Author: Yuri Gagarin

Oracle has released the first version of the UEK-next kernel, based on Linux kernel 6.9.

Oracle has announced the formation of packages with the UEK-next (Next Unbreakable Enterprise Kernel), built on the basis of the Linux kernel release 6.9. By default, instead of the kernel from Red Hat Enterprise Linux, the Oracle Linux distribution continues to use the UEK 7 kernel, based on Linux kernel 5.15, while the UEK-next kernel is positioned as a continuously updated option for […]

Indirector — a new microarchitectural attack affecting Intel Raptor Lake and Alder Lake CPUs.

Researchers from the University of California, San Diego, have presented a new method of attack on the microarchitectural structures of Intel processors, applicable among others to CPUs based on the Raptor Lake and Alder Lake microarchitectures. The attack, codenamed Indirector, allows for modification of the speculative execution of instructions in other processes and at other privilege levels (for example, in the kernel or another virtual […]

The new version of Vivaldi 6.8 for PC

The new version of the Vivaldi 6.8 browser for desktops has been released. Major work has been done on the built-in email client, which has now reached version 2.0. Among the most notable features of the email client are: Preloading emails Starting with this version, the email client will by default load all emails from the server for the last 30 days and all messages visible […]

Release of Apache HTTP Server 2.4.61 addressing vulnerabilities

The release of the Apache HTTP server 2.4.61 is now available, which was published almost immediately after the 2.4.60 release and includes a fix for a regression issue that caused a vulnerability (CVE-2024-39884) allowing for code viewing of scripts configured using the AddType directive (for example, it is possible to craft a specially formatted request to a PHP script that leads to displaying its contents, rather than executing it). The Apache httpd version 2.4.60 fixed 8 […]

Google will begin offering rewards for identifying vulnerabilities in the KVM hypervisor.

Google has introduced the kvmCTF initiative, under which security researchers can receive monetary rewards for detecting vulnerabilities in the KVM (Kernel-based Virtual Machine) hypervisor. Google's interest in KVM is driven by its use in Google Cloud services as well as in Android and ChromeOS platforms (CrosVM is based on KVM). To receive a reward, a demonstration of an exploit against specially prepared […]

Release of the GNU findutils 4.10.0 toolkit with renewed support for the Musl C library

The GNU Project has released version 4.10.0 of the findutils package, which includes implementations of utilities for organizing file searches in the system, such as find, updatedb, and locate. The findutils also develop the xargs utility, designed to build commands executed with data from standard input, typically generated by the find utility. In the new version: Support for the Musl C library, distributed under the […]

Fedora 42 intends to implement telemetry and change the access model for disks and flatpak.

In the upcoming release of Fedora Workstation 42, scheduled for spring next year, there is a proposal to add components for collecting and sending metrics, which will allow for studying real user preferences and considering them in decision-making related to the distribution's development, priority setting in development, and enhancing user comfort. The proposal is still under discussion and has not yet been reviewed by the FESCo committee (Fedora […]

The MySQL DBMS 9.0.0 is available

Oracle has launched a new branch of the MySQL DBMS 9.0.0. The MySQL Community Server 9.0.0 builds are prepared for all major Linux distributions, FreeBSD, macOS, and Windows. Under the release model introduced last year, MySQL 9.0 is categorized under the 'Innovation' branches, which will also include the upcoming significant releases MySQL 9.1 and 9.2. The Innovation branches are recommended for those […]

Release of OpenSSH 9.8 with the disabling of the DSA algorithm and additional security mechanisms.

The OpenSSH 9.8 release has been published, an open implementation of a client and server for operating with SSH 2.0 and SFTP protocols. Besides addressing a separately announced critical vulnerability (CVE-2024-6387) that allows remote code execution with root privileges before authentication, the new version also fixes another less severe vulnerability and proposes several significant changes aimed at enhancing security. […]

A vulnerability in OpenSSH allows remote code execution with root privileges on servers with Glibc.

Qualys has identified a critical vulnerability (CVE-2024-6387) in OpenSSH, allowing remote code execution with root privileges without authentication. The vulnerability, code-named regreSSHion, occurs in the default configuration starting from OpenSSH 8.5 on systems with the standard Glibc library. The possibility of an attack has been demonstrated on a 32-bit system with Glibc with ASLR (Address Space Layout Randomization) protection enabled […]

The dhclient utility has been removed from OpenBSD in favor of the background process dhcpleased.

Theo de Raadt has introduced a change in the OpenBSD-current codebase, which forms the basis for the next significant release, removing the DHCP client dhclient. Instead of dhclient, a continuously running background process called dhcpleased is recommended, which has been included since OpenBSD 6.9 and uses the ifconfig utility to enable automatic configuration of network interfaces via DHCP (enabled by launching 'ifconfig $if autoconf' or adding […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster