REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
224 reports · page 1 of 6
lwn_kernel · tlp:amber · 7/20/2026, 6:26:55 PM
[$] Fedora grapples with change The Fedora Project is known for, among other things, having a well-defined set of processes for just about everything. It has extensive packaging guidelines that deal with the complexities of creating RPMs to install software, as well as processes for managing the legal questions that arise around shipping software. Fedora also has a well-defined change process for dealing with self-contained technical changes as well as major changes to the d…
Read original ↗https://lwn.net/Articles/1081557lwn_kernel · tlp:amber · 7/20/2026, 3:52:44 PM
Catanzaro: Some changes to GNOME security tracking Michael Catanzaro, who has been managing GNOME security issue tracking since November 2020, has written a blog post that details some changes in how he will be managing GNOME vulnerability reports from now on due to an increase in AI-generated security reports. He will be switching from a 90-day deadline for disclosures to 30 days for issues reported on August 1, or later. " The shorter deadline would probably work bett…
Read original ↗lwn_kernel · tlp:amber · 7/20/2026, 1:15:47 PM
[$] Merging famfs? The famfs filesystem , which is meant to provide shared access to huge memory-resident files on CXL and other devices, returned to the Linux Storage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026. It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025 gathering , but it still has not made its way into the kernel; LWN looked at a discussion about merging famfs back in April 2026.
Read original ↗https://lwn.net/Articles/1082687lwn_kernel · tlp:amber · 7/20/2026, 1:10:02 PM
Security updates for Monday Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, per…
Read original ↗https://lwn.net/Articles/1083708lwn_kernel · tlp:amber · 7/19/2026, 10:11:57 PM
Kernel prepatch 7.2-rc4 The 7.2-rc4 kernel prepatch is out for testing. Linus said: " This whole week I had the feeling that people were starting to go on summer vacation, but running the numbers shows that I must have been wrong - it all looks pretty normal. " Kernel prepatch 7.2-rc4 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Reg…
Read original ↗https://lwn.net/Articles/1083543lwn_kernel · tlp:amber · 7/18/2026, 4:52:04 PM
"Half a Second" — a book on the XZ backdoor Adrian Mastronardi has released a book called Half a Second ; it is a detailed look into the XZ backdoor attempt of 2024. The book is freely available under a (non-free) noncommercial, no-derivatives CC license. Half a Second tells that story as one continuous narrative: the burned-out volunteer who maintained the code alone and was patiently, expertly manipulated into giving it up; the engineer whose half-second of curiosity caugh…
Read original ↗https://lwn.net/Articles/1083466lwn_kernel · tlp:amber · 7/18/2026, 4:41:27 PM
Three stable kernel updates The 7.1.4 , 6.18.39 , and 6.12.96 stable kernel updates have been released; each contains a fairly large set of important fixes. Three stable kernel updates [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernel updates [Posted July 18, 2026 by corbet] The 7.1.4 , 6.18.39 , and 6.12.96 …
Read original ↗https://lwn.net/Articles/1083462lwn_kernel · tlp:amber · 7/17/2026, 5:03:50 PM
Building an Arch Linux aarch64 port for Holo Core (Collabora blog) Collabora has published a blog post about its work with Valve on Holo Core, which is a port of Arch Linux to aarch64 to be used as the the operating system on Valve's 64-bit Arm Steam Frame gaming system. Collabora has released the sources , binary packages , and a container image for aarch64 devices. The post describes some of the challenges in porting Arch Linux to a new architecture, and what remains to be…
Read original ↗https://lwn.net/Articles/1083392lwn_kernel · tlp:amber · 7/17/2026, 3:58:17 PM
[$] Securing BPF LSMs against tampering Since 2020, BPF programs have been able to act as Linux security modules (LSMs). Several projects, including systemd, have been working to use that capability to provide more security to users. Christian Brauner spoke at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit about some of the limitations of using BPF in this way, and the changes he would like to see for systemd's use. In particular, he would like a way t…
Read original ↗https://lwn.net/Articles/1082111lwn_kernel · tlp:amber · 7/17/2026, 1:06:22 PM
Security updates for Friday Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Oracle (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kern…
Read original ↗https://lwn.net/Articles/1083388lwn_kernel · tlp:amber · 7/16/2026, 2:00:05 PM
[$] Sched-ext: enqueue() for sub-schedulers and proxy-execution support The extensible scheduler class (sched_ext) allows the installation of custom CPU schedulers as a set of BPF programs. While sched_ext, in its current form, has already led to a lot of interesting scheduler-development work, the subsystem itself is still undergoing rapid evolution. Among other work, the ability to set up a hierarchy of sub-schedulers is approaching completion, and a longstanding incompati…
Read original ↗https://lwn.net/Articles/1082717lwn_kernel · tlp:amber · 7/16/2026, 1:02:10 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), Debian (chromium, dhcpcd5, and ntfs-3g), Fedora (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), Mageia (openssl, poppler, python-mistune, and tmux), Oracle (389-ds-base, cups, git-lfs, glibc, host-metering, kernel, libsolv, libxml2, nginx:1.24, PackageKit, python-pillow, and qemu-kvm), Red Hat (bui…
Read original ↗https://lwn.net/Articles/1083201lwn_kernel · tlp:amber · 7/16/2026, 1:24:55 AM
[$] LWN.net Weekly Edition for July 16, 2026 Inside this week's LWN.net Weekly Edition: Front : Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE. Briefs : Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1081915lwn_kernel · tlp:amber · 7/15/2026, 4:19:26 PM
[$] Topics in filesystem testing It should come as no surprise that a gathering of filesystem developers would discuss filesystem testing; it has been a mainstay of the Linux Storage, Filesystem, Memory Management, and BPF Summit over the years and the 2026 summit was no exception. Ted Ts'o led the discussion this time; he had a few different topics to raise, including his perception of increasing regressions for ext4 in the stable kernels and what can be done to help reduce…
Read original ↗https://lwn.net/Articles/1082342lwn_kernel · tlp:amber · 7/15/2026, 3:52:13 PM
Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog) The SUSE Security Team Blog has a post with an analysis of seunshare , which is used by SELinux to confine untrusted programs. During a review of version 3.10 of the program, the team identified two local Denial-of-Service (DoS) vectors. Since seunshare is supposed to run on SELinux-enabled systems, it is important to understand what kind of privilege escalation can be achieved when vulnerabilities are expl…
Read original ↗https://lwn.net/Articles/1083076lwn_kernel · tlp:amber · 7/15/2026, 1:35:43 PM
[$] Lockless MPSC FIFO queues for io_uring Processes that use io_uring tend to keep a lot of balls in the air; being able to have many operations underway at any given time is part of the point of that API in the first place. The io_uring subsystem must, as a result, keep track of a lot of tasks that have to be performed at the right time. In current kernels, io_uring uses a standard kernel linked-list primitive to track those work items. As of the 7.2 kernel release, though…
Read original ↗https://lwn.net/Articles/1081871lwn_kernel · tlp:amber · 7/15/2026, 1:19:02 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, ope…
Read original ↗https://lwn.net/Articles/1083044lwn_kernel · tlp:amber · 7/15/2026, 12:49:36 PM
Many old shim versions are still accepted by secure boot The CMU CERT Coordination Center has put out an advisory that many exploitable versions of the shim binary, used to boot Linux on systems with UEFI secure boot enabled, were never added to the revocation list. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operat…
Read original ↗https://lwn.net/Articles/1082940lwn_kernel · tlp:amber · 7/14/2026, 4:50:47 PM
The Linux.org story Rob Kennedy has posted the story of the birth of Linux.org — one of the earliest Linux-related web sites — and its more recent rebirth. The site was founded in May 1994 by Michael McLagan, at a time when Linux itself was barely three years old. Linus Torvalds had only just released it to the world, there was no real way for a newcomer to find their footing, no search engines, no Wikipedia, none of the infrastructure people take for granted now for figurin…
Read original ↗https://lwn.net/Articles/1082901lwn_kernel · tlp:amber · 7/14/2026, 1:41:12 PM
Call for topics for the 2026 Maintainers Summit The Maintainers Summit is an annual, invitation-only gathering of kernel developers and maintainers to discuss development-process issues; see LWN's 2025 Maintainers Summit coverage for an example. The call for topics for the 2026 gathering (Prague, October 8) has gone out. One of the best ways to obtain an invitation to the Summit is with a good topic proposal. For best consideration, topics should be submitted before Jul…
Read original ↗https://lwn.net/Articles/1082838lwn_kernel · tlp:amber · 7/14/2026, 1:16:52 PM
[$] Sending packets directly from BPF Tetragon , the BPF-based security monitoring tool, uses BPF to monitor different aspects of a running kernel and enforce user-specified policies. It sends its data to a user-space process, which forwards the data to a central monitoring service elsewhere in the network, however. This presents a point of vulnerability: if an attacker can kill Tetragon's user-space agent, it won't be able to properly report on the situation. Song Liu, Mahé…
Read original ↗https://lwn.net/Articles/1081696lwn_kernel · tlp:amber · 7/14/2026, 1:16:38 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (imagemagick, p7zip, and redis), Fedora (breezy, calibre, and golang-github-openprinting-ipp-usb), Mageia (ffmpeg, gzip, haproxy, libheif, libtiff, libxml2, packages, perl-List-SomeUtils-XS, and pe…
Read original ↗https://lwn.net/Articles/1082832lwn_kernel · tlp:amber · 7/13/2026, 2:14:08 PM
[$] Shielding running kernels against exploits with BPF Cisco has some unusual challenges when it comes to deploying security patches across the company's many devices running custom kernels. John Fastabend spoke about his work preventing exploits with BPF at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . The technique could substantially reduce the time necessary to respond to kernel vulnerabilities, but it will not be fully effective unless more ho…
Read original ↗https://lwn.net/Articles/1081546lwn_kernel · tlp:amber · 7/13/2026, 1:26:16 PM
Final normal Debian bookworm release Debian has announced the final normal update for Debian 12 ("bookworm"). Long-term-support updates will continue until 2028 . As may be expected from a stable version, the update is mostly limited to security fixes. Still, it may be time for Debian users to look into upgrading to a more recent version. Conveniently, Debian 13 ("trixie") also received an update this weekend, with many of the same security fixes. Final normal Debian bookwo…
Read original ↗https://lwn.net/Articles/1082647lwn_kernel · tlp:amber · 7/13/2026, 12:40:26 PM
Security updates for Monday Security updates have been issued by Debian (chromium, libxfont, mesa, opam, and wireless-regdb), Fedora (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-dulwich, python-idna, python-pillow, python-tornado, sssd, tmux, upower, webkitgtk, xorg-x11-server, and xorg-x11-server-Xwayland), Mageia (libarchive and …
Read original ↗https://lwn.net/Articles/1082642lwn_kernel · tlp:amber · 7/12/2026, 11:29:47 PM
Kernel prepatch 7.2-rc3 The 7.2-rc3 kernel prepatch is out for testing. Linus said: " Things continue to look normal (the 'new normal' with slightly higher rates of commits, although I do get the feeling that we're seeing that slightly balanced out by people starting to go on summer vacation) ". Kernel prepatch 7.2-rc3 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Pas…
Read original ↗https://lwn.net/Articles/1082487lwn_kernel · tlp:amber · 7/10/2026, 3:20:51 PM
[$] An update on the scraper situation Our article " Fighting the AI scraper bot scourge ", published in early 2025, discussed the problem of widespread scraping of web sites in search of training data for large language models and related projects. This activity overwhelms sites with traffic. Over a year after that article is published, the problem is still growing. The hammering of sites by shadowy actors has reached new heights, and the open web is becoming increasingly d…
Read original ↗https://lwn.net/Articles/1080822lwn_kernel · tlp:amber · 7/10/2026, 1:50:40 PM
[$] QBE 1.3: metaprogramming, performance, and cross-platform support QBE , a compact compiler backend developed by Quentin Carbonneaux, is a lightweight alternative to larger compiler backends such as LLVM and GCC. Designed to be small enough for a single developer to understand, QBE uses a static single-assignment (SSA) intermediate representation (IR), supports the C ABI, and serves as the backend for projects such as Hare and the cproc C11 compiler. Frontends emit the te…
Read original ↗https://lwn.net/Articles/1080519lwn_kernel · tlp:amber · 7/10/2026, 1:41:03 PM
Security updates for Friday Security updates have been issued by AlmaLinux (aardvark-dns, cups, edk2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, oci-seccomp-bpf-hook, python-urllib3, and tomcat), Debian (rlottie), Fedora (c-ares, k9s, kind, libXfont2, nmap, pam, perl-DBI, php, python-pendulum, tmux, and xorg-x11-server-Xwayland), Mageia (7zip and ack), Slackware (tigervnc), S…
Read original ↗https://lwn.net/Articles/1082272lwn_kernel · tlp:amber · 7/9/2026, 2:25:18 PM
[$] Kitty chases the mouse Kitty is a terminal emulator that runs on Linux, macOS, and the BSDs, which is notable for its speed and features such as image support and advanced font handling. It is under active development; a recent major release adds a new level of mouse support. Here, we will look at some of those features and show how the program can also be used as platform for text-based applications. Kitty is free software, released under the GPLv3.
