Category: Blog

New Facts About the Origin of cut

New facts have emerged regarding the origin of the cut command in Unix. It has long been believed that cut first appeared in the AT&T System III UNIX in 1982. However, British researchers, referencing a lost library of Peter the Great, argue that A.S. Pushkin first mentions this command in his lines from 'Poltava': 'Mazepa's face torments Kat'. […]

The Linux.org.ru project is changing its license to a non-free one

The coordinator of the Linux.org.ru project, Maxim 'maxcom' Valyanskiy, announced a change in the forum engine's source code license from the free Apache License 2.0 to the LOLX license (Linux.org.ru Original License xD). The new license does not meet the criteria for free software set by the FSF, OSI, and Debian. Activists from Linux.org.ru plan to create a fork under the GNU AGPL 3.0 license, which will develop independently […]

Vulnerability in the io_uring subsystem allows obtaining root privileges

A vulnerability (CVE-2024-0582) has been discovered in the io_uring asynchronous input/output interface provided by the Linux kernel, allowing an unprivileged user to gain root rights in the system. Exploiting the vulnerability requires only regular local access to the system, without the need for namespace manipulations. A working exploit is currently publicly available, and a second exploitation technique has also been described in detail. The vulnerability is caused by accessing already released […]

Time to check versions: a sophisticated supply chain attack has been detected in Linux

Malicious code has been found in xz/liblzma aimed at gaining unauthorized remote access via SSH (backdoor) and executing commands (CVE-2024-3094). The malware was injected in versions 5.6.0 and 5.6.1 and, as reported by OpenNet, has been integrated into builds and repositories of Gentoo, Arch Linux, Debian sid/unstable, Fedora Rawhide/40-beta, openSUSE factory/tumbleweed, LibreELEC, Alpine edge, Solus, CRUX, Cygwin, MSYS2 mingw, HP-UX, Homebrew, […]

A change was detected in the xz codebase that prevented the activation of the Landlock protection mechanism

Changes made by the author of the backdoor continue to emerge in the xz project repository aimed at blocking protective mechanisms. A modification in the CMakeLists.txt build script was found that prevented the use of the Landlock application isolation mechanism, even with its support in the system. An unnecessary extra dot was deliberately added to the C code that checks the availability of the Landlock system call, causing the check to fail on […]

NetBSD 10.0

The release of NetBSD 10.0 has been announced. Changes in the new version include: Hardware Support: Added support for Apple M1. Added support for Raspberry Pi 4. The rkv1crypto driver is included for PINE64 Rock64 and NanoPi R2S. spiflash support has been added for Rockchip RK3328. compat_linux support for the AArch64 architecture has been included. Kernel Changes: Added WireGuard support. Adiantum encryption implementation is introduced for efficient disk encryption […]

Release of the NetBSD 10.0 operating system

A year and a half after the last update, the release of NetBSD 10 has been published. Installation images sized 630 MB are available for download in builds for 57 system architectures and 16 different CPU families. The new branch includes several significant improvements, such as support for access control lists in the FFS file system, substantial performance optimization, and disk encryption with […]

Analysis of the activation logic and operation of the backdoor in the xz package

Preliminary results of reverse engineering a malicious object file embedded in liblzma as part of a backdoor promotion campaign in the xz package are now available. The backdoor affects only x86_64 systems running on the Linux kernel and the Glibc C library, with an additional patch applied to sshd that links to the libsystemd library for sd_notify support. It was initially thought that the backdoor allows bypassing authentication […]

Debian 10 "Buster" has been moved to the archive

Debian 10 'Buster' repositories have been moved to archive.debian.org, after which the distribution will soon become unavailable through the main mirror network. The removal of Debian 10 packages from mirrors for architectures that do not have LTS support is planned for mid-April. The Debian 10 release was presented on July 7, 2019, and was officially supported until September 2022. During the LTS cycle […]

Retrospective on the promotion of the backdoor in the xz package

The backdoor in the xz package is believed to have been implanted by developer Jia Tan, who in 2022 became a maintainer and released versions starting from 5.4.2. In addition to the xz project, the alleged backdoor author also participated in the development of the xz-java and xz-embedded packages, and was included among the maintainers of the XZ Embedded project used in the Linux kernel. In the organization promoting the backdoor […]

A backdoor has been found in the xz code of versions 5.6.0 and 5.6.1

Debian developer and information security researcher Andres Freund reports the discovery of a potential backdoor in the source code of xz versions 5.6.0 and 5.6.1. The backdoor consists of a line in one of the m4 scripts that appends obfuscated malicious code to the end of the configure script. This code then modifies one of the generated Makefiles of the project, ultimately leading to […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster