Security updates have been issued by Fedora (freerdp, gnome-boxes, gnome-connections, gnome-remote-desktop, guacamole-server, hydra, java-1.8.0-openjdk-aarch32, medusa, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugin…
Stable kernel 5.15.5
The 5.15.5 stable kernel has been
released. As usual, it contains lots of important fixes throughout the
kernel tree. Users should upgrade.
Security updates for Thursday
Security updates have been issued by Fedora (busybox, getdata, and php), Mageia (couchdb, freerdp, openexr, postgresql, python-reportlab, and rsh), openSUSE (bind, java-1_8_0-openjdk, and kernel), SUSE (java-1_7_0-openjdk), and Ubuntu (icu).
…
Security updates for Friday
Security updates have been issued by Arch Linux (chromium, grafana, kubectl-ingress-nginx, and opera), Debian (netkit-rsh and salt), Fedora (freeipa and samba), Mageia (opensc, python-django-filter, qt4, tinyxml, and transfig), openSUSE (opera a…
Two more stable kernels
Greg Kroah-Hartman has released two more stable kernels. 5.14.20 reverts three patches from the
5.14.19 release, while 5.10.80 is one of the
massive updates mentioned yesterday. The
other massive release mentioned, 5.15.3, is still under
review…
Security updates for Thursday
Security updates have been issued by CentOS (binutils, firefox, flatpak, freerdp, httpd, java-1.8.0-openjdk, java-11-openjdk, kernel, openssl, and thunderbird), Fedora (python-sport-activities-features, rpki-client, and vim), and Red Hat (devtoo…
[$] Rollercoaster: group messaging for mix networks
Even encrypted data sent on the internet leaves some footprints—metadata
about where packets originate, where they are bound, and when they are sent.
Mix networks are
meant to hide that metadata by routing packets through various intermediate
n…
[$] Trojan Source and Python
The Trojan Source vulnerabilities have been
rippling through various development
communities since their disclosure on
November 1. The oddities that can arise when handling Unicode, and
bidirectional Unicode in particular, in a programmin…
ClusterFuzzLite: Continuous fuzzing for all (Google Security blog)
Over on the Google Security blog, Jonathan Metzman announced the release of ClusterFuzzLite, which is “a continuous fuzzing solution that runs as part of CI/CD workflows to find vulnerabilities faster than ever before”. ClusterFuzzLite is a de…
Eight new stable kernels
Greg Kroah-Hartman has announced the release of eight stable kernels: 5.15.2, 5.14.18, 5.10.79, 5.4.159, 4.19.217, 4.14.255, 4.9.290, and 4.4.292. They contain a relatively small set
of important fixes, but, as usual, users should upgrade.
…