LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, May 14th, 2021

    Time Event
    1:53p
    Security updates for Friday
    Security updates have been issued by Debian (jetty9, libgetdata, and postgresql-11), openSUSE (java-11-openjdk), SUSE (dtc, ibsim, ibutils, ipvsadm, and kernel), and Ubuntu (awstats and glibc).
    2:10p
    Stable kernels 5.12.4, 5.11.21, 5.10.37, and 5.4.119
    Greg Kroah-Hartman has announced the release of the 5.12.4, 5.11.21, 5.10.37, and 5.4.119 stable kernels. These are enormous
    updates, with changes throughout the kernel tree; users should upgrade.
    3:58p
    [$] Sticky groups in the shadows
    Group membership is normally used to grant access to some resource;
    examples might include using groups to control access to a shared
    directory, a printer, or the ability to use tools like sudo. It
    is possible, though, to use group membership to deny access to a
    resource instead, and some administrators make use of that feature. But
    groups only work as a negative credential if the user cannot shed them at
    will. Occasionally, some way to escape a group has turned up, resulting in
    vulnerabilities on systems where they are used to block access; despite
    fixes in the past, it turns out that there is still a potential problem
    with groups and user namespaces; this
    patch set
    from Giuseppe Scrivano seeks to mitigate it through the
    creation of "shadow" groups.

    << Previous Day 2021/05/14
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org