REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
224 reports · page 4 of 6
lwn_kernel · tlp:amber · 6/11/2026, 2:33:27 PM
[$] Automatic mTHP creation in 7.2 The Linux kernel has long tried to use huge pages as a way to improve performance, sometimes with more success than others. The size of huge pages has traditionally been imposed by the hardware, which typically only offers a couple of relatively large options. In more recent times, though, the use of multi-size transparent huge pages (mTHPs), with more flexible sizing implemented in software, has been growing. If all goes well, the 7.2 deve…
Read original ↗https://lwn.net/Articles/1077208lwn_kernel · tlp:amber · 6/11/2026, 1:08:29 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, podman, poppler, and postgresql-jdbc), Debian (chromium, jackson-core, libdbi-perl, and libinput), Fedora (httpd, rust, and xmlstarlet), Mageia (openssh, postfix, and roundcubemail), Oracle (frr, kernel, libyang, n, postgresql-jdbc, and unbound), Red Hat (.NET 10.0, .NET 8.0, .NET 9.0, redis, and redis:7), SUSE (agama-web-ui, cockpit, cosign, glibc, google-cloud-sap-a…
Read original ↗lwn_kernel · tlp:amber · 6/11/2026, 12:02:58 AM
[$] LWN.net Weekly Edition for June 11, 2026 Inside this week's LWN.net Weekly Edition: Front : Suspicious AI activity in Fedora; fork() + exec(); splice() + vmsplice(); BPF loop verification; fanotify; trusted publishing. Briefs : CA age bill; Bundler cooldowns; insecure code completion; Asahi and macOS 27 beta; Buildroot 2026.05; Ubuntu MATE; rsync 3.4.4; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1076254lwn_kernel · tlp:amber · 6/10/2026, 4:43:14 PM
Larson: Are insecure code completions a vulnerability? Seth Larson, the Python Software Foundation's security developer-in-residence , has written about the difficulty in classifying insecure code completion in the PyCharm IDE using its Full Line code completion plugin. Larson discovered that the plugin, which uses a local "deep learning module" to offer code completions, suggests code that would lead to severe vulnerabilities. He was unsure whether it warranted a CVE or not…
Read original ↗https://lwn.net/Articles/1077413lwn_kernel · tlp:amber · 6/10/2026, 2:35:25 PM
[$] AI agent runs amok in Fedora and elsewhere Agentic AI systems can be used to do a variety of things autonomously on behalf of a human user: open or manage bugs, generate code, submit pull-requests, and (apparently) even complain about rejection . In May, a Fedora developer discovered that an allegedly rogue agent had been pestering the project in a number of ways: reassigning bugs, fabricating unhelpful replies to bugs, and even persuading maintainers to merge questionab…
Read original ↗https://lwn.net/Articles/1077035lwn_kernel · tlp:amber · 6/10/2026, 2:03:16 PM
Buildroot 2026.05 released Version 2026.05 of the Buildroot tool has been released. Buildroot simplifies and automates the process of building embedded Linux systems using cross-compilation. Notable changes in this release include support for Arm Neoverse cores, addition of XFS rootfs generation, as well as many package updates and bug fixes. See the CHANGES file for the full list. Buildroot 2026.05 released [LWN.net] LWN .net News from the source Content Weekly Edition Arc…
Read original ↗https://lwn.net/Articles/1077379lwn_kernel · tlp:amber · 6/10/2026, 1:09:28 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (poppler), Debian (dnsmasq, mistral, okular, openssl, poppler, and strongswan), Fedora (exim, firefox, pcs, putty, and xorg-x11-server), Mageia (freeciv, golang-x-net, jq, libssh, libxmp, libxpm, minetest, ruby-net-ssh, tor, and wireshark), SUSE (389-ds, ack, agama-web-ui, amazon-ssm-agent, avahi, dpkg, elemental-register, elemental-system-agent, elemental-toolkit, ggml-devel-9500, go1.25, go1.26, …
Read original ↗https://lwn.net/Articles/1077362lwn_kernel · tlp:amber · 6/9/2026, 6:00:16 PM
Future of Ubuntu MATE Thomas Ward has published an update about the future of the Ubuntu MATE project, which did not have a 26.04 release with the other Ubuntu flavors in April: There is a new team working on Ubuntu MATE who have stepped up to help take over flavor management. They haven't formally introduced themselves yet, but I can safely say that other developers HAVE stepped up for the future of the MATE flavor, despite its prior team lead having stepped down. [...…
Read original ↗https://lwn.net/Articles/1077221lwn_kernel · tlp:amber · 6/9/2026, 5:50:49 PM
[$] Eliminating long-lived credentials with trusted publishing Trusted publishing is an authentication mechanism that relies on short-lived credentials to reduce the risk of supply-chain attacks. At the 2026 Open Source Summit North America , Mike Fiedler walked the audience through why trusted publishing exists, how it works, and made the case for its adoption. It is not a silver bullet against all attacks, but it does offer protection against theft of long-lived credential…
Read original ↗https://lwn.net/Articles/1076205lwn_kernel · tlp:amber · 6/9/2026, 2:30:25 PM
Asahi Linux warns users not to upgrade to macOS 27 beta The Asahi Linux project, which brings Linux support to Apple Arm-based Macs, has warned its users not to upgrade to the macOS 27 "Golden Gate" beta. Apple has changed how the boot picker and Startup Disk applications detect valid OS boot volumes. When using either from macOS 27, your Asahi partition will not be visible! We believe this to be a bug, and have filed a report (FB22994760). If you have already upgr…
Read original ↗https://lwn.net/Articles/1077209lwn_kernel · tlp:amber · 6/9/2026, 1:37:36 PM
[$] BPF loop verification with scalar evolution The BPF verifier has, in the course of wrestling with the difficult problem of statically analyzing loops, grown special support for many kinds of loops over its history, but its fundamental approach to simple for loops has not changed. When it encounters a loop, it evaluates it, iteration by iteration, until reaching an exit condition — a process that can cause the verifier to mistakenly hit the limit on the number of allowed …
Read original ↗https://lwn.net/Articles/1076121lwn_kernel · tlp:amber · 6/9/2026, 1:03:24 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (bind and libyang), Debian (keystone and openssl), Fedora (mingw-objfw, objfw, sentencepiece, and tailscale), Mageia (packagekit and suricata), Oracle (bind, bind9.16, go-toolset:ol8, ImageMagick, kernel, samba, and vim), SUSE (apache-commons-lang3, apache-commons-text, apache-commons- configuration2, apache-commons-cli, apache-commons-io, apache-commons-codec, avahi, busybox, chromedriver, chromium,…
Read original ↗https://lwn.net/Articles/1077163lwn_kernel · tlp:amber · 6/9/2026, 12:52:58 PM
Linux App Summit 2026 (Heise) Heise is carrying a report from the Linux App Summit , held in Berlin in May. The slightly more than a dozen talks were symbolically framed between the opening keynote by systemd creator Lennart Poettering and the closing talk by Jorge Castro, initiator of the Universal Blue project, from which the modern Linux systems Bluefin and Bazzite emerged. Both Castro and Poettering call for a fundamental rethink of how Linux operating systems are delive…
Read original ↗https://lwn.net/Articles/1077084lwn_kernel · tlp:amber · 6/9/2026, 11:44:19 AM
Three stable kernels for Tuesday Greg Kroah-Hartman has announced the release of the 7.0.12 , 6.18.35 , and 6.12.93 stable kernels. Each contains important fixes throughout the tree. Users are advised to upgrade. Three stable kernels for Tuesday [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernels for Tuesday […
Read original ↗https://lwn.net/Articles/1077078lwn_kernel · tlp:amber · 6/8/2026, 3:35:10 PM
[$] An update on fanotify In a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Amir Goldstein updated attendees on the fanotify filesystem-event monitoring subsystem. He wanted to describe changes that had come in the last year or so, as well as upcoming features and some remaining challenges in his efforts to use fanotify for hierarchical storage management (HSM). Fanotify is the user-space API for monitoring files, direct…
Read original ↗https://lwn.net/Articles/1075829lwn_kernel · tlp:amber · 6/8/2026, 2:23:23 PM
rsync 3.4.4 released with regression fixes Andrew Tridgell has announced the release of rsync 3.4.4 with fixes for the regressions introduced in the 3.4.3 release. He also notes there will be an rsync 3.5.0 soon, with many more security updates: As part of the 3.5.0 release update I have created a rsync-security@lists.samba.org mailing list for anyone who is willing to do testing of the 3.5.0 release. The idea is to try to reduce the chance of more regressions by expanding t…
Read original ↗https://lwn.net/Articles/1076989lwn_kernel · tlp:amber · 6/8/2026, 1:32:33 PM
Security updates for Monday Security updates have been issued by AlmaLinux (bind, bind9.16, frr, kernel, kernel-rt, libexif, mysql, php, and unbound), Debian (apache2, chromium, glibc, gsasl, jackson-core, libxml2, nginx, request-tracker4, request-tracker5, tomcat10, tomcat11, and tomcat9), Fedora (chromium, firefox, haveged, keylime, libinput, libssh2, nasm, perl-CryptX, rust, thunderbird, and webkitgtk), Mageia (cockpit, golang-x-crypto, golang-x-sys-devel, kernel, kmod-vi…
Read original ↗https://lwn.net/Articles/1076983lwn_kernel · tlp:amber · 6/8/2026, 12:28:06 AM
Kernel prepatch 7.1-rc7 The 7.1-rc7 kernel prepatch is out for testing. Linus said: " Anyway, as things look now this is the last rc. Something can obviously always come up and force us to change that, but please give rc7 a whirl and keep testing for one more week. " Kernel prepatch 7.1-rc7 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe…
Read original ↗https://lwn.net/Articles/1076835lwn_kernel · tlp:amber · 6/5/2026, 2:06:43 PM
[$] Moving beyond fork() + exec() Since the earliest days of Unix, two of the core process-oriented system calls have been fork() , which creates a child process as a copy of the parent, and exec() , which runs a new program in the place of the current one. In Linux kernels, those system calls are better known as clone() and execve() , but the core functionality remains the same. While there is elegance to this process-creation model, there are shortcomings as well. A recent…
Read original ↗https://lwn.net/Articles/1076018lwn_kernel · tlp:amber · 6/5/2026, 12:57:00 PM
Ruby's Bundler adds a cooldown feature Version 4.0.13 of Ruby's Bundler package-manager has added dependency cooldowns in order to help mitigate the effect of supply-chain attacks: Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. Bundler 4.0.13 introduces cooldown, a time-based filter that refuses to resolve to a version unt…
Read original ↗https://lwn.net/Articles/1076526lwn_kernel · tlp:amber · 6/5/2026, 12:56:47 PM
Security updates for Friday Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, ru…
Read original ↗https://lwn.net/Articles/1076605lwn_kernel · tlp:amber · 6/4/2026, 10:22:17 PM
Dave Airlie on Linux Kernel Maintenance (SE Radio) The Software Engineering Radio podcast has put up an interview with graphics maintainer Dave Airlie . Much of what is in there will not be news to LWN readers, but it is an interesting overview of the life of a large-subsystem maintainer. I was talking to a few of the Rust people, and I thought: these are very young people, these are a group of people in their 20s, maybe 30s, they are a younger cohort of developers than the …
Read original ↗https://lwn.net/Articles/1076478lwn_kernel · tlp:amber · 6/4/2026, 4:22:46 PM
[$] Splicing out vmsplice() The splice() and vmsplice() system calls are meant to improve performance for certain data-movement tasks by minimizing (or avoiding altogether) system calls and the copying of data. They also have a long history of security problems. The recent flood of LLM-discovered vulnerabilities has drawn attention, once again, to splice() and vmsplice() ; as a result, they may end up being removed altogether.
Read original ↗https://lwn.net/Articles/1075838lwn_kernel · tlp:amber · 6/4/2026, 2:53:00 PM
One step forward, two steps back on CA age bill (EFF Deeplinks Blog) The EFF has a blog post looking at a new bill in California that would exempt open-source operating systems from the Digital Age Assurance Act passed last year, but has problems of its own: While the open source exemption, if passed, would improve the law, the remaining amendments proposed by AB 1856 would require all web browsers and websites to request and collect users' ages. This is an expansion of last…
Read original ↗https://lwn.net/Articles/1076377lwn_kernel · tlp:amber · 6/4/2026, 1:17:19 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), Debian (ceph and sudo), Fedora (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), Mageia (lxc), Oracle (expat, gnutls, kernel, php:8.2, thunderbird, and uek-kernel), Slackware (httpd, net, proftpd, tigervnc, and xorg), SUSE (apache-sshd, app…
Read original ↗https://lwn.net/Articles/1076364lwn_kernel · tlp:amber · 6/4/2026, 1:31:14 AM
[$] LWN.net Weekly Edition for June 4, 2026 Inside this week's LWN.net Weekly Edition: Front : MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module. Briefs : Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust 1.96.0; rsync; Vim Classic 8.3; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1074950lwn_kernel · tlp:amber · 6/3/2026, 3:02:35 PM
[$] Open-source security is not a solo activity Over time, many open-source maintainers face the same problem: they lack the time to do all of the work that their project needs, and no one else is stepping up to provide adequate help. Maintainers, though, are often reluctant to throw in the towel. The result is suboptimal all around; the maintainer is stressed out, project quality suffers, and users face security risks that they may not be fully aware of. At the 2026 Open So…
Read original ↗https://lwn.net/Articles/1075741lwn_kernel · tlp:amber · 6/3/2026, 1:14:39 PM
[$] BPF in the agentic era Alexei Starovoitov gave " less of a presentation, more of a scream of realization " at the BPF track of the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . He shared a set of ideas for how BPF could change to avoid being swept away by the sea-change in programming represented by modern large language models (LLMs) and the coding agents based on them. In a follow-up session, the discussion covered more problems with how coding ag…
Read original ↗https://lwn.net/Articles/1075067lwn_kernel · tlp:amber · 6/3/2026, 1:00:46 PM
Tridgell: rsync and outrage Andrew Tridgell has written a blog post responding to complaints that he has begun using LLM tools in his work maintaining rsync : Like many developers of open source packages I've been hit by a flood of security reports lately in my role as the rsync maintainer. Many of those reports are AI generated (not all though, there are some notable ones with very careful and high quality manual analysis). As this flood started to get more intense I realis…
Read original ↗https://lwn.net/Articles/1076040lwn_kernel · tlp:amber · 6/3/2026, 12:59:17 PM
Security updates for Wednesday Security updates have been issued by Debian (php-twig), Fedora (hplip, python-wsgidav, roundcubemail, and xorg-x11-server), Oracle (compat-openssl10, httpd:2.4, and kernel), Red Hat (osbuild-composer), SUSE (busybox, cloudflared, cockpit, cups, ffmpeg-4, gnutls, google-osconfig-agent, helm, hplip, kernel, kubelogin, libjxl, libsoup, libunbound8, LibVNCServer-devel, mapserver, nvidia-open-driver-G06-signed, nvidia-open-driver-G07-signed, openssh…
Read original ↗https://lwn.net/Articles/1076117lwn_kernel · tlp:amber · 6/2/2026, 6:35:52 PM
[$] Caching for extended attributes Extended attributes (xattrs) provide a way to attach key/value metadata to inodes—files, directories, and the like—in a filesystem. As with many Linux filesystems, the FUSE filesystem supports xattrs. In a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , FUSE maintainer Miklos Szeredi led a discussion about caching xattrs in kernel memory; he would like to create some common infrastructure…
Read original ↗https://lwn.net/Articles/1074919lwn_kernel · tlp:amber · 6/2/2026, 1:33:43 PM
[$] Trying to make sense of package-manager metadata Package managers for operating systems and programming languages have been around for decades. Each package manager, and its accompanying packaging format, has been shaped by the needs of its respective ecosystem, but there is a growing need to make use of package metadata for more than software management: for example, in vulnerability scans, software bills of materials (SBOMs), and more. On May 19, Damián Vicino spo…
Read original ↗https://lwn.net/Articles/1074908lwn_kernel · tlp:amber · 6/1/2026, 8:55:10 PM
Ombredanne: An AI agent ported our codebase from Python to Rust Over on the AboutCode blog, lead maintainer Philippe Ombredanne writes about an agentic LLM system porting the ScanCode Toolkit to Rust. In the process, the LLM (or the people behind it) infringed the ScanCode trademark, stripped copyright and license notices, " and started an outreach campaign, without ever engaging the AboutCode community ". Ironically, the toolkit is used to scan source code and binaries in o…
Read original ↗https://lwn.net/Articles/1075832lwn_kernel · tlp:amber · 6/1/2026, 6:59:43 PM
[$] Representing the true signatures of kernel functions Optimizing compilers can, under some circumstances, infer when a parameter to a function is not needed, and remove it. This is all well and good until the kernel's tracing or BPF subsystems need information on how to call the function or where its arguments are stored. Alan Maguire and Yonghong Song spoke at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit about their work on recording information …
Read original ↗https://lwn.net/Articles/1073762lwn_kernel · tlp:amber · 6/1/2026, 5:38:56 PM
Seven stable kernels for the first day of June Greg Kroah-Hartman has announced the release of the 7.0.11 , 6.18.34 , 6.12.92 , 6.6.142 , 6.1.175 , 5.15.209 , and 5.10.258 stable kernels. As usual, each contains important fixes throughout the tree, including a fix for the " CIFSwitch " vulnerability ( CVE-2026-46243 ) which could allow a local-privilege-escalation exploit. Users are advised to upgrade. Seven stable kernels for the first day of June [LWN.net] LWN .net News f…
Read original ↗https://lwn.net/Articles/1075806lwn_kernel · tlp:amber · 6/1/2026, 2:39:35 PM
DistroWatch turns 25 The DistroWatch site is celebrating its 25th anniversary . " All in all, it has been an incredible ride. Many of you who read these pages regularly know that downloading and testing distributions is a highly addictive pastime. I have been an avid distro-hopper for the last 25 years and I don't see myself abandoning this activity for many more years to come. " Congratulations to Ladislav Bodnar and all the others who have kept that resource going for so l…
Read original ↗https://lwn.net/Articles/1075766lwn_kernel · tlp:amber · 6/1/2026, 2:22:19 PM
[$] Reconsidering x32 — again The x32 ABI was meant to be the best of both worlds, providing the expanded registers and instruction set of the x86-64 architecture while preserving the lower memory use of 32-bit systems. The Linux kernel has supported x32 since the 3.4 release in 2012. The initial excitement around x32 did not last, though, and kernel developers are considering removing that support — and not for the first time. Even the most unloved features tend to have a f…
Read original ↗https://lwn.net/Articles/1074897lwn_kernel · tlp:amber · 6/1/2026, 2:05:04 PM
Multiple redhat-cloud-services npm packages compromised (StepSecurity Blog) StepSecurity is reporting that a number of npm packages in the @redhat-cloud-services scope include malware that runs automatically on every npm install : The payload is a multi-stage credential harvester that sweeps GitHub Actions secrets along with AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm, and CircleCI tokens, and it is purpose-built to evade detection, including an explicit attempt to byp…
Read original ↗https://lwn.net/Articles/1075742lwn_kernel · tlp:amber · 6/1/2026, 1:20:00 PM
Fedora F44 election interviews published The Fedora Project has published interviews with candidates running for the open seats on the Fedora Council , Fedora Engineering Steering Committee , Fedora Mindshare Committee , and EPEL Steering Committee . Voting is open through Friday, June 12 at 23:59 UTC. Fedora F44 election interviews published [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FA…
Read original ↗https://lwn.net/Articles/1075736lwn_kernel · tlp:amber · 6/1/2026, 1:04:09 PM
Security updates for Monday Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), Debian (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), Fedora (chromium, djvulibre, docker-compose, giflib, haveged, libsoup3, libssh2, mingw-objfw, netatalk, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more,…
Read original ↗https://lwn.net/Articles/1075733