Category: Blog

Vulnerabilities in the Linux kernel exploitable remotely via Bluetooth

A vulnerability has been identified in the Linux kernel (CVE-2022-42896), which could potentially be exploited to enable remote code execution at the kernel level by sending a specially crafted L2CAP packet via Bluetooth. Additionally, another similar issue (CVE-2022-42895) has been found in the L2CAP handler, which may lead to a leak of kernel memory content in configuration information packets. The first vulnerability has been manifested since August […]

Release of Libreboot 20221214, a fully free distribution of Coreboot

The release of the Libreboot 20221214 free boot firmware has been announced. This project represents a fully free branch of the CoreBoot project, providing a binary-free replacement for proprietary UEFI and BIOS firmware responsible for initializing the CPU, memory, peripheral devices, and other hardware components. Libreboot aims to create a system environment that can function entirely without proprietary software, not only at the operating system level, […]

labwc 0.6

labwc is a composite manager for Wayland with features similar to Openbox. It is compatible with Openbox themes. It is built on the wlroots library. Key innovations include: Support for virtual desktops added; Touch device support added (such as tablets and smartphones); Protocols implemented for using virtual keyboards and pointers; Added a mode to pin windows on top of others (ToggleAlwaysOnTop); Arrow rendering ensured […]

Release of QEMU 7.2

The release of QEMU 7.2 has been introduced. As an emulator, QEMU enables running a program compiled for one hardware platform on a system with a completely different architecture, for example, executing an ARM application on an x86-compatible PC. In virtualization mode, QEMU's code execution performance in an isolated environment is close to that of a physical system due to direct execution of instructions on the CPU and involvement of […]

Google has released OSV-Scanner, a vulnerability scanner that considers dependencies

Google has introduced the OSV-Scanner toolkit for checking for unpatched vulnerabilities in code and applications, considering the entire chain of dependencies related to the code. OSV-Scanner allows identifying situations where an application becomes vulnerable due to issues in one of the libraries used as a dependency. Moreover, the vulnerable library may be used indirectly, i.e., invoked through another dependency. The project code […]

The HTTP server hinsightd has been introduced, utilizing the Linux io_uring subsystem

A compact HTTP server, hinsightd, has been released, notable for utilizing the asynchronous I/O interface io_uring provided in the Linux kernel. The server supports the HTTP/1.1 protocol and is designed for low resource consumption while providing essential functionality. For example, hinsightd supports TLS, reverse proxying (rproxy), caching of dynamically generated content in the local filesystem, on-the-fly data compression, seamless restarts without breaking established connections, and connection […]

Update of X.Org Server 21.1.5 and xwayland 22.1.6 addressing 6 vulnerabilities

Corrective releases of X.Org Server 21.1.5 and xwayland 22.1.6 have been published, which is the DDX component (Device-Dependent X) enabling the X.Org Server to run X11 applications in Wayland-based environments. The new versions fix 6 vulnerabilities that could potentially be exploited for privilege escalation in systems where the X server runs with root permissions, as well as for remote code execution in […]

Release of the cryptographic library LibreSSL 3.7.0

The developers of the OpenBSD project have introduced a portable release of the LibreSSL 3.7.0 package, which is a fork of OpenSSL aimed at providing a higher level of security. The LibreSSL project focuses on quality support for SSL/TLS protocols by removing unnecessary functionality, adding additional protections, and significantly cleaning up and reworking the codebase. The LibreSSL 3.7.0 release is considered experimental, in which […]

Release of Firefox 108

The release of the Firefox 108 web browser has been announced. Additionally, an update for the long-term support branch—102.6.0—has been formed. The Firefox 109 branch is soon to enter beta testing, with its release scheduled for January 17. Key innovations in Firefox 108 include the addition of the keyboard shortcut Shift+ESC for quick access to the process manager page (about:processes), which allows evaluation of which processes and internal […]

Release of Git source code management system 2.39.

After two months of development, the release of the distributed version control system Git 2.39 has been published. Git is one of the most popular, reliable, and high-performance version control systems, providing flexible tools for non-linear development based on branching and merging. To ensure the integrity of the history and resilience to 'backdating' changes, implicit hashing of all prior history is used in every commit, […]

Release of the OpenNMT-tf 2.30 translation system

The release of the OpenNMT-tf 2.30.0 (Open Neural Machine Translation) machine translation system has been announced, utilizing machine learning methods. The code for the modules developed by the OpenNMT-tf project is written in Python, uses the TensorFlow library, and is distributed under the MIT license. Simultaneously, a variant of OpenNMT based on the PyTorch library is being developed, which differs at the level of supported capabilities. Additionally, OpenNMT based on PyTorch is presented as more […]

Chrome has proposed memory and energy-saving modes. The deactivation of the second version of the manifest has been postponed.

Google has announced the implementation of Memory Saver and Energy Saver modes in the Chrome browser, which they plan to roll out to Chrome users for Windows, macOS, and ChromeOS over the coming weeks. The Memory Saver mode significantly reduces RAM consumption by freeing up memory used by inactive tabs, allowing it to provide the necessary resources […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster