Author: Yuri Gagarin

The first stable release of the Mold linker, developed by the LLVM lld creator.

Rui Ueyama, the author of the LLVM lld linker and the chibicc compiler, has introduced the first stable release of the new high-performance linker Mold, which significantly outpaces the GNU gold and LLVM lld linkers in terms of object file linking speed. The project is deemed ready for production use and can serve as a faster drop-in replacement for the GNU linker on Linux systems. Future plans for the next significant release include […]

A vulnerability in the Linux kernel USB Gadget subsystem that could potentially allow code execution.

A vulnerability (CVE-2021-39685) has been discovered in USB Gadget, a subsystem of the Linux kernel that provides a programming interface for creating client USB devices and software simulation of USB devices. This vulnerability could lead to information leakage from the kernel, crashes, or arbitrary code execution at the kernel level. The attack can be executed by an unprivileged local user through manipulations with various device classes implemented over the USB Gadget API, such as […]

Release of OpenVPN 2.5.5

The release of OpenVPN 2.5.5 has been prepared, which is a package for creating virtual private networks that allows for encrypted connections between two client machines or to set up a centralized VPN server for multiple clients to operate simultaneously. OpenVPN code is distributed under the GPLv2 license, and binary packages are prepared for Debian, Ubuntu, CentOS, RHEL, and Windows. The new version marks the deprecation of outdated 64-bit ciphers that are susceptible to […]

Buffer overflow in Toxcore, exploited through sending a UDP packet

A vulnerability (CVE-2021-44847) has been identified in Toxcore, the reference implementation of the P2P messaging protocol Tox, which potentially allows for code execution upon processing specially crafted UDP packets. All users of applications based on Toxcore that have not disabled UDP transport are affected by this vulnerability. An attack can be executed by simply sending a UDP packet, knowing the victim's IP address, network port, and open DHT key (this information is publicly available in the DHT, […]

Update OpenSSL 3.0.1 addressing the vulnerability

Corrective releases of the OpenSSL cryptographic library 3.0.1 and 1.1.1m are now available. Version 3.0.1 fixes a vulnerability (CVE-2021-4044), and about a dozen bugs have been addressed in both releases. The vulnerability is present in the implementation of SSL/TLS clients and is related to the way the libssl library handles negative error codes returned by the X509_verify_cert() function, invoked to verify a certificate passed to the client by the server. Negative codes are returned […]

Release of the Pop!_OS 21.10 distribution, advancing the COSMIC desktop

The company System76, which specializes in manufacturing laptops, PCs, and servers shipped with Linux, has released Pop!_OS 21.10. Pop!_OS is based on the Ubuntu 21.10 package base and comes with its own COSMIC desktop environment. The project's developments are distributed under the GPLv3 license. ISO images are available for x86_64 and ARM64 architectures in versions for NVIDIA (2.9 GB) and Intel/AMD […]

Release of QEMU emulator 6.2

The release of QEMU 6.2 has been presented. As an emulator, QEMU allows you to run a program compiled for one hardware platform on a system with a completely different architecture, for example, running an application for ARM on an x86-compatible PC. In virtualization mode, the performance of code execution in an isolated environment is close to that of the hardware system, thanks to direct execution of instructions on the CPU and using […]

A new variant of the attack on Log4j 2 allows bypassing the added protection.

Another vulnerability (CVE-2021-45046) has been discovered in the JNDI lookup implementation within the Log4j 2 library, appearing despite the fixes added in release 2.15 and regardless of the use of the 'log4j2.noFormatMsgLookup' configuration for protection. The issue poses a danger mainly for older versions of Log4j 2, protected by the 'noFormatMsgLookup' flag, as it allows for bypassing the protections against the previous vulnerability (Log4Shell, CVE-2021-44228), […]

Vulnerabilities in X.Org Server

Four vulnerabilities have been identified in the X.Org Server that allow for privilege escalation on the system if the X server is running with root rights, or remote code execution if access is gained through X11 session forwarding via SSH. These issues are expected to be fixed in the upcoming xorg-server 21.1.2 release, which is anticipated in the coming days. In distributions, the issues remain unresolved (Debian, Ubuntu, RHEL, […]

17 Apache projects affected by a vulnerability in Log4j 2

The Apache Software Foundation has published a summary report on the projects affected by a critical vulnerability in Log4j 2 that allows arbitrary code execution on the server. The following Apache projects are vulnerable: Archiva, Druid, EventMesh, Flink, Fortress, Geode, Hive, JMeter, Jena, JSPWiki, OFBiz, Ozone, SkyWalking, Solr, Struts, TrafficControl, and Calcite Avatica. The vulnerability has also affected GitHub products, including GitHub.com, GitHub Enterprise […]

Chrome update 96.0.4664.110 addresses critical and 0-day vulnerabilities.

Google has released Chrome version 96.0.4664.110, which fixes five vulnerabilities, including a (CVE-2021-4102) vulnerability that is already being exploited by attackers in exploits (0-day) and a critical vulnerability (CVE-2021-4098) that allows bypassing all layers of browser protection and executing code in the system outside of the sandbox environment. Details are not yet disclosed, but it is known that the 0-day vulnerability is caused by use-after-free memory […]

YAOC — a prototype of a secure Russian-language operating system based on the A2 project

The YOS project is developing a branch from the A2 operating system, also known as Bluebottle and Active Oberon. One of the main goals of the project is the radical implementation of the Russian language throughout the system, including (at least partial) translation of the source texts into Russian. YOS can operate as a windowed application under Linux or Windows, as well as in the form of a standalone operating […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster