Category: Internet News

In Firefox 90, the code providing support for FTP will be removed.

Mozilla has decided to remove the built-in implementation of the FTP protocol from Firefox. In the Firefox 88 release, scheduled for April 19, FTP support will be disabled by default (including the setting browserSettings.ftpProtocolEnabled being set to read-only), and in the Firefox 90 release, planned for June 29, the code related to FTP will be removed. When trying to open […]

Release of module LKRG 0.9.0 for protection against exploitation of vulnerabilities in the Linux kernel

The Openwall project has released version 0.9.0 of the LKRG (Linux Kernel Runtime Guard) kernel module, designed to detect and block attacks and integrity violations in kernel structures. For example, the module can protect against unauthorized changes to a running kernel and attempts to alter user process privileges (defining exploitation attempts). The module is suitable for organizing protection against exploits of already known kernel vulnerabilities […]

The GNU Assembly initiative is promoting a new model for managing the GNU project.

A group of maintainers and developers from various GNU projects, most of whom previously advocated for stepping away from Stallman's sole leadership in favor of collective management, founded the GNU Assembly community, thereby attempting to reform the management system of the GNU project. The GNU Assembly is presented as a platform for collaboration among GNU package developers, who act for user freedom and share the proposed vision […]

Chrome 90 Release

Google has released version 90 of the Chrome web browser. At the same time, a stable release of the open-source project Chromium, which underpins Chrome, is also available. The Chrome browser is characterized by the use of Google logos, a system for sending notifications in the event of a crash, modules for playing protected video content (DRM), an automatic update installation system, and the transmission of RLZ parameters during searches. The next release of Chrome 91 is scheduled for May 25. Key changes […]

Google has introduced multi-level LRU patches for Linux.

Google has released patches with improved implementation of the LRU (Least Recently Used) mechanism for Linux. LRU is a mechanism that allows unused memory pages to be discarded or swapped out. According to Google, the existing implementation of the page eviction mechanism places too high a load on the CPU and often makes poor decisions about which pages to evict. In experiments, […]

Rust support for the Linux kernel has faced criticism from Torvalds.

Linus Torvalds reviewed the patches for enabling driver development in Rust for the Linux kernel and expressed some critical remarks. The major concern was the potential for panicking in erroneous situations, such as out-of-memory scenarios where dynamic memory allocation operations, including those within the kernel, could fail. Torvalds stated that such […]

Chrome update 89.0.4389.128 addresses a 0-day vulnerability. Chrome 90 is delayed.

Google has released Chrome 89.0.4389.128, fixing two vulnerabilities (CVE-2021-21206, CVE-2021-21220) that have working exploits (0-day) available. The CVE-2021-21220 vulnerability was used to compromise Chrome at the Pwn2Own 2021 competition. Exploitation of this vulnerability occurs through the execution of specially crafted WebAssembly code (the vulnerability is caused by a flaw in the WebAssembly virtual machine, allowing the read or write of arbitrary data […]

Release of nginx 1.19.10

The release of the main branch nginx 1.19.10 has been formed, continuing the development of new features (while only critical bug fixes and vulnerabilities are addressed in the concurrently maintained stable branch 1.18). Key changes: The default value of the 'keepalive_requests' parameter, which defines the maximum number of requests that can be sent through a single keep-alive connection, has been increased from 100 to 1000. A new directive has been added […]

Update X.Org Server 1.20.11 addressing the vulnerability

The release of X.Org Server 1.20.11 has been published, addressing a vulnerability (CVE-2021-3472) that allows privilege escalation in systems where the X server runs with root privileges. The issue stems from a bug in the XInput extension, leading to the modification of memory contents outside the allocated buffer when processing ChangeFeedbackControl requests with specially crafted input. A similar issue has also been resolved in the xwayland 21.1.1 component. […]

Release of FreeBSD 13.0

After two and a half years since the formation of branch 12.x, FreeBSD 13.0 has been released, which is prepared for architectures amd64, i386, powerpc, powerpc64, powerpc64le, powerpcspe, armv6, armv7, aarch64, and riscv64. Additionally, images have been created for virtualization systems (QCOW2, VHD, VMDK, raw) and cloud environments such as Amazon EC2, Google Compute Engine, and Vagrant. Key innovations include the transition to a unified c […]

Vulnerabilities in FreeBSD, IPnet, and Nucleus NET related to compression implementation errors in DNS

Research groups Forescout Research Labs and JSOF Research have published the results of a joint security study on various implementations of the compression scheme used to pack repeated names in DNS messages, mDNS, DHCP, and IPv6 RA (packing duplicate parts of domains in messages containing multiple names). The work identified 9 vulnerabilities collectively named NAME:WRECK. The issues were identified […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster