RSS 생중계
[$] Meeting the Debian Technical Committee
Japan Issues First Ever 'Megaquake' Warning
Read more of this story at Slashdot.
FDA Rejects MDMA-Assisted Therapy For PTSD
Read more of this story at Slashdot.
Russia Blocks Signal Messaging App
Read more of this story at Slashdot.
'Sinkclose' Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections
Read more of this story at Slashdot.
Cisco To Lay Off Thousands More in Second Job Cut This Year
Read more of this story at Slashdot.
Cow and Calf Die After Hackers Attack Farm's Milking Robot
Read more of this story at Slashdot.
Linux Will Be Able To Boot 0.035 Seconds Faster With One Line Kernel Patch
Read more of this story at Slashdot.
Nova Launcher, Savior of Cruft-Filled Android Phones, Is On Life Support
Read more of this story at Slashdot.
FCC Proposes New Rules For AI-Generated Robocalls and Robotexts
Read more of this story at Slashdot.
A new kernel-version policy for Ubuntu
To provide users with the absolute latest in features and hardware support, Ubuntu will now ship the absolute latest available version of the upstream Linux kernel at the specified Ubuntu release freeze date, even if upstream is still in Release Candidate (RC) status.
The post goes on to acknowledge that "there are issues with this approach"; there are a lot of policy details that will apply depending on just how raw the shipped kernel is.
A Crackdown Is Coming for People Hanging On To Student Discounts
Read more of this story at Slashdot.
Agile is Killing Software Innovation, Says Moxie Marlinspike
Read more of this story at Slashdot.
How China Built Tech Prowess: Chemistry Classes and Research Labs
Read more of this story at Slashdot.
OpenAI Finds That GPT-4o Does Some Truly Bizarre Stuff Sometimes
Read more of this story at Slashdot.
Sellafield, World's Largest Store of Plutonium, Apologizes After Guilty Plea Over String of Cybersecurity Failings
Read more of this story at Slashdot.
Microsoft Researchers Report Iran Hackers Targeting US Officials Before Election
Read more of this story at Slashdot.
US Landfills Are Major Source of Toxic PFAS Pollution, Study Finds
Read more of this story at Slashdot.
[$] Distinguishing Debian testing from unstable
New attack against the SLUB allocator
Researchers from Graz University of Technology have published details of a new attack on the Linux kernel called SLUBStick. The attack uses timing information to turn an ability to trigger use-after-free or double-free bugs into the ability to overwrite page tables, and thence into the ability to read and write arbitrary areas of memory. The good news is that this attack does require an existing bug to be usable; the bad news is that the kernel regularly sees bugs of this kind.
We assume that an unprivileged user has code execution. Additionally, we consider the presence of a heap vulnerability in the Linux kernel. We assume that the Linux kernel incorporates all defense mechanisms available in version 6.4, the most recent Linux kernel version when we started our work. These mechanisms include features such as WˆX, KASLR, SMAP, and kCFI. We do not assume any microarchitectural vulnerabilities, e.g., transient execution, fault injection, or hardware side channels.