REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
224 reports · page 6 of 6
lwn_kernel · tlp:amber · 5/13/2026, 1:09:08 PM
Sovereign Tech Fund invests in KDE The KDE project has announced that it has been awarded over €1 million from the Sovereign Tech Fund to improve its desktop-environment software. " The investment will be used to strengthen the structural reliability and security of KDE's core infrastructure, including Plasma, KDE Linux, and the frameworks underlying its communication services. " Sovereign Tech Fund invests in KDE [LWN.net] LWN .net News from the source Content Weekly …
Read original ↗https://lwn.net/Articles/1072565lwn_kernel · tlp:amber · 5/12/2026, 5:25:31 PM
[$] Using dma-bufs for read and write operations The kernel's dma-buf subsystem provides a way for drivers to share memory buffers, usually in order to support efficient device-to-device I/O . At the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Pavel Begunkov, assisted by Kanchan Joshi, led a joint session of the storage and memory-management tracks to explore ways to make the use of dma-bufs more efficient yet, and to make them available for read and …
Read original ↗lwn_kernel · tlp:amber · 5/12/2026, 1:24:49 PM
[$] Scaling transparent huge pages to 1GB As a general rule, when developers talk about huge pages, they are referring to PMD-level pages that are 1MB or 2MB in size, depending on the CPU architecture. Most CPUs can support other huge-page sizes, though. On x86 systems, PUD-level huge pages hold 1GB of data. Providing such large pages transparently to processes has generally not been considered as either feasible or desirable, but Usama Arif is trying to change that assessme…
Read original ↗https://lwn.net/Articles/1071716lwn_kernel · tlp:amber · 5/12/2026, 1:17:34 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (freerdp, glib2, libsoup3, and openexr), Debian (dnsmasq, p7zip, p7zip-rar, python-authlib, and rails), Fedora (chromium, firefox, httpd, and nss), SUSE (java-25-openj9, krb5, libmodsecurity3, and mcphost), and Ubuntu (imagemagick, linux, linux-aws, linux-aws-fips, linux-aws-hwe, linux-azure-4.15, linux-fips, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-hwe, linux-kvm, linux-oracle, linux-azure, …
Read original ↗https://lwn.net/Articles/1072498lwn_kernel · tlp:amber · 5/11/2026, 2:35:53 PM
Stenberg: Mythos finds a curl vulnerability Daniel Stenberg has published a lengthy article on his thoughts on Anthropic's Mythos, which the company decided was too dangerous for wide public release. My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos.…
Read original ↗https://lwn.net/Articles/1072325lwn_kernel · tlp:amber · 5/11/2026, 1:35:31 PM
Two stable kernels with Dirty Frag fixes Greg Kroah-Hartman has released the 7.0.6 and 6.18.29 stable kernels with Hyunwoo Kim's patch for the second vulnerability ( CVE-2026-43500 ) reported with Dirty Frag and Copy Fail 2 . All users are advised to upgrade. Two stable kernels with Dirty Frag fixes [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password…
Read original ↗https://lwn.net/Articles/1072311lwn_kernel · tlp:amber · 5/11/2026, 1:35:25 PM
[$] Providing 64KB base pages with 4KB kernels, two different ways Some CPU architectures are able to run with a number of different base-page sizes; using a larger size can often result in better performance at the cost of increased memory use. Other architectures are more limited. At the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , two sessions in the memory-management track explored options for letting processes run with 64KB page sizes when the und…
Read original ↗https://lwn.net/Articles/1071484lwn_kernel · tlp:amber · 5/11/2026, 1:21:40 PM
Debian to require reproducible builds Paul Gevers has slipped an interesting bit of news into a " bits from the release team " message: Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages. Since yesterday, we have enabled our migration software to block migration of new packages that can't be reproduced or existing packages (in testing) that regress in reproducibility. As Gioele Barabucci pointed…
Read original ↗https://lwn.net/Articles/1072314lwn_kernel · tlp:amber · 5/11/2026, 1:10:02 PM
Security updates for Monday Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), Mageia (firefox, nss, rootcerts, openvpn, thunderbird, and vim), Oracle (corosync, freeipmi, gstreame…
Read original ↗https://lwn.net/Articles/1072301lwn_kernel · tlp:amber · 5/10/2026, 11:23:10 PM
Kernel prepatch 7.1-rc3 Linus has released 7.1-rc3 for testing. " I think this answers the 'is 7.1 continuing the larger size pattern that we saw with 7.0?' question, and the answer is yes: that wasn't a fluke brought on by a .0 release - it simply seems to be the new normal. " Kernel prepatch 7.1-rc3 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in …
Read original ↗https://lwn.net/Articles/1072100lwn_kernel · tlp:amber · 5/8/2026, 7:50:34 PM
More stable kernels with partial Dirty Frag fixes Greg Kroah-Hartman has released the 6.1.171 , 5.15.205 , and 5.10.255 stable kernels, quickly followed by 6.1.172 and 5.15.206 kernels. This is another round of stable kernels to provide fixes for one of the CVEs ( CVE-2026-43284 ) assigned following the Dirty Frag and Copy Fail 2 security disclosures. There is not, yet, a stable kernel with a fix for CVE-2026-43500 , though a patch to fix the second half is in the …
Read original ↗https://lwn.net/Articles/1071483lwn_kernel · tlp:amber · 5/8/2026, 4:30:46 PM
[$] Forgejo "carrot disclosure" raises security questions An unusual, some might say hostile, approach to disclosing an alleged remote-code-execution (RCE) flaw in the Forgejo software-collaboration platform has sparked a multifaceted conversation. A so-called " carrot disclosure " in April has raised questions about the researcher's methods of unveiling a security problem, Forgejo's security policies, and the project's overall security posture.
Read original ↗https://lwn.net/Articles/1071499lwn_kernel · tlp:amber · 5/8/2026, 1:36:05 PM
killswitch for short-term emergency vulnerability mitigation It seems that we are in for an extended period of the disclosure of vulnerabilities before fixes become available. One possible way of coping with this flood might be the killswitch proposal from Sasha Levin. In short, killswitch can immediately disable access to specific functionality in a running kernel, essentially blasting a vulnerable path (and its associated functionality) out of existence until a fix can be …
Read original ↗https://lwn.net/Articles/1071861lwn_kernel · tlp:amber · 5/8/2026, 1:20:57 PM
[$] A 2026 DAMON update The kernel's DAMON subsystem provides user-space monitoring and management of system memory. DAMON is developing rapidly, so an update on its progress has become a regular feature of the annual Linux Storage, Filesystem, Memory Management, and BPF Summit . This tradition continued at the 2026 gathering with an update from DAMON creator SeongJae Park covering a long list of new capabilities — tiering, data attributes monitoring, transparent huge pages,…
Read original ↗https://lwn.net/Articles/1071256lwn_kernel · tlp:amber · 5/8/2026, 1:13:53 PM
Security updates for Friday Security updates have been issued by AlmaLinux (libsoup and mingw-libtiff), Debian (apache2, chromium, lcms2, libreoffice, and prosody), Fedora (openssl and perl-Starman), Oracle (git-lfs, libsoup, and perl-XML-Parser), Slackware (libgpg, mozilla, and php), SUSE (389-ds, cairo, cf-cli, chromedriver, cri-tools, freeipmi, gnutls, grafana, java-11-openjdk, java-17-openjdk, jetty-minimal, libmariadbd-devel, librsvg, mesa, mozjs52, mutt, nix, opencrypt…
Read original ↗https://lwn.net/Articles/1071859lwn_kernel · tlp:amber · 5/8/2026, 9:49:05 AM
Four stable kernels with partial fixes for Dirty Frag Greg Kroah-Hartman has announced the release of the 7.0.5 , 6.18.28 , 6.12.87 , and 6.6.138 stable kernels. These kernels contain a partial fix for the Dirty Frag and Copy Fail 2 security flaws. Kroah-Hartman has confirmed that a second patch is required, but it is still in development and has not yet been merged. Four stable kernels with partial fixes for Dirty Frag [LWN.net] LWN .net News from the source Cont…
Read original ↗https://lwn.net/Articles/1071775lwn_kernel · tlp:amber · 5/7/2026, 8:25:43 PM
Dirty Frag: a zero-day universal Linux LPE Hyunwoo Kim has announced the Dirty Frag security flaw, a local-privilege-escalation (LPE) vulnerability similar to the recently disclosed Copy Fail flaw: Because the embargo has now been broken, no patches or CVEs exist for these vulnerabilities. After consultation with the linux-distros@vs.openwall.org maintainers, and at the maintainers' request, I am publicly releasing this Dirty Frag document. As with the previous Copy Fail vul…
Read original ↗https://lwn.net/Articles/1071719lwn_kernel · tlp:amber · 5/7/2026, 2:42:35 PM
[$] A new era for memory-management maintainership On April 21, Andrew Morton let it be known that he intends to begin stepping away from the maintainership of kernel's memory-management subsystem — a responsibility he has carried since before memory management was even seen as its own subsystem. At the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit, one of the first sessions in the memory-management track was devoted to how the maintainership would be man…
Read original ↗https://lwn.net/Articles/1070994lwn_kernel · tlp:amber · 5/7/2026, 2:10:52 PM
An update on KDE's Union style engine Arjen Hiemstra has published an article on the status of the Union project: a single system to support all of KDE's technologies used for styling applications. The work on Union's Breeze implementation has progressed to the point where it is very hard to distinguish whether or not you are running the Union version. We have also tested with a bunch of applications and made sure that any differences were fixed. So we are at a stage where w…
Read original ↗https://lwn.net/Articles/1071703lwn_kernel · tlp:amber · 5/7/2026, 1:10:37 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), Mageia (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, p…
Read original ↗https://lwn.net/Articles/1071700lwn_kernel · tlp:amber · 5/7/2026, 6:36:28 AM
Three stable kernel updates The 7.0.4 , 6.18.27 , and 6.12.86 stable kernels have been released; each contains another set of important fixes. Three stable kernel updates [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernel updates [Posted May 7, 2026 by corbet] The 7.0.4 , 6.18.27 , and 6.12.86 stable kernels h…
Read original ↗https://lwn.net/Articles/1071568lwn_kernel · tlp:amber · 5/7/2026, 12:01:08 AM
[$] LWN.net Weekly Edition for May 7, 2026 Inside this week's LWN.net Weekly Edition: Front : LLMs and security; restartable sequences and TCMalloc; Fedora and GNOME bug reports; Prolly trees; Arm on s390. Briefs : NHS open source; Alpine outage; GCC 16.1; Incus 7.0 LTS; NetHack 5.0.0; PHP license; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1070466lwn_kernel · tlp:amber · 5/6/2026, 2:56:20 PM
[$] LLM-driven security reports disrupt coordinated disclosure Predictions that LLM tools would cause a surge in reports of security vulnerabilities have, unquestionably, borne out. As expected, maintainers are having to wade through more security reports than ever before; in addition, LLM tools are disrupting traditional-coordinated disclosure practices as well. The method of Copy Fail 's disclosure, in particular, left vendors, projects, and users scrambling. In addition, …
Read original ↗https://lwn.net/Articles/1070698lwn_kernel · tlp:amber · 5/6/2026, 1:53:58 PM
Incus 7.0 LTS released Version 7.0 of the Incus container and virtual-machine management system has been released. Notable changes in this release include the inclusion of a low-level backup API, the addition of basic S3 operations directly in Incus to replace the now-unmaintained MinIO project, as well as the removal of support for cgroups v1 and xtables (iptables/ip6tables/ebtables). This is a long-term-support (LTS) release, with support through June 2031. The first 2 yea…
Read original ↗https://lwn.net/Articles/1071469