Author: Yuri Gagarin

A new version of patches for the Linux kernel with support for the Rust language has been released.

Miguel Ojeda, the author of the Rust-for-Linux project, has proposed for consideration by Linux kernel developers the v5 release of components for developing device drivers in Rust. This is the sixth edition of the patches, taking into account the first variant released without a version number. Rust support is considered experimental but is already included in the linux-next branch and sufficiently developed to begin work on creating layers […]

Release of Pale Moon Browser 30.0

The release of the Pale Moon web browser 30.0 has been published, branching off from the Firefox codebase to provide higher performance, maintain a classic interface, minimize memory consumption, and offer additional customization options. Pale Moon builds are created for Windows and Linux (x86 and x86_64). The project’s code is distributed under the MPLv2 (Mozilla Public License). The project adheres to a classic interface organization, without […]

Mozilla implements identifiers in downloadable Firefox installation files

Mozilla has begun utilizing a new method for identifying browser installations. In the builds distributed from the official website, provided as exe files for the Windows platform, dltoken identifiers, unique to each download, are inserted. Consequently, performing multiple downloads of the installation archive for the same platform results in files with different checksums, as the identifiers are added directly […]

Release of OpenVPN 2.5.6 and 2.4.12 with vulnerability fixes

Corrective releases of OpenVPN 2.5.6 and 2.4.12 have been prepared, packages for creating virtual private networks that allow establishing an encrypted connection between two client machines or providing a centralized VPN server for simultaneous client connections. The OpenVPN code is distributed under the GPLv2 license, ready-made binary packages are created for Debian, Ubuntu, CentOS, RHEL, and Windows. The new versions eliminate a vulnerability that potentially allows […]

Remote DoS vulnerability in the Linux kernel exploited through sending ICMPv6 packets

A vulnerability (CVE-2022-0742) has been discovered in the Linux kernel, which allows exhausting available memory and remotely triggering a denial of service by sending specially crafted icmp6 packets. The issue is related to memory leakage occurring while processing ICMPv6 messages with types 130 or 131. The problem appears from kernel version 5.13 and has been fixed in releases 5.16.13 and 5.15.27. The issue did not affect stable branches of Debian, SUSE, […]

Vulnerability in OpenSSL and LibreSSL leading to looping when processing invalid certificates

Corrective releases of the OpenSSL cryptographic library 3.0.2 and 1.1.1n are now available. The update addresses the vulnerability (CVE-2022-0778) that can be exploited to create a denial of service (infinite loop of the handler). To exploit the vulnerability, it's enough to trigger the processing of a specially crafted certificate. The issue manifests in both server and client applications that may handle user-provided certificates. The problem is caused by an error in the function […]

Chrome 99.0.4844.74 update addressing a critical vulnerability

Google has released updates for Chrome 99.0.4844.74 and 98.0.4758.132 (Extended Stable) that fix 11 vulnerabilities, including a critical vulnerability (CVE-2022-0971) that allows bypassing all levels of browser protection and executing code in the system outside the sandbox environment. Details have not yet been disclosed, but it is known that the critical vulnerability is related to accessing already freed memory (use-after-free) in the browser engine […]

Debian maintainer steps down over disagreement with new community behavior model

The team responsible for managing accounts in the Debian project has downgraded Norbert Preining's status for inappropriate behavior in the private mailing list debian-private. In response, Norbert has decided to cease his involvement in Debian development and join the Arch Linux community. Norbert has been involved in Debian development since 2005 and has maintained around 150 packages, primarily […]

Red Hat attempted to take over the domain WeMakeFedora.org under the pretext of trademark infringement

Red Hat has initiated legal proceedings against Daniel Pocock regarding the trademark infringement of Fedora in the domain name WeMakeFedora.org, which published criticism directed at participants of the Fedora project and Red Hat. Representatives of Red Hat demanded the transfer of domain rights to the company, as it violates the registered trademark, but the court sided with the defendant […]

Library rating update requiring special security checks

The OpenSSF (Open Source Security Foundation), established by the Linux Foundation and aimed at enhancing the security of open-source software, has published a new edition of the Census II study, aimed at identifying open projects in need of urgent security audits. The study focuses on the analysis of shared open code that is implicitly used in various corporate projects in the form of dependencies downloaded from external repositories. In […]

Initial support for SMP has been implemented in ReactOS

Developers of the ReactOS operating system, designed to ensure compatibility with Microsoft Windows programs and drivers, announced the readiness of an initial set of patches for booting the project on multiprocessor systems with SMP mode enabled. Changes to support SMP are not yet included in the main codebase of ReactOS and require further refinement, but the fact that it can be booted with SMP mode enabled is noted […]

Release of the Apache HTTP Server 2.4.53 addressing critical vulnerabilities

The HTTP Server Apache 2.4.53 has been released, featuring 14 changes and addressing 4 vulnerabilities: CVE-2022-22720 — a potential HTTP Request Smuggling attack that allows specially crafted client requests to be injected into the content of requests from other users, transmitted via mod_proxy (for example, this can enable the injection of malicious JavaScript code into the session of another user on the site). The issue is caused by leaving incoming connections open […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster