LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Wednesday, February 12th, 2020

    Time Event
    12:21a
    Three stable kernels
    Stable kernels 5.5.3, 5.4.19, and 4.19.103 have been released. They all contain
    many important fixes throughout the tree and users should upgrade.
    3:31p
    Security updates for Wednesday
    Security updates have been issued by CentOS (spice-gtk), Debian (libemail-address-list-perl), openSUSE (chromium, libqt5-qtbase, nginx, systemd, and wicked), Oracle (spice-gtk), Slackware (firefox and thunderbird), and Ubuntu (libexif and Yubico PIV Tool).
    5:13p
    Horn: Mitigations are attack surface, too
    On the Google Project Zero blog, Jann Horn looks
    at a number of vulnerabilities
    in a Samsung Android kernel, some of
    which are caused by the addition of out-of-tree "security" features.
    "The Samsung kernel on the A50 contains an extra security subsystem
    (named 'PROCA', short for 'Process Authenticator', with code in
    security/proca/) to track process identities. By combining several logic
    issues in this subsystem (which, on their own, can already cause a mismatch
    between the tracking state and the actual process state) with a brittle
    code pattern, it is possible to cause memory unsafety by winning a race
    condition.
    "
    9:24p
    [$] Enabling the persistent journal in Debian
    It seems unlikely that anyone on any "side" of the systemd war that has
    raged in Debian over the last few years thought that the results of the recent general resolution (GR)
    vote ended the matter. The vote showed a clear preference for moving ahead
    with systemd as the preferred init system, though it was far from any kind
    of landslide—there were definitely plenty of voters who would have preferred a
    different outcome. It was a complicated
    GR
    , with a wide spectrum of options, but at this point, the project
    as a whole has spoken. Actually implementing some of the changes that the
    GR enabled may not have the smooth path that some might have hoped for, however.

    << Previous Day 2020/02/12
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org