Author: Erik Peterson

Copy Fail — a vulnerability in the Linux kernel that allows gaining root access in most distributions.

Researchers from Xint have discovered a vulnerability (CVE-2026-31431) in the Linux kernel that allows an unprivileged user to gain root access to the system. The issue has been assigned the code name Copy Fail. A prototype exploit is available. The exploitation of this vulnerability has been demonstrated in Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16, though it is noted that kernel packages from other distributions, including Debian, Arch, Fedora, […]

curl 8.20.0

On April 29, after more than a month of development, 521 commits, and the correction of 282 bugs, the release of version 8.20.0 (the 274th) of the cross-platform console utility and library curl, written in C and distributed under the curl license, took place. Key Changes Security As mentioned earlier ('High quality chaos'), there has been a significant increase in reports of security issues lately. This time […]

CVE-2026-31431: local vulnerability with privilege escalation in all modern Linux systems

Details have been published regarding the vulnerability 'Copy Fail' CVE-2026-31431 (Base Score: 7.8 HIGH), which allows any local user to gain root privileges locally without special tools or conditions. Most systems released since 2017 are affected. The vulnerability is linked to an error in authencesn—a cryptographic template in the Linux kernel—and it is exploited through the AF_ALG interface. An exploit with code is available on […]

Release of LXC 7.0 and LXD 6.8 container management tools

The Linux Containers community has released the toolkit for managing isolated containers LXC 7.0, providing a runtime suitable for running containers with complete system environments, akin to virtual machines, as well as executing unprivileged containers for individual applications (OCI). LXC belongs to low-level tools that operate at the level of individual containers. For centralized management of containers deployed in a cluster of […]

GTK2-NG: a fork of the GTK2 library

One of the developers of the Devuan distribution has presented the GTK2-NG project, which will develop a fork of the GTK2 library aimed at continuing its maintenance and ensuring quality operation in modern distributions. Maintaining the fork will allow the continued provision of applications tied to GTK2 in Devuan, after the end of GTK2 support in the Debian 14 distribution, which is expected to be released in the summer of 2027. The developers of the GTK project have ceased […]

GTK2-NG has been introduced, a fork of the GTK2 library.

One of the developers of the Devuan distribution has presented the GTK2-NG project, which will develop a fork of the GTK2 library aimed at continuing its maintenance and ensuring quality operation in modern distributions. Maintaining the fork will allow the continued provision of applications tied to GTK2 in Devuan, after the end of GTK2 support in the Debian 14 distribution, which is expected to be released in the summer of 2027. The developers of the GTK project have ceased […]

Valve has released the GameNetworkingSockets 1.5.0 network library

After four years of development, Valve has released the GameNetworkingSockets library 1.5.0, featuring a message transmission system over UDP that can be used to facilitate high-speed and reliable data exchange in games. The code is written in C++ and is distributed under the BSD license. GameNetworkingSockets implements a TCP-like protocol over UDP that ensures connection establishment, but is focused on […]

Fedora 44

On April 28, yet another version of the Fedora Linux distribution family was quietly released – 44. The Fedora team prefers to test the distribution before the release, which is why the launch was delayed twice as part of the standard protocol (the initial date was April 14). Key innovations in Gnome 50 include: removal of X11-related code; the Anaconda installer has had its logic for creating network profiles changed; Wine NTSYNC is enabled by default […]

7-Zip 26.01

The release of 26.01 of the library and console utility 7-Zip has occurred, which is designed to work with archives in the formats of 7z, XZ, BZIP2, GZIP, TAR, ZIP, WIM, and many others. The project is written in C and C++ and is distributed under the GNU LGPL license. Changes: The Linux version of 7-Zip can use large (2 MB) memory pages, which allows for increased compression speeds for 7z/xz/LZMA/LZMA2 […]

In the Netherlands, a collaborative code development platform for government institutions has been created based on Forgejo.

The Netherlands government has launched its own source code hosting platform, code.overheid.nl, where they plan to publish and collaboratively develop open source software for government institutions. The hosting service is positioned as a European alternative to GitHub and GitLab and aims to ensure digital sovereignty. The open collaborative development platform Forgejo has been used as the basis. The project was initiated by the Open Source Program Office, established under the Ministry of Internal […]

Updates for Firefox 150.0.1 and Chrome 147.0.7727.137 addressing critical vulnerabilities.

A corrective release of Firefox 150.0.1 is available, which addresses 28 vulnerabilities (19 vulnerabilities are classified under CVE-2026-7322, 4 under CVE-2026-7323, and 4 under CVE-2026-7324). All vulnerabilities are caused by memory management issues, such as buffer overflows and accessing already freed memory areas. These issues could potentially lead to code execution by an attacker when opening specially crafted pages. […]

Malicious code has been implanted in the Python package elementary-data, which has 1.1 million downloads per month.

Elementary Data has reported a compromise of its GitHub Actions workflows, during which attackers managed to publish a release of the elementary-data package 0.23.3 in the PyPI directory and the GitHub repository that included malicious code to steal confidential information from user systems. This malicious release was also included in the official Docker image of the project. Last month, the elementary-data package […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster