Author: Yuri Gagarin

Vulnerability in ADOdb allowing SQL query injection

A vulnerability (CVE-2025-46337) has been identified in the ADOdb library, widely used in many PHP projects for abstracting database access, with approximately 3 million installations from the Packagist repository. This allows for the injection of custom SQL queries. The issue has been assigned a critical severity level (10 out of 10). The vulnerability has been fixed in ADOdb version 5.22.9. It manifests when using ADOdb with PostgreSQL databases in applications that invoke […]

Linux kernel developers are moving towards removing support for i486 processors.

Ingo Molnar, the maintainer of the x86 architecture, locking mechanisms, and task scheduler in the Linux kernel, has put forth a set of patches to discuss the removal of support for 486 processors (M486, M486SX, AMD ELAN) and early series 586 processors from the kernel. The kernel is proposed to only support x86 processors that include the CX8 instruction (CMPXCHG8B) and TSC (Time Stamp Counter) register […]

The Debian Project has initiated a general vote on the openness criteria for AI models.

The Debian Project has announced a general resolution (GR) vote among project developers to establish the criteria for accepting machine learning models into the main repository. Currently, a discussion phase has started, after which the voting will commence (the voting start date is yet to be determined). Approximately one thousand developers, involved in package maintenance and Debian's infrastructure support, are eligible to vote […]

A vulnerability in LibJS allows code execution when opening a page in the Ladybird browser.

A vulnerability (CVE-2025-47154) has been identified in the LibJS JavaScript engine used in the Ladybird web browser, which enables the execution of custom code on the system when processing specially crafted JavaScript code. This vulnerability is caused by memory being freed on the m_argument_values_buffer vector, while a pointer remained in the arguments_list structure, leading to access to an already freed memory area. A working prototype exploit is available. The researcher who discovered the issue conducted fuzzing tests on LibJS […]

Release of Wine 10.7 and beta version of Proton 10.0

An experimental release of the open implementation of the Win32 API — Wine 10.7 has been published. Since the release of 10.6, 14 bug reports have been closed and 271 changes have been made. The most important changes: In the ntdll library, the UFFD (userfaultfd) mechanism has been implemented to improve the performance of tracking memory write operations, allowing the creation of handlers for page faults in the […]

Intel has launched iaprof, a performance profiling tool for GPUs.

Brendan Gregg, one of the developers of the dynamic debugging system DTrace, now working at Intel and developing performance analysis tools based on eBPF in the Linux kernel, has announced the open sourcing of the iaprof (AI Flame Graphs) toolkit. This toolkit is designed for analyzing Intel GPU performance information and visualizing it. The code is written in C […]

The Redis project has returned to using an open license. Redis 8.0 has been released.

Redis Ltd has announced a change in the licensing policy of the project. Starting with the release of Redis 8.0, the project's code has become available under the AGPLv3 open license. The shift to an open license was made possible by the return of Salvatore Sanfilippo, the creator of the Redis database, to the company. After leaving Redis Ltd, Salvatore developed a set of vector extensions (Vector Sets), which was ready […]

Release of Libreboot 25.04 and Canoeboot 25.04 boot firmware

The release of the free boot firmware Libreboot 25.04 has been published, which has the status of an experimental release focused on feature development (stable releases mainly contain fixes and are published about once a year, the last stable release was in December). The project develops a ready-built version of the Coreboot project, providing a replacement for proprietary UEFI and BIOS firmware responsible for initializing the CPU, memory, peripherals, and […]

Vulnerability in the finit init system allowing system access without a password

A vulnerability has been identified in the finit initialization system (CVE-2025-29906), allowing anyone to log in as any user without password verification. Exploiting this vulnerability involves manipulating the login prompt and requires console access. The vulnerability has been present since version 3.0 (October 2017) and was fixed in the finit 4.11 release. Subsequently, version 4.12 has been released which addresses […]

Release of the DragonFly BSD 6.4.1 operating system

After two and a half years since the release of version 6.4, the DragonFly BSD 6.4.1 operating system has been released. Developed in 2003 as an alternative fork of FreeBSD 4.x, DragonFly BSD features the distributed versioned file system HAMMER, support for booting 'virtual' kernel systems as user processes, and the capability for caching data and metadata on SSDs […]

Beta release of the openSUSE Leap 16 distribution

Beta testing has begun for the openSUSE Leap 16 distribution, built on technologies from the next major branch of the commercial SLES 16 distribution, transitioning to the new SLFO (SUSE Linux Framework One) platform, previously known as ALP (Adaptable Linux Platform). openSUSE Leap 16 will retain characteristics of a classic distribution using traditional packages, while providing an atomically updated system with a base of […]

Release of web browser Chrome 136 with isolation of viewed links style

Google has released version 136 of the Chrome web browser. At the same time, a stable version of the free Chromium project, which forms the basis of Chrome, is available. Chrome differs from Chromium by including Google branding, a crash notification system, modules for playing protected video content (DRM), an automatic update system, always-on Sandbox isolation, the provision of keys for Google API, and the submission of RLZ parameters […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster