Author: Yuri Gagarin

Release of the NetworkManager 1.34.0 network configurator

A stable release of the interface for simplifying network configuration - NetworkManager 1.34.0 is now available. Plugins for supporting VPN, OpenConnect, PPTP, OpenVPN, and OpenSWAN are being developed within their own development cycles. Key innovations of NetworkManager 1.34 include the introduction of a new service, nm-priv-helper, designed to facilitate operations that require elevated privileges. Currently, the use of this service is limited, but there are plans to eliminate […]

Firefox 96.0.1 Update. Firefox Focus has introduced Cookie Isolation Mode.

In response to recent events, a corrective release of Firefox 96.0.1 has been issued, which fixes a bug in Firefox 96 related to parsing the "Content-Length" header when using HTTP/3. The issue was that the search for the string "Content-Length:" was case sensitive, which did not account for variations like "content-length:". This new version also addresses a specific issue […]

Vulnerability in XFS allowing raw data to be read from a block device

A vulnerability has been found in the XFS filesystem code (CVE-2021-4155) that allows a local unprivileged user to read data from unused blocks directly from the block device. All significant Linux kernel versions above 5.16 that contain the XFS driver are affected by this issue. The fix was included in version 5.16, as well as in updates for kernels 5.15.14, 5.10.91, 5.4.171, 4.19.225, and so on. The state of the updates addressing the issue […]

An experiment simulating a full-size Tor network

Researchers from the University of Waterloo and the U.S. Naval Research Laboratory have unveiled results from the development of a Tor network simulator, comparable in the number of nodes and users to the main Tor network, allowing for experiments that closely resemble real-world conditions. The toolkit and methodology prepared during the experiment enabled simulation of a network with 6,489 nodes on a computer with 4 TB of RAM […]

The LLVM project is transitioning from mailing lists to the Discourse platform.

The LLVM project has announced a transition from its mailing list system to the llvm.discourse.group site based on the Discourse platform for developer communication and announcements. By January 20, all archives of past discussions will be transferred to the new platform. The mailing lists will switch to a read-only mode on February 1. This transition will simplify communication and make it more familiar for […]

Another vulnerability in the eBPF subsystem that allows privilege escalation

Another vulnerability has been identified in the eBPF subsystem (CVE is not assigned), similar to yesterday's issue that allows a local unprivileged user to execute code at the Linux kernel level. The problem has been present since Linux kernel 5.8 and remains unpatched for now. A working exploit is expected to be released on January 18. The new vulnerability is caused by incorrect validation of eBPF programs being executed. In particular, the eBPF verifier does not appropriately […]

The leader of Apache PLC4X has shifted to a model of paid feature development.

Christofer Dutz, the creator and lead developer of the free library set for industrial automation Apache PLC4X, who holds the position of Vice President at the Apache Software Foundation overseeing the Apache PLC4X project, has issued an ultimatum to corporations, expressing his willingness to cease development if he cannot resolve funding issues. His dissatisfaction stems from the fact that the usage of Apache PLC4X […]

Release of the interactive IPython shell 8.0

The release of IPython 8.0 has taken place, an interactive shell for the Python language that combines the features of the Python interactive console and the Unix command line, providing flexible debugging, code editing, and data visualization tools. IPython is actively used in the scientific community for development, data processing, and interactive execution of applications related to libraries such as numpy, matplotlib, sympy, and scipy. The new version includes the ability to […]

The third candidate for the Slackware Linux 15.0 releases

Patrick Volkerding announced the formation of the third and final release candidate for the Slackware 15.0 distribution, which has reached the freeze stage with 99% of packages ready before release. A 3.4 GB (x86_64) installation image has been prepared for download, along with a minimal build for live mode. Among the final changes before the freeze is the update of the Linux kernel to version 5.15.14 (consideration is being given to […]

Уязвимости в systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js

A vulnerability (CVE-2021-3997) has been identified in the systemd utility systemd-tmpfiles, allowing for uncontrolled recursion. This issue can be exploited to create a denial of service during system boot by generating a large number of nested subdirectories in the /tmp directory. A patch is currently available as a fix. Package updates addressing the issue have been proposed in Ubuntu and SUSE but are not yet available in […]

A vulnerability in the eBPF subsystem that allows code execution at the Linux kernel level.

A vulnerability (CVE-2021-4204) has been discovered in the eBPF subsystem, which allows running handlers inside the Linux kernel in a special JIT virtual machine, enabling a local unprivileged user to escalate privileges and execute their code at the Linux kernel level. The issue has been present since Linux kernel 5.8 and remains unfixed (affecting the 5.16 release as well). The status of the updates in development is […]

The installer Anaconda used in Fedora and RHEL is being transferred to a web interface

Jiri Konecny from Red Hat announced efforts to modernize and improve the user interface of the Anaconda installer used in Fedora, RHEL, CentOS, and some other Linux distributions. Notably, instead of using the GTK library, the new interface will be built on web technologies and will allow for remote management via a web browser. It is noted that the decision to revamp the installer has already […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster