (dotnet-build-reference-packages, dotnet3.1, and firefox), Oracle (.NET 5.0, firefox, kernel, and kernel-container), Red Hat (firefox), Scientific Linux (firefox), SUSE (unbound), and Ubuntu (firefox).
Like most components in the computing landscape, networking hardware hasgrown steadily faster over time. Indeed, today's high-end networkinterfaces can often move data more quickly than the systems they areattached to can handle. The networking developers have been working foryears to increase the scalability of their subsystem; one of the currentprojects is theBIG TCP patch set from Eric Dumazet and Coco Li. BIG TCP isn't foreverybody, but it has the potential to significantly improve networkingperformance in some settings.
The 5.17-rc4 kernel prepatch is out fortesting. "Things continue to look pretty normal for 5.17. Both thediffstat and the number of commits looks pretty much average for an rc4release." The code name for the release has been changed to "SuperbOwl".
The Debian project is known for its commitment to free software, the effortthat it puts into ensuring that its distribution is compliant with thelicenses of the software it ships, and the energy itputs into discussions around that work. A recent (and ongoing) discussionstarted with a query about a relatively obscure aspect of the process by which newpackages enter the distribution, but ended up questioning the project'sapproach toward licensing and copyright issues. While no real conclusionswere reached, it seems likely that the themes heard in this discussion,which relate to Debian's role in the free-software community in general, willplay a prominent part in future debates.
The Debian project is known for its commitment to free software, the effortthat it puts into ensuring that its distribution is compliant with thelicenses of the software it ships, and the energy itputs into discussions around that work. A recent (and ongoing) discussionstarted with a query about a relatively obscure aspect of the process by which newpackages enter the distribution, but ended up questioning the project'sapproach toward licensing and copyright issues. While no real conclusionswere reached, it seems likely that the themes heard in this discussion,which relate to Debian's role in the free-software community in general, willplay a prominent part in future debates.
The5.16.9,5.15.23,5.10.100,5.4.179,4.19.229,4.14.266,and 4.9.301stable kernel updates have been released; each contains a small number ofimportant fixes.
The5.16.9,5.15.23,5.10.100,5.4.179,4.19.229,4.14.266,and 4.9.301stable kernel updates have been released; each contains a small number ofimportant fixes.
Security updates have been issued by Debian (cryptsetup), Fedora (firefox, java-1.8.0-openjdk, microcode_ctl, python-django, rlwrap, and vim), openSUSE (kernel), and SUSE (kernel and ldb, samba).
Security updates have been issued by Debian (cryptsetup), Fedora (firefox, java-1.8.0-openjdk, microcode_ctl, python-django, rlwrap, and vim), openSUSE (kernel), and SUSE (kernel and ldb, samba).
Well-maintained free-software projects usually make a point of quicklyfixing known security problems, and the Sambaproject, which provides interoperability between Windows and Unixsystems, is no exception. So it is natural to wonder why the fix for CVE-2021-20316,a symbolic-link vulnerability, was well over two years in coming.Sometimes, a security bug can be fixed with a simple tweak to the code.Other times, the fix requires a massive rewrite of much of a projects'sinternal code. This particular vulnerability fell firmly into the lattercategory, necessitating a public rewrite of Samba's virtual filesystem(VFS) layer to address a non-disclosed vulnerability.
Well-maintained free-software projects usually make a point of quicklyfixing known security problems, and the Sambaproject, which provides interoperability between Windows and Unixsystems, is no exception. So it is natural to wonder why the fix for CVE-2021-20316,a symbolic-link vulnerability, was well over two years in coming.Sometimes, a security bug can be fixed with a simple tweak to the code.Other times, the fix requires a massive rewrite of much of a projects'sinternal code. This particular vulnerability fell firmly into the lattercategory, necessitating a public rewrite of Samba's virtual filesystem(VFS) layer to address a non-disclosed vulnerability.
Security updates have been issued by Debian (firefox-esr and openjdk-8), Fedora (phoronix-test-suite and php-laminas-form), Mageia (epiphany, firejail, and samba), Oracle (aide, kernel, kernel-container, and qemu), Red Hat (.NET 5.0 on RHEL 7 and .NET 6.0 on RHEL 7), Scientific Linux (aide), Slackware (mozilla), SUSE (clamav, expat, and xen), and Ubuntu (speex).
Security updates have been issued by Debian (firefox-esr and openjdk-8), Fedora (phoronix-test-suite and php-laminas-form), Mageia (epiphany, firejail, and samba), Oracle (aide, kernel, kernel-container, and qemu), Red Hat (.NET 5.0 on RHEL 7 and .NET 6.0 on RHEL 7), Scientific Linux (aide), Slackware (mozilla), SUSE (clamav, expat, and xen), and Ubuntu (speex).
The PinePhone is a Linux-basedsmartphone made by PINE64 that runs freeand open-source software (FOSS); it is designed to use a close-to-mainline Linux kernel. While manysmartphones already use the Linux kernel as part of Android, few rundistributions that are actually similar to those used on desktops andlaptops. The PinePhone is different, however; it provides an experiencethat is much closer to normal desktop Linux, though it probably cannotcompletely replace a full-featured smartphone—at least yet.
The PinePhone is a Linux-basedsmartphone made by PINE64 that runs freeand open-source software (FOSS); it is designed to use a close-to-mainline Linux kernel. While manysmartphones already use the Linux kernel as part of Android, few rundistributions that are actually similar to those used on desktops andlaptops. The PinePhone is different, however; it provides an experiencethat is much closer to normal desktop Linux, though it probably cannotcompletely replace a full-featured smartphone—at least yet.
Version 2.38 of the GNU Binutils tool set has been released. Changesinclude new hardware support (including for the LoongArch architecture),various Unicode-handling improvements, a new --thin option toar for the creation of thin archives, and more.
Version 2.38 of the GNU Binutils tool set has been released. Changesinclude new hardware support (including for the LoongArch architecture),various Unicode-handling improvements, a new --thin option toar for the creation of thin archives, and more.
Version 5.24of the KDE-based Plasma desktop is out; this is a long-term-supportrelease. Changes include various task-manager improvements, a new overviewmode, fingerprint-reader support, improved Wayland support, and more.
It's been two whole days since the last set of stable kernel releases, butthe long wait is over:5.16.8,5.15.22,5.10.99,5.4.178,4.19.228,4.14.265, and4.9.300have all been released. Each contains yet another set of important fixes.
This is a few days old, but evidently thereis still need for this message: Konstantin Ryabitsev explainshow it is easy to cause a commit to appear falsely to be part of a GitHubrepository:
Go 1.18, the biggest release of the Go language since Go 1.0 in March 2012, is expectedto be released in February. The first beta was released in December with two features which, each on their own, would havemade the release a big one. It adds support for generic types and nativesupport for fuzz testing.In the blog post announcing thebeta, core developer Russ Cox emphasized that the release "representsan enormous amount of work".
Security updates have been issued by CentOS (log4j), Debian (chromium, xterm, and zabbix), Fedora (kate, lua, and podman), Oracle (aide and log4j), and SUSE (xen).
Version 4.1.0 of the secure-desktop-oriented Qubes OS distribution has beenreleased. "Theculmination of years of development, this release brings a host of newfeatures, major improvements, and numerous bug fixes". New featuresan experimental GUI domain separate from dom0, the "Qrexec" policy system,progress toward a reproducible build, and more. See below and this article for more information.
Digital photography opens up a whole new world of photo postprocessingopportunities, especially if the photographer uses their camera's rawformat to take advantage of all of the data collected by the sensor. Onthe other hand, using raw images means doing without all of the processingdone by the camera and taking on a range of complex tasks. Raw photoeditors are designed to work with raw images as a key part of aphotographer's workflow. Your editor recently reviewed the darktable editor, but there areother options available in the free-software community. RawTherapee is a GPLv3-licensed raweditor that is in some ways simpler than darktable — but that is not thesame as saying that it is simple.
Security updates have been issued by Debian (ldns and libphp-adodb), Fedora (kernel, kernel-headers, kernel-tools, mingw-binutils, mingw-openexr, mingw-python3, mingw-qt5-qtsvg, scap-security-guide, stratisd, util-linux, and webkit2gtk3), Mageia (lrzsz, qtwebengine5, and xterm), openSUSE (chromium), and Ubuntu (python-django).
The 5.17-rc3 kernel prepatch is out fortesting. Linus says: "Things look fairly normal so far, with apretty average number of commits for an rc3 release".
The5.16.6,5.15.20,5.10.97, and5.4.177stable kernel updates have been released. Unfortunately, aproblem was reported almost immediately after that release, leading tothe reversion of a broken patch and the subsequent release of5.16.7,5.15.21, and5.10.98.It's worth noting that numerous groups tested the first set of releases andreported successful results (they can be seen as replies to the-rc1 posting), but nobody hit this problem in time.
Version1.20.0 of the GStreamer multimedia system is out. Changes include a new high-levelplayback library replacing GstPlayer, decoding support for WebM Alpha,updated Rust bindings, and more; see the announcement for lots of details.