Read original ↗https://lwn.net/Articles/1080821lwn_kernel · tlp:amber · 7/9/2026, 1:19:01 PM
Rust 1.97.0 released Version 1.97.0 of the Rust programming language has been released. Changes include using a new symbol-mangling scheme by default, support for denying warnings in Cargo, and an end to the practice of hiding the linker's output after a successful build. Rust 1.97.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscri…
Read original ↗https://lwn.net/Articles/1082032lwn_kernel · tlp:amber · 7/9/2026, 1:00:11 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (389-ds-base, aardvark-dns, buildah, compat-openssl10, freeipmi, frr, gnutls, grafana, grafana-pcp, kernel, kernel-rt, libyang, nginx, openexr, pcs, perl-HTTP-Daemon, postgresql:18, python3.14-pip, skopeo, tomcat9, and wireshark), Debian (chromium and pgextwlist), Fedora (openssh, opkssh, perl-CSS-Minifier-XS, python-jiter, python-nh3, python-pendulum, rust-jiter, and upower), Mageia (openvpn and vi…
Read original ↗https://lwn.net/Articles/1082030lwn_kernel · tlp:amber · 7/9/2026, 1:12:33 AM
[$] LWN.net Weekly Edition for July 9, 2026 Inside this week's LWN.net Weekly Edition: Front : Cryptography API; Iomap explanation; Negative dentries; Faster RCUs and lockless allocation for BPF; Negative dentries; LLMs in memory-management code Briefs : Guix vulnerabilities; OpenSSH 10.4; trusted publishing; kernel archive; CalyxOS; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1080835lwn_kernel · tlp:amber · 7/8/2026, 10:31:34 PM
OpenMandriva: Statement regarding attempted distribution sabotage Over on the OpenMandriva forum , the Linux distribution has reported sabotage of its repositories by a disgruntled contributor with administrative credentials. According to "AngryPenguin", an abusive incident in a distribution Matrix chat led to a user being kicked out of the chat; that " triggered a cascade of events ", which led to people resigning from the distribution. Eventually, one of those people used …
Read original ↗https://lwn.net/Articles/1081884lwn_kernel · tlp:amber · 7/8/2026, 1:14:23 PM
[$] Progress in modernizing kernel cryptography At the 2026 Linux Security Summit North America , Eric Biggers spoke about some of the problems with the kernel's cryptography framework, as well as the recent progress in adding library APIs to allow developers to use cryptographic functions without using the traditional crypto API. He walked through a couple of examples to demonstrate the frailty of the original API and showed how the new library API made life easier for deve…
Read original ↗https://lwn.net/Articles/1077427lwn_kernel · tlp:amber · 7/8/2026, 12:50:59 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (container-tools:rhel8, kernel-rt, libreoffice, nodejs:22, nodejs:24, opentelemetry-collector, perl-HTTP-Daemon, and python-markdown), Debian (dpkg, imagemagick, and postfix), Fedora (betterleaks, docker-compose, firefox, helm, perl-Compress-Raw-Bzip2, perl-IO-Compress, perl-JavaScript-Minifier-XS, python-cramjam, python-fastar, python-pillow-jxl-plugin, python-rignore, and tor), Oracle (grafana, g…
Read original ↗https://lwn.net/Articles/1081798lwn_kernel · tlp:amber · 7/7/2026, 2:27:57 PM
Woodruff: You shouldn't trust trusted publishing William Woodruff, better known online as "yossarian", has published a blog post to make the case that users should not place their trust in trusted publishing : Trusted Publishing is a mechanism for establishing trust between an external machine identity (like a CI/CD workflow) and one or more projects on a package index/registry. The "trust" in "Trusted Publishing" refers to that trust relationship, and not to anything else. …
Read original ↗https://lwn.net/Articles/1081690lwn_kernel · tlp:amber · 7/7/2026, 1:39:34 PM
[$] Faster RCUs and lockless memory allocation Puranjay Mohan shared some of the work he's been doing recently on improving the performance of read-copy-update (RCU) at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit ; his talk would have been nice context to have earlier in the day when Harry Yoo and Alexei Starovoitov led a session about the new kmalloc_nolock() function that allows for lockless allocation from any kernel context, and which interacts …
Read original ↗https://lwn.net/Articles/1081009lwn_kernel · tlp:amber · 7/7/2026, 1:07:58 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (nodejs22 and nodejs24), Fedora (clamav, hplip, kernel, kernel-headers, librabbitmq, mingw-expat, mir, perl-Imager, podman-tui, prometheus-podman-exporter, python-rpds-py, rust-ashpd, rust-busd, rust-gtk4-macros, rust-inferno, rust-quick-xml, rust-reqsign-aws-v4, rust-wayland-scanner, and sandogasa), Oracle (container-tools:rhel8, kernel, mariadb:10.11, mariadb:11.8, nginx, perl:5.32, php, php:7.4, r…
Read original ↗https://lwn.net/Articles/1081644lwn_kernel · tlp:amber · 7/6/2026, 4:13:19 PM
OpenSSH 10.4 released OpenSSH 10.4 has been released. In addition to a number of security and bug fixes, there are a few notable changes; this release adds experimental support for a composite post-quantum signature scheme combining ML-DSA 44 and Ed25519 as described in this IETF draft . With 10.4, if OpenSSH is compiled with sandbox support it will fail on Linux systems that have not enabled SECCOMP or NO_NEW_PRIVS ; prior to this release, sshd would log an error but contin…
Read original ↗https://lwn.net/Articles/1081536