LWN.net is a comprehensive source of news and opinions from
and about the Linux community. This is the main LWN.net feed,
listing all articles which are posted to the site front page.
업데이트: 1시간 29분 지남
화, 2026/07/21 - 3:26오전
The Fedora Project is known for,
among other things, having a well-defined set of processes for just about
everything. It has extensive packaging
guidelines that deal with the complexities of creating RPMs to install
software, as well as processes for managing the legal questions that
arise around shipping software. Fedora also has a well-defined change
process for dealing with self-contained technical changes as well as major
changes to the distribution, and other issues as they arise. At the moment,
though, the project seems to be experiencing a sort of midlife crisis as it
re-examines several of its change processes at once to determine if they are
still effective.
화, 2026/07/21 - 12:52오전
Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a blog post that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day deadline for
disclosures to 30 days for issues reported on August 1, or later. "The
shorter deadline would probably work better for GNOME even if not for the
increase in AI-generated issue reports."
He also has indicated that he will be stepping away from the task of managing
security issue tracking entirely by December 1, 2026, which means that there
will be a gap to fill:
Currently nobody else is tracking GNOME security issues. If you are an
experienced GNOME community member and you are interested in taking over this
work, let me know and I will help you get started. (Security tracking is not a
good task for newcomers.)
This may also be an opportunity to improve our tracking infrastructure. I use
a wiki
page, but this is fairly primitive and requires considerable manual
upkeep. It's easy to forget to update the page when an issue report is closed,
for example. Ideally, we would replace the wiki with a proper web app that
dynamically updates based on the actual state of the issue.
월, 2026/07/20 - 10:10오후
Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and SUSE (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).
월, 2026/07/20 - 7:11오전
The
7.2-rc4 kernel prepatch is out for
testing. Linus said: "This whole week I had the feeling that people
were starting to go on summer vacation, but running the numbers shows that
I must have been wrong - it all looks pretty normal."
일, 2026/07/19 - 1:52오전
Adrian Mastronardi has released a book called
Half a Second; it is a
detailed look into the
XZ backdoor attempt
of 2024. The book is freely available under a (non-free) noncommercial,
no-derivatives CC license.
Half a Second tells that story as one continuous narrative:
the burned-out volunteer who maintained the code alone and was
patiently, expertly manipulated into giving it up; the engineer
whose half-second of curiosity caught the attack through a chain of
luck and hard-won instinct; and the operator who built it, who has
never been identified and, this book argues, may never be.
일, 2026/07/19 - 1:41오전
The
7.1.4,
6.18.39, and
6.12.96 stable kernel updates have been
released; each contains a fairly large set of important fixes.
토, 2026/07/18 - 2:03오전
Collabora has published a blog
post about its work with Valve on Holo Core, which is a port of Arch Linux to
aarch64 to be used as the the operating system on Valve's
64-bit Arm Steam Frame gaming system. Collabora has released the
sources,
binary
packages, and a container image for aarch64 devices. The post
describes some of the challenges in porting Arch Linux to a new
architecture, and what remains to be done:
Whilst the infrastructure developed to this point is capable of
building from first principles up until a point-in-time snapshot, the
next step is to build this into a system which can track Arch Linux as
it is developed. This work will serve as the basis of a
continuously-operating CI system capable of shadowing Arch Linux
itself. We will work with the upstream Arch Linux project to help Arch
with their efforts to port the distribution to aarch64 architecture
and work towards automated repeatable builds.
The post also includes instructions on how to create and test an
aarch64 build container on an x86_64 host, for users who would like to
follow along at home but lack a 64-bit Arm device.
토, 2026/07/18 - 12:58오전
Since 2020, BPF programs have been able to
act as Linux security modules
(LSMs). Several projects, including systemd, have been working to use
that capability to provide more security to users. Christian Brauner
spoke at the 2026
Linux Storage, Filesystem, Memory-Management, and BPF Summit
about some of the limitations of using BPF in this way, and the changes he
would like to see for systemd's use. In particular, he would like a way to make
sure that BPF programs cannot be removed or have their private data tampered with.
금, 2026/07/17 - 10:06오후
Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Oracle (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kernel), Red Hat (kernel, kernel-rt, and podman), Slackware (netatalk), SUSE (agama, aws-nitro-enclaves-binaryblobs-upstream, gimp, gpsd, grafana, hostapd, ImageMagick, jackson-databind, kernel, libssh2_org, nm-configurator, opennlp, perl-Mojolicious, python-Pillow, python-python-engineio, python-python-socketio, and tomcat11), and Ubuntu (ntfs-3g, python-authlib, ruby2.3, tar, and ubuntu-advantage-tools).
목, 2026/07/16 - 11:00오후
The
extensible
scheduler class (sched_ext) allows the installation of custom CPU
schedulers as a set of BPF programs. While sched_ext, in its current form,
has already led to a lot of interesting scheduler-development work, the
subsystem itself is still undergoing rapid evolution. Among other work,
the ability to set up a hierarchy of
sub-schedulers is approaching completion, and
a longstanding incompatibility with
proxy
execution is coming to an end.
목, 2026/07/16 - 10:02오후
Security updates have been issued by AlmaLinux (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), Debian (chromium, dhcpcd5, and ntfs-3g), Fedora (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), Mageia (openssl, poppler, python-mistune, and tmux), Oracle (389-ds-base, cups, git-lfs, glibc, host-metering, kernel, libsolv, libxml2, nginx:1.24, PackageKit, python-pillow, and qemu-kvm), Red Hat (buildah, containernetworking-plugins, and skopeo), SUSE (buildah, cosign, curl, distribution, dnsmasq, glib-networking, glibc, gnutls, gstreamer-plugins-bad, ImageMagick, kernel, podman, python-cryptography, python313-django-debug-toolbar, rekor, sccache, sssd, and yelp), and Ubuntu (dotnet8, dotnet10, libslirp, luajit, python-idna, sympa, and tomcat8).
목, 2026/07/16 - 10:24오전
Inside this week's LWN.net Weekly Edition:
- Front: Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE.
- Briefs: Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
목, 2026/07/16 - 1:19오전
It should come as no surprise that a gathering of filesystem developers
would discuss filesystem testing; it has been a mainstay of the
Linux Storage,
Filesystem, Memory Management, and BPF Summit over the years and the
2026 summit was no exception. Ted Ts'o led the discussion this time; he
had a few different topics to raise, including his perception of increasing
regressions for ext4 in the stable kernels and what can be done to help
reduce them. As
with other similar
sessions at the summit over the years,
there is a lot of interest in collaborating on test inputs and outputs, but
finding a way to centralize that information has so far eluded the
filesystem community.
목, 2026/07/16 - 12:52오전
The SUSE Security Team Blog has a post
with an analysis of seunshare,
which is used by SELinux to confine untrusted programs. During a
review of version
3.10 of the program, the team identified two local
Denial-of-Service (DoS) vectors.
Since seunshare is supposed to run on SELinux-enabled systems, it
is important to understand what kind of privilege escalation can be
achieved when vulnerabilities are exploited in a setuid-root binary
like this. Many SELinux-enabled systems, such as Fedora and openSUSE,
ship with the "targeted" SELinux policy by default. This policy is
focused on confining well-known system services, but assigns an
unconfined SELinux context to interactive users by default to achieve
a balance between security and usability.
There is currently no domain transition from the unconfined domain
to the more restricted seunshare_t defined in the SELinux policy for
seunshare. This means the execution of seunshare continues in the
unconfined domain. Thus in the context of attacks carried out by
interactive users, the impact of the vulnerabilities below will be a
root-like privilege escalation despite the system running in SELinux
enforced mode.
See the post for the full write-up of the team's discoveries and timeline. The
vulnerabilities have been fixed in version 3.11.
수, 2026/07/15 - 10:35오후
Processes that use
io_uring
tend to keep a lot of balls in the air; being able to have many operations
underway at any given time is part of the point of that API in the first
place. The io_uring subsystem must, as a result, keep track of a lot of
tasks that have to be performed at the right time. In current kernels,
io_uring uses a standard kernel linked-list primitive to track those work
items. As of the 7.2 kernel release, though, io_uring will, instead, use a
new lockless, multi-producer, single-consumer (MPSC) queue, resulting in
some notable performance gains. Lockless algorithms tend to be tricky, but
the one used here is relatively approachable and shows how these algorithms
can work.
수, 2026/07/15 - 10:19오후
Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, openssl, perl-DBI, podman, vim, xorg-x11-server, and xorg-x11-server-Xwayland), Red Hat (python3.12), SUSE (afterburn, buildah, busybox, enc, freetype2-devel, go1.25, go1.25-openssl, go1.26-openssl, gosec, grafana, helm, krb5, kubernetes-old, libopenbabel8, libxml2, libxml2-16, nasm, openssl-3, patch, python-Authlib, python-mistune, python-soupsieve, python-sqlparse, python3-dulwich, python313-Pillow, rootlesskit, sbootutil-1, tomcat, and tomcat11), and Ubuntu (alsa-lib, dnsmasq, gnutls28, libheif, linux-aws, linux-fips, linux-lts-xenial, linux-gcp-5.15, linux-intel-iotg-5.15, linux-hwe-6.17, linux-raspi, mariadb, openvpn, python-httplib2, vim, and wget).
수, 2026/07/15 - 9:49오후
The CMU CERT Coordination Center has put out
an advisory that many
exploitable versions of the shim binary, used to boot Linux on systems with
UEFI secure boot enabled, were never added to the revocation list.
An attacker with administrative privileges or the ability to modify
the boot process could use one of the vulnerable shim bootloaders
to bypass Secure Boot protections and execute arbitrary code before
the operating system loads. Code executed during this early boot
phase may achieve persistent compromise of the platform, including
the ability to load unsigned or malicious kernel components that
can survive system reboots and, in some cases, operating system
reinstallation.
The advisory contains a list of vulnerable shims.
수, 2026/07/15 - 1:50오전
Rob Kennedy has
posted the
story of the birth of
Linux.org — one
of the earliest Linux-related web sites — and its more recent rebirth.
The site was founded in May 1994 by Michael McLagan, at a time when
Linux itself was barely three years old. Linus Torvalds had only
just released it to the world, there was no real way for a newcomer
to find their footing, no search engines, no Wikipedia, none of the
infrastructure people take for granted now for figuring out a new
piece of technology. Michael built linux.org to fill that gap, a
place for people to learn about Linux and follow the movement as it
grew.
화, 2026/07/14 - 10:41오후
The Maintainers Summit is an annual, invitation-only gathering of kernel
developers and maintainers to discuss development-process issues; see
LWN's 2025 Maintainers Summit coverage for an
example. The
call for
topics for the 2026 gathering (Prague, October 8) has gone out.
One of the best ways to obtain an invitation to the Summit is with a good
topic proposal. For best consideration, topics should be submitted before
July 24.
페이지