Category: Blog

Vulnerabilities in the Linux kernel allowing privilege escalation through nf_tables and ksmbd

A vulnerability (CVE-2024-1086) has been identified in Netfilter, a Linux kernel subsystem used for filtering and modifying network packets, allowing a local user to execute code at the kernel level and elevate their privileges in the system. The problem is caused by a double free in the nf_tables module, which facilitates the operation of the nftables packet filter. The researcher who discovered the vulnerability has developed and published a working prototype of the exploit. The exploit works […]

Update for Qubes OS 4.2.1, which uses virtualization to isolate applications

The release of the operating system Qubes 4.2.1 has been announced, implementing the idea of using a hypervisor for strict isolation of applications and OS components (each class of applications and system services operate in separate virtual machines). It is recommended to use a system with 16 GB of RAM (minimum 6 GB) and a 64-bit Intel or AMD CPU with support for VT-x with EPT/AMD-v with RVI and […]

Bubblewrap 0.9 Release: A Layer for Creating Isolated Environments

After a year of development, a new version of the Bubblewrap toolkit 0.9 has been released, used for organizing work in isolated environments, limiting access for individual applications of unprivileged users. In practice, Bubblewrap is used by the Flatpak project as a layer for isolating applications launched from packages. The project code is written in C and is distributed under the LGPLv2+ license. Traditional container isolation technologies for Linux are used […]

Fedora Linux 40 has entered beta testing.

Testing of the beta version of the Fedora Linux 40 distribution has begun. The beta release marks the transition to the final testing phase, where only critical bugs can be fixed. The release is scheduled for April 23. It covers Fedora Workstation, Fedora Server, Fedora Silverblue, Fedora IoT, Fedora CoreOS, Fedora Cloud Base, Fedora Onyx, and Live images provided as spins with user environments K proposed KDE Plasma […]

The Ext2 filesystem driver has been deprecated.

A change has been accepted into the codebase that forms the Linux kernel 6.9, transferring the driver implementing the Ext2 filesystem from the supported category to the deprecated category. The reason given is that the driver only supports 32-bit time counters in inodes, which will overflow on January 19, 2038. For existing partitions, it is recommended to use […]

The demise of Upstart, 32-bit builds, Unity, and Deb packages in Ubuntu has been postponed by 2 years: LTS releases have received an additional two years of support.

According to a blog post from Canonical, Ubuntu 14.04 LTS (the last LTS release with Upstart as the default) will be supported until April 2026, Ubuntu 16.04 — the last official release with Unity 7 as the default desktop environment — will be supported until 2028, Ubuntu 18.04 (the last LTS release with 32-bit architecture support) will be supported until 2030, and Ubuntu 20.04 is the last release with the package […]

The transition to Wayland by default in the SDL3 library has been postponed

The developers of the SDL (Simple DirectMedia Layer) library, aimed at simplifying game and multimedia application development, have canceled the change that would have made Wayland the default protocol in environments supporting both Wayland and X11. The reason mentioned is the existence of unresolved issues in the Wayland ecosystem related to surface locking and FIFO (vsync) implementation. These problems lead to […]

ZenHammer — an attack method for manipulating memory content on AMD Zen platforms

Researchers from the Swiss Federal Institute of Technology Zurich have developed the ZenHammer attack method, a variant of RowHammer attacks intended to modify the contents of individual bits in dynamic random-access memory (DRAM), tailored for platforms with AMD processors. Previous RowHammer attack methods were limited to Intel-based systems, but the conducted research has shown that memory cell distortions can also […]

Vulnerability in the implementation of the NFS server in FreeBSD and OpenBSD

A vulnerability CVE-2024-29937 has been discovered in the NFS server code of the FreeBSD and OpenBSD projects, leading to remote code execution by arbitrary users. This issue has existed since the very first release and affects the latest OpenBSD 7.4 and FreeBSD 14.0 releases. Details will be presented later in a report at the t2 security conference taking place in Helsinki on April 18-19. Source: linux.org.ru

Fedora 41 is set to transition to the DNF5 package manager.

The release of Fedora 41 proposes to switch the default package manager to DNF5. Initially, the transition to DNF5 was planned for Fedora 39, but the migration was postponed due to toolset unpreparedness. Although full functional parity with the old tool has not yet been achieved, the developers believe the distribution is ready for migration, while the missing features […]

Vulnerability in the NFS server of FreeBSD and OpenBSD leading to remote code execution

A critical vulnerability (CVE-2024-29937) has been identified in the implementation of the NFS server used in BSD systems, allowing for remote code execution with root privileges on the server. This issue affects all releases of OpenBSD and FreeBSD, up to OpenBSD 7.4 and FreeBSD 14.0-RELEASE. Detailed information about the vulnerability is not yet disclosed, but it is known that the problem is caused by a logical error not related to memory corruption. […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster