Category: Blog

TSA attack leads to information leakage from AMD CPU microarchitecture structures.

AMD has disclosed information about a new class of microarchitectural attacks on its processors—TSA (Transient Scheduler Attack). This attack allows an attacker to bypass CPU isolation mechanisms and determine data being processed in other contexts, for instance, to obtain information processed at the kernel level from user space or to learn data used in another guest system from a guest system. Vulnerabilities were identified during […]

Vulnerabilities in Git allow for code execution when accessing an external repository.

Corrective releases of the distributed source control system Git versions 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1 have been published, which fix vulnerabilities that allow attackers to execute their code on a user's system when performing a repository cloning operation controlled by the attacker. CVE-2025-48384—this vulnerability is caused by Git clearing specified trailing newline characters when reading configuration parameter values […]

Release of the Thunderbird email client 140

The release of the Thunderbird 140 email client has been announced, developed by the community and based on Mozilla technologies. Thunderbird 140 is built on the ESR codebase of Firefox 140 and is classified as a long-term support version, which receives updates throughout the year. Key changes in Thunderbird 140 include improved dark mode implementation. The message panel has integrated the Dark extension.

Ardour has discontinued support for the GTK2 build in favor of the YTK fork.

The developers of the Ardour audio editor have removed support for building with the GTK2 library from the codebase and only left the option of using YTK. YTK is a fork of GTK2 created by the Ardour project in February 2024. The reason for discontinuing the GTK2 build is linked to the addition of extra functionality in YTK, which supports touchscreen input devices and provides rendering capabilities on the platform.

Release of OBS Studio streaming software 31.1

After six months of development, OBS Studio 31.1 has been released, a package for streaming, compositing, and recording video. The code is written in C/C++ and is distributed under the GPLv2 license. Builds are available for Linux (flatpak), Windows, and macOS. The goal of developing OBS Studio was to create a portable version of the Open Broadcaster Software (OBS Classic) that is not tied to the Windows platform and supports OpenGL.

AlmaLinux has updated ELevate, the migration tool for switching between RHEL clone branches.

The developers of the AlmaLinux distribution have introduced a new version of the ELevate toolkit, which simplifies migration between major releases of distributions based on the Red Hat Enterprise Linux package base while preserving applications, data, and settings. The project supports migration between major branches of AlmaLinux, Rocky Linux, and CentOS Stream. The migration utilizes the Leapp utility developed by Red Hat, which has been enhanced with patches that account for the specifics of CentOS.

Tomorrow's Windows Server update will break compatibility with Samba

Emergency updates for Samba 4.22.3 and 4.21.7 have been released to address compatibility issues between Samba servers and the upcoming Windows Server update. If the proposed corrective updates are not installed, Samba servers will be unable to function as members of Windows Active Directory domains if the user ID mapping settings utilize the ‘ad’ backend. Microsoft has scheduled this update for July 8.

Release of DXVK 2.7, providing implementation of Direct3D 8/9/10/11 over Vulkan API

The release of DXVK 2.7 is now available, providing an implementation of DXGI (DirectX Graphics Infrastructure), Direct3D 8, 9, 10, and 11, which operates through API call translation to Vulkan. To use DXVK, drivers supporting Vulkan API 1.3 are required, such as Mesa RADV 25.0, NVIDIA 550.54.14, and Intel ANV 25.0. DXVK can be used to run 3D applications and games in […]

Vulnerabilities in Redis and Valkey databases

Corrective releases of the Redis DBMS (6.2.19, 7.2.10, 7.4.5, 8.0.3) and Valkey (8.0.4, 8.1.3) have been published, addressing two vulnerabilities. The most critical vulnerability (CVE-2025-32023) could potentially allow remote code execution on the server due to data being written outside the bounds of allocated buffers. To exploit the vulnerability, the attacker must be capable of sending commands to the DBMS. This issue is caused by a flaw in […]

Wayland 1.24 is now available

After 13 months of development, a stable release of the Wayland protocol, inter-process communication mechanisms, and libraries has been introduced as version 1.24. The 1.24 branch is backward compatible with API and ABI levels of the 1.x releases and primarily contains bug fixes and minor protocol updates. The project developments are distributed under the MIT license. The reference compositor server Weston provides code and working examples for using Wayland […]

Bash 5.3 shell release

After nearly three years of development, a new version of the GNU Bash command interpreter 5.3 has been released, which is used by default in most Linux distributions. At the same time, the readline library 8.3 was released, which is used in bash for command line editing. Key improvements include: New forms of command substitution "${ command; }" and "${|command;}" have been implemented, allowing the capture of command output without forking […]

Let's Encrypt to start issuing TLS certificates for IP addresses

The non-profit Let’s Encrypt certificate authority, community-controlled and providing certificates free of charge to anyone, announced the upcoming issuance of free certificates for IP addresses. Unlike certificates for domains, the validity period for IP address certificates will be 30 days, and 6 days. This capability will enable secure encrypted access to hosts not only when using domain names but also when […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster