Category: Internet News

Exploitable vulnerabilities identified in the Linux kernel for POSIX CPU timer, cls_route, and nf_tables

Several vulnerabilities have been discovered in the Linux kernel, caused by accessing already freed memory areas, allowing a local user to escalate their privileges in the system. Working prototypes for exploits have been created for all identified issues and will be published one week after the vulnerabilities are disclosed. Patches addressing the issues have been sent to Linux kernel developers. CVE-2022-2588 — a vulnerability in the cls_route filter implementation, […]

Google has expanded its vulnerability discovery incentive program for the Linux kernel

Google has announced an expansion of its initiative to reward payouts for discovering vulnerabilities in the Linux kernel. The maximum payout for a new vulnerability and the creation of a working exploit based on it has been increased from $91,000 to $133,000. In addition to the previously used kCTF (Kubernetes Capture the Flag) environment for hacking attempts, new environments have been offered based on the latest stable […]

The release of the security-focused distribution Kali Linux 2022.3

The Kali Linux 2022.3 distribution release has been announced, intended for testing systems for vulnerabilities, conducting audits, analyzing residual information, and identifying the aftermath of attacks by malicious actors. All original contributions made within the distribution are distributed under the GPL license and available through a public Git repository. Several versions of the iso images have been prepared for download, sized at 432 MB, 2.9 GB, 3.4 GB, and 9.8 […]

Release of nftables batch filter 1.0.5

The release of the nftables 1.0.5 packet filter has been published, unifying the filtering interfaces for IPv4, IPv6, ARP, and network bridges (aiming to replace iptables, ip6tables, arptables, and ebtables). Concurrently, the release of the accompanying library libnftnl 1.2.3 has been published, providing a low-level API for interacting with the nf_tables subsystem. The nftables package includes packet filter components operating in user space, while […]

NPM plans to use Sigstore for package authenticity verification.

GitHub has opened a discussion on a proposal to implement the Sigstore service for verifying packages through digital signatures and maintaining a public log to confirm authenticity when distributing releases. The use of Sigstore will allow for an additional level of protection against attacks targeting the substitution of software components and dependencies (supply chain). For example, the proposed change will protect project source codes in case of account compromise […]

The release of the Ubuntu Sway Remix 22.04 LTS distribution.

The release of Ubuntu Sway Remix 22.04 LTS is now available, providing a pre-configured and ready-to-use desktop based on the mosaic compositor manager Sway. This distribution is an unofficial edition of Ubuntu 22.04 LTS, designed for both experienced GNU/Linux users and newcomers who want to try a tiling window manager environment without the need for extensive setup. Available for download […]

Release of the backup distribution Rescuezilla 2.4

The release of Rescuezilla 2.3, designed for system backup, recovery after failures, and diagnosis of various hardware issues, is now available. The distribution is based on the Ubuntu package base and continues the development of the 'Redo Backup & Rescue' project, which was discontinued in 2012. Live builds for 64-bit x86 systems (1GB) and a deb package for installation on Ubuntu are available for download. Rescuezilla […]

openSUSE developers discuss the cessation of support for ReiserFS.

Jeff Mahoney, the director of SUSE Labs, has submitted a proposal to the community for the discontinuation of support for the ReiserFS file system in openSUSE. The motivation mentions a plan to remove ReiserFS from the main kernel by 2025, stagnation in maintaining this file system, and the lack of reliability features offered by modern file systems to protect against data corruption in case of […]

A mechanism for verifying the correct operation of the kernel has been proposed for Linux.

A set of patches implementing the RV (Runtime Verification) mechanism is proposed for inclusion in Linux kernel 5.20 (possibly the branch will be numbered 6.0). This mechanism provides tools for verifying the correctness of operation in highly reliable systems, ensuring the absence of failures. Verification is performed at runtime by attaching handlers to trace points that compare the actual execution path with a previously defined reference deterministic model of the automaton, […]

A vulnerability (CVE-2022-29582) has been identified in the implementation of the asynchronous input/output interface io_uring, which has been included in the Linux kernel since version 5.1. This allows an unprivileged user to gain root privileges.

The release of Minetest 5.6.0 has been presented, an open cross-platform version of the game MineCraft, allowing groups of players to collaboratively build various structures from blocks, creating a resemblance to a virtual world (sandbox genre). The game is written in C++ using the irrlicht 3D engine. Lua is used for creating extensions. The Minetest code is distributed under the LGPL license, and the game resources are under the CC BY-SA 3.0 license. Ready […]

Vulnerability in the io_uring subsystem of the Linux kernel allows obtaining root privileges from a container

A vulnerability (CVE-2022-29582) has been identified in the implementation of the asynchronous I/O interface io_uring, which has been included in the Linux kernel since version 5.1. This vulnerability allows an unprivileged user to gain root privileges on the system, even when running the exploit from a container. The vulnerability is caused by accessing a previously freed memory block and manifests in Linux kernels starting from the 5.10 branch. It was addressed in April updates […]

Minetest 5.6.0 release, an open clone of the game Minecraft

Fifteen months after the release of the last update, NetBSD 9.3 has been released. Installation images of 470 MB have been prepared for download, available in builds for 57 system architectures and 16 different CPU families. Version 9.3 is fully compatible with previous releases in the 9.x branch and contains important fixes, including those related to vulnerability mitigation. Initially, it was planned […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster