<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Sun, 19 Apr 2026 03:28:59 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Linux Action News - Episodes Tagged with “Buffer Overflow”</title>
    <link>https://linuxactionnews.com/tags/buffer%20overflow</link>
    <pubDate>Thu, 19 Jan 2023 10:30:00 -0800</pubDate>
    <description>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Our weekly take on the free and open source world.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Linux Action News 276</title>
  <link>https://linuxactionnews.com/276</link>
  <guid isPermaLink="false">b0fdfcdd-3ec2-4c0e-93c0-7bbd81219973</guid>
  <pubDate>Thu, 19 Jan 2023 10:30:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/b0fdfcdd-3ec2-4c0e-93c0-7bbd81219973.mp3" length="14058654" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</itunes:subtitle>
  <itunes:duration>16:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, netfilter, Linux, kernel, security, privilege escalation, packet filtering, networking, iptables, nftables, CVE-2023-0179, Linux 6.2, buffer overflow, auditing, stack overflow, responsible disclosure, unprivileged user namespaces, sysctl, nft_payload, VLAN,  Red Hat, oss-sec, libvirt 9.0, libvirt,  virtualization, QEMU, Daniel Berrange, Qumranet, Windows, macOS, C, Python, Perl, Go, PASST, emulated network, JFS, journaling filesystems, ReiserFS, snapshots, Christoph Hellwig, Mozilla, Firefox 109, Firefox, Manifest V3, Browser Extensions, WebRequest API, adblocking, uBlock Origin, AdBlock Plus, declarativeNetRequest, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="A new privilege escalation vulnerability in the Linux kernel" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/20">A new privilege escalation vulnerability in the Linux kernel</a> &mdash; The vulnerability consists of a stack buffer overflow due to an integer
underflow vulnerability inside the nft_payload_copy_vlan function, which is
invoked with nft_payload expressions as long as a VLAN tag is present in
the current skb.</li><li><a title="netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1" rel="nofollow" href="https://github.com/torvalds/linux/commit/f6ae9f1">netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1</a></li><li><a title="CVE-2023-0179" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2023-0179">CVE-2023-0179</a></li><li><a title="CVE-2023-0179- Red Hat Customer Portal" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2023-0179">CVE-2023-0179- Red Hat Customer Portal</a></li><li><a title="[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork" rel="nofollow" href="https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/">[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork</a></li><li><a title="oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/22">oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup</a></li><li><a title="libvirt 9.0 Released For Latest Linux Virtualization API" rel="nofollow" href="https://www.phoronix.com/news/libvirt-9.0">libvirt 9.0 Released For Latest Linux Virtualization API</a> &mdash; Libvirt 9.0 adds support for external snapshot deletion with QEMU using its existing API, libvirt 9.0 with QEMU now supports PASST as "Plug A Simple Socket Transport" for connecting an emulated network device to the host's network, QEMU external back-end support for SWTPM as a software Trusted Platform Module (TPM), support for passing file descriptors rather than passing files for the QEMU disk, and other additions. </li><li><a title="JFS Filesystem’s Days are Numbered" rel="nofollow" href="https://www.phoronix.com/news/Linux-Possible-Orphan-JFS">JFS Filesystem’s Days are Numbered</a> &mdash; IBM developed the JFS file-system originally in the 90's for AIX and the second-generation implementation then ported to Linux after it was made open-source. </li><li><a title="Firefox 109.0 Ships Manifest Version 3" rel="nofollow" href="https://www.mozilla.org/en-US/firefox/109.0/releasenotes/">Firefox 109.0 Ships Manifest Version 3</a> &mdash; Manifest Version 3 (MV3) extension support is now enabled by default (MV2 remains enabled/supported). This major update also ushers an exciting user interface change in the form of the new extensions button.</li><li><a title="Here’s what’s going on in the world of extensions" rel="nofollow" href="https://blog.mozilla.org/en/products/firefox/extensions-addons/heres-whats-going-on-in-the-world-of-extensions/">Here’s what’s going on in the world of extensions</a></li><li><a title="Manage your extensions using the extensions button in the toolbar" rel="nofollow" href="https://support.mozilla.org/en-US/kb/unified-extensions">Manage your extensions using the extensions button in the toolbar</a></li><li><a title="Manifest v3 signing available November 21 on Firefox Nightly" rel="nofollow" href="https://blog.mozilla.org/addons/2022/11/17/manifest-v3-signing-available-november-21-on-firefox-nightly/">Manifest v3 signing available November 21 on Firefox Nightly</a></li><li><a title="Google delays start of Manifest V2 Chrome extension deprecation" rel="nofollow" href="https://9to5google.com/2022/12/12/manifest-v2-chrome-extension/">Google delays start of Manifest V2 Chrome extension deprecation</a> &mdash; The original plan called for Chrome Beta, Dev, and Canary builds to start experiments that turned off Manifest V2 extension support. Additionally, Manifest V3 would be required to get the “Featured” badge in the Chrome Web Store. </li><li><a title="Firefox 109 Adds New Extensions Button, Manifest V3 Support" rel="nofollow" href="https://www.omgubuntu.co.uk/2023/01/firefox-109-released">Firefox 109 Adds New Extensions Button, Manifest V3 Support</a> &mdash; The biggest new feature is the new Unified Extensions button in the toolbar. </li><li><a title="Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed" rel="nofollow" href="https://arstechnica.com/gadgets/2022/12/chrome-delays-plan-to-limit-ad-blockers-new-timeline-coming-in-march">Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed</a></li><li><a title=" Chrome Users Beware: Manifest V3 is Deceitful and Threatening" rel="nofollow" href="https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening"> Chrome Users Beware: Manifest V3 is Deceitful and Threatening</a> &mdash; Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="A new privilege escalation vulnerability in the Linux kernel" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/20">A new privilege escalation vulnerability in the Linux kernel</a> &mdash; The vulnerability consists of a stack buffer overflow due to an integer
underflow vulnerability inside the nft_payload_copy_vlan function, which is
invoked with nft_payload expressions as long as a VLAN tag is present in
the current skb.</li><li><a title="netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1" rel="nofollow" href="https://github.com/torvalds/linux/commit/f6ae9f1">netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1</a></li><li><a title="CVE-2023-0179" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2023-0179">CVE-2023-0179</a></li><li><a title="CVE-2023-0179- Red Hat Customer Portal" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2023-0179">CVE-2023-0179- Red Hat Customer Portal</a></li><li><a title="[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork" rel="nofollow" href="https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/">[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork</a></li><li><a title="oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/22">oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup</a></li><li><a title="libvirt 9.0 Released For Latest Linux Virtualization API" rel="nofollow" href="https://www.phoronix.com/news/libvirt-9.0">libvirt 9.0 Released For Latest Linux Virtualization API</a> &mdash; Libvirt 9.0 adds support for external snapshot deletion with QEMU using its existing API, libvirt 9.0 with QEMU now supports PASST as "Plug A Simple Socket Transport" for connecting an emulated network device to the host's network, QEMU external back-end support for SWTPM as a software Trusted Platform Module (TPM), support for passing file descriptors rather than passing files for the QEMU disk, and other additions. </li><li><a title="JFS Filesystem’s Days are Numbered" rel="nofollow" href="https://www.phoronix.com/news/Linux-Possible-Orphan-JFS">JFS Filesystem’s Days are Numbered</a> &mdash; IBM developed the JFS file-system originally in the 90's for AIX and the second-generation implementation then ported to Linux after it was made open-source. </li><li><a title="Firefox 109.0 Ships Manifest Version 3" rel="nofollow" href="https://www.mozilla.org/en-US/firefox/109.0/releasenotes/">Firefox 109.0 Ships Manifest Version 3</a> &mdash; Manifest Version 3 (MV3) extension support is now enabled by default (MV2 remains enabled/supported). This major update also ushers an exciting user interface change in the form of the new extensions button.</li><li><a title="Here’s what’s going on in the world of extensions" rel="nofollow" href="https://blog.mozilla.org/en/products/firefox/extensions-addons/heres-whats-going-on-in-the-world-of-extensions/">Here’s what’s going on in the world of extensions</a></li><li><a title="Manage your extensions using the extensions button in the toolbar" rel="nofollow" href="https://support.mozilla.org/en-US/kb/unified-extensions">Manage your extensions using the extensions button in the toolbar</a></li><li><a title="Manifest v3 signing available November 21 on Firefox Nightly" rel="nofollow" href="https://blog.mozilla.org/addons/2022/11/17/manifest-v3-signing-available-november-21-on-firefox-nightly/">Manifest v3 signing available November 21 on Firefox Nightly</a></li><li><a title="Google delays start of Manifest V2 Chrome extension deprecation" rel="nofollow" href="https://9to5google.com/2022/12/12/manifest-v2-chrome-extension/">Google delays start of Manifest V2 Chrome extension deprecation</a> &mdash; The original plan called for Chrome Beta, Dev, and Canary builds to start experiments that turned off Manifest V2 extension support. Additionally, Manifest V3 would be required to get the “Featured” badge in the Chrome Web Store. </li><li><a title="Firefox 109 Adds New Extensions Button, Manifest V3 Support" rel="nofollow" href="https://www.omgubuntu.co.uk/2023/01/firefox-109-released">Firefox 109 Adds New Extensions Button, Manifest V3 Support</a> &mdash; The biggest new feature is the new Unified Extensions button in the toolbar. </li><li><a title="Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed" rel="nofollow" href="https://arstechnica.com/gadgets/2022/12/chrome-delays-plan-to-limit-ad-blockers-new-timeline-coming-in-march">Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed</a></li><li><a title=" Chrome Users Beware: Manifest V3 is Deceitful and Threatening" rel="nofollow" href="https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening"> Chrome Users Beware: Manifest V3 is Deceitful and Threatening</a> &mdash; Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 270</title>
  <link>https://linuxactionnews.com/270</link>
  <guid isPermaLink="false">ff6c3941-75cc-43f4-b8fb-54255784b93a</guid>
  <pubDate>Thu, 08 Dec 2022 10:30:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/ff6c3941-75cc-43f4-b8fb-54255784b93a.mp3" length="14633191" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The Linux kernel has some exciting updates this week, including a significant Asahi milestone and some good news for Android. Then we take openSUSE's new web-based installer for a spin.</itunes:subtitle>
  <itunes:duration>17:25</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>The Linux kernel has some exciting updates this week, including a significant Asahi milestone and some good news for Android. Then we take openSUSE's new web-based installer for a spin. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Apple M1, M2 hardware, Asahi Linux, Rust, graphics drivers, Linux desktop, GL2, GLES 2.0, gaming on Linux, OpenGL, Vulkan, Apple Silicon, CPUFreq driver, Linux 6.2, floppy disk driver, Google, Android, security, Rust adoption, Android 13, memory safety vulnerabilities, Alyssa Rosenzweig, floppies, Fedora, Mobility Phosh, Purism, Wayland, GNOME, buffer overflow, FreeBSD, ping, ICMP, capability-based-security, Capsicum, D-Installer, openSUSE, SUSE, web-based installer, D-Bus, YaST, X11, Firefox, Arm, Tumbleweed, Cockpit, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The Linux kernel has some exciting updates this week, including a significant Asahi milestone and some good news for Android. Then we take openSUSE&#39;s new web-based installer for a spin.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Apple GPU drivers now in Asahi Linux" rel="nofollow" href="https://rosenzweig.io/blog/asahi-gpu-part-7.html">Apple GPU drivers now in Asahi Linux</a> &mdash; We’ve been working hard over the past two years to bring this new driver to everyone, and we’re really proud to finally be here. This is still an alpha driver, but it’s already good enough to run a smooth desktop experience and some games</li><li><a title="Asahi Linux Enables Early Apple GPU Driver Support - WIP OpenGL 2.1 + GLES 2.0" rel="nofollow" href="https://www.phoronix.com/news/Asahi-Linux-Enables-Apple-GPU">Asahi Linux Enables Early Apple GPU Driver Support - WIP OpenGL 2.1 + GLES 2.0</a></li><li><a title="Apple Silicon CPUFreq Driver Heading To Linux 6.2" rel="nofollow" href="https://www.phoronix.com/news/Apple-Silicon-CPUFreq-Linux-6.2">Apple Silicon CPUFreq Driver Heading To Linux 6.2</a> &mdash; Sent in yesterday were the Arm CPUFreq updates to queue in the Linux power management tree ahead of the Linux 6.2 merge window. </li><li><a title="[GIT PULL] cpufreq/arm updates for 6.2 - Viresh Kumar" rel="nofollow" href="https://lore.kernel.org/linux-pm/20221205235341.bs7v3nr5bnhllteu@vireshk-i7/">[GIT PULL] cpufreq/arm updates for 6.2 - Viresh Kumar</a></li><li><a title="Floppy Driver Update Ready For Linux 6.2" rel="nofollow" href="https://www.phoronix.com/news/Linux-6.2-Floppy">Floppy Driver Update Ready For Linux 6.2</a> &mdash; This memory leak with the floppy disk driver has been in the mainline kernel since Linux 5.11 </li><li><a title="Android memory safety vulnerabilities declined as Rust usage grew " rel="nofollow" href="https://9to5google.com/2022/12/01/android-memory-safety-rust/">Android memory safety vulnerabilities declined as Rust usage grew </a> &mdash; Specifically, the number of annual memory safety vulnerabilities fell from 223 to 85 between 2019 and 2022. They are now 35% of Android’s total vulnerabilities versus 76% four years ago. In fact, “2022 is the first year where memory safety vulnerabilities do not represent a majority of Android’s vulnerabilities.”</li><li><a title="Google says Android runs better when covered in Rust" rel="nofollow" href="https://www.theregister.com/2022/12/02/android_google_rust/">Google says Android runs better when covered in Rust</a></li><li><a title="Fedora 38 Cleared To Produce “Mobility Phosh” Spins" rel="nofollow" href="https://www.phoronix.com/news/Fedora-Mobility-Phosh-Approved">Fedora 38 Cleared To Produce “Mobility Phosh” Spins</a> &mdash; The Fedora Engineering and Steering Committee (FESCo) has provided their blessing to begin creating new x86_64 and AArch64 ISO images for mobile devices that feature the Phosh Wayland compositor. </li><li><a title="Ping bug potentially allows remote hack of FreeBSD systemsSecurity Affairs" rel="nofollow" href="https://securityaffairs.co/wordpress/139300/hacking/cve-2022-23093-freebsd-systems-flaw.html">Ping bug potentially allows remote hack of FreeBSD systemsSecurity Affairs</a> &mdash; A remote attacker can trigger the vulnerability, causing the ping program to crash and potentially leading to remote code execution in ping. </li><li><a title="D-Installer needs your help" rel="nofollow" href="https://yast.opensuse.org/blog/2022-12-05/d-installer-needs-you">D-Installer needs your help</a> &mdash; Today we published a new prototype of D-Installer, fixing several bugs reported by early testers and improving the usage experience in some areas like the configuration of passwords and users. But beyond those improvements, a couple of new features deserve some attention.</li><li><a title="Bug 1205938 – D-Installer - Slowness initialization on real hardware" rel="nofollow" href="https://bugzilla.suse.com/show_bug.cgi?id=1205938">Bug 1205938 – D-Installer - Slowness initialization on real hardware</a></li><li><a title="GitHub - yast/d-installer: A service-based Linux installer" rel="nofollow" href="https://github.com/yast/d-installer#live-iso-image">GitHub - yast/d-installer: A service-based Linux installer</a></li><li><a title="openSUSE’s D-Installer Adds LVM &amp; Full Disk Encryption Configuration" rel="nofollow" href="https://www.phoronix.com/news/New-D-Installer-Prototype">openSUSE’s D-Installer Adds LVM &amp; Full Disk Encryption Configuration</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The Linux kernel has some exciting updates this week, including a significant Asahi milestone and some good news for Android. Then we take openSUSE&#39;s new web-based installer for a spin.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Apple GPU drivers now in Asahi Linux" rel="nofollow" href="https://rosenzweig.io/blog/asahi-gpu-part-7.html">Apple GPU drivers now in Asahi Linux</a> &mdash; We’ve been working hard over the past two years to bring this new driver to everyone, and we’re really proud to finally be here. This is still an alpha driver, but it’s already good enough to run a smooth desktop experience and some games</li><li><a title="Asahi Linux Enables Early Apple GPU Driver Support - WIP OpenGL 2.1 + GLES 2.0" rel="nofollow" href="https://www.phoronix.com/news/Asahi-Linux-Enables-Apple-GPU">Asahi Linux Enables Early Apple GPU Driver Support - WIP OpenGL 2.1 + GLES 2.0</a></li><li><a title="Apple Silicon CPUFreq Driver Heading To Linux 6.2" rel="nofollow" href="https://www.phoronix.com/news/Apple-Silicon-CPUFreq-Linux-6.2">Apple Silicon CPUFreq Driver Heading To Linux 6.2</a> &mdash; Sent in yesterday were the Arm CPUFreq updates to queue in the Linux power management tree ahead of the Linux 6.2 merge window. </li><li><a title="[GIT PULL] cpufreq/arm updates for 6.2 - Viresh Kumar" rel="nofollow" href="https://lore.kernel.org/linux-pm/20221205235341.bs7v3nr5bnhllteu@vireshk-i7/">[GIT PULL] cpufreq/arm updates for 6.2 - Viresh Kumar</a></li><li><a title="Floppy Driver Update Ready For Linux 6.2" rel="nofollow" href="https://www.phoronix.com/news/Linux-6.2-Floppy">Floppy Driver Update Ready For Linux 6.2</a> &mdash; This memory leak with the floppy disk driver has been in the mainline kernel since Linux 5.11 </li><li><a title="Android memory safety vulnerabilities declined as Rust usage grew " rel="nofollow" href="https://9to5google.com/2022/12/01/android-memory-safety-rust/">Android memory safety vulnerabilities declined as Rust usage grew </a> &mdash; Specifically, the number of annual memory safety vulnerabilities fell from 223 to 85 between 2019 and 2022. They are now 35% of Android’s total vulnerabilities versus 76% four years ago. In fact, “2022 is the first year where memory safety vulnerabilities do not represent a majority of Android’s vulnerabilities.”</li><li><a title="Google says Android runs better when covered in Rust" rel="nofollow" href="https://www.theregister.com/2022/12/02/android_google_rust/">Google says Android runs better when covered in Rust</a></li><li><a title="Fedora 38 Cleared To Produce “Mobility Phosh” Spins" rel="nofollow" href="https://www.phoronix.com/news/Fedora-Mobility-Phosh-Approved">Fedora 38 Cleared To Produce “Mobility Phosh” Spins</a> &mdash; The Fedora Engineering and Steering Committee (FESCo) has provided their blessing to begin creating new x86_64 and AArch64 ISO images for mobile devices that feature the Phosh Wayland compositor. </li><li><a title="Ping bug potentially allows remote hack of FreeBSD systemsSecurity Affairs" rel="nofollow" href="https://securityaffairs.co/wordpress/139300/hacking/cve-2022-23093-freebsd-systems-flaw.html">Ping bug potentially allows remote hack of FreeBSD systemsSecurity Affairs</a> &mdash; A remote attacker can trigger the vulnerability, causing the ping program to crash and potentially leading to remote code execution in ping. </li><li><a title="D-Installer needs your help" rel="nofollow" href="https://yast.opensuse.org/blog/2022-12-05/d-installer-needs-you">D-Installer needs your help</a> &mdash; Today we published a new prototype of D-Installer, fixing several bugs reported by early testers and improving the usage experience in some areas like the configuration of passwords and users. But beyond those improvements, a couple of new features deserve some attention.</li><li><a title="Bug 1205938 – D-Installer - Slowness initialization on real hardware" rel="nofollow" href="https://bugzilla.suse.com/show_bug.cgi?id=1205938">Bug 1205938 – D-Installer - Slowness initialization on real hardware</a></li><li><a title="GitHub - yast/d-installer: A service-based Linux installer" rel="nofollow" href="https://github.com/yast/d-installer#live-iso-image">GitHub - yast/d-installer: A service-based Linux installer</a></li><li><a title="openSUSE’s D-Installer Adds LVM &amp; Full Disk Encryption Configuration" rel="nofollow" href="https://www.phoronix.com/news/New-D-Installer-Prototype">openSUSE’s D-Installer Adds LVM &amp; Full Disk Encryption Configuration</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 265</title>
  <link>https://linuxactionnews.com/265</link>
  <guid isPermaLink="false">ee9013c5-bc14-4d86-82d7-ae77ed4a9d38</guid>
  <pubDate>Thu, 03 Nov 2022 04:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/ee9013c5-bc14-4d86-82d7-ae77ed4a9d38.mp3" length="14659522" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>What you need to know about that new OpenSSL vulnerability, the big bcachefs update we've been waiting for, and why the community is creating a Gitea fork.</itunes:subtitle>
  <itunes:duration>17:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>What you need to know about that new OpenSSL vulnerability, the big bcachefs update we've been waiting for, and why the community is creating a Gitea fork. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, OpenSSL, OpenSSL 3.0.7, buffer overflow, X.509, security vulnerability, Fedora 37, Linux 6.2, lazy RCU, read-copy-update synchronization, batching callbacks, power savings, power usage, idle power draw, Apple M1, Mac Studio, Asahi Linux, Hector Martin, IRC, kernel maintainers, Twitter, bcachefs, Kent Overstreet, CoW, on-disk format changes, disk allocator, RAID 5, RAID 6, 4k random writes, FreeBSD, FreeBSD 14, WireGuard, Jason Donenfeld, FreeBSD Ports, Gitea, Gitea Limited, Open Letter, non-profit, open-source governance, Gitea fork, git, git forge, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>What you need to know about that new OpenSSL vulnerability, the big bcachefs update we&#39;ve been waiting for, and why the community is creating a Gitea fork.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="OpenSSL 3.0.7 Released Fixing Critical Flaw" rel="nofollow" href="https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/">OpenSSL 3.0.7 Released Fixing Critical Flaw</a> &mdash; Today we published an advisory about CVE-2022-3786 (“X.509 Email Address Variable Length Buffer Overflow”) and CVE-2022-3602 (“X.509 Email Address 4-byte Buffer Overflow”).</li><li><a title="OpenSSL version 3.0.7 published" rel="nofollow" href="https://mta.openssl.org/pipermail/openssl-announce/2022-November/000241.html">OpenSSL version 3.0.7 published</a></li><li><a title="/news/openssl-3.0-notes.html" rel="nofollow" href="https://www.openssl.org/news/openssl-3.0-notes.html">/news/openssl-3.0-notes.html</a></li><li><a title="Fedora 37 Release Delayed To Mid-November Over Critical OpenSSL Vulnerability" rel="nofollow" href="https://www.phoronix.com/news/Fedora-37-November-Delay">Fedora 37 Release Delayed To Mid-November Over Critical OpenSSL Vulnerability</a></li><li><a title="Linux 6.2 Power-Savings While Idle Or Lightly Loaded" rel="nofollow" href="https://www.phoronix.com/news/Lazy-RCU-Likely-For-Linux-6.2">Linux 6.2 Power-Savings While Idle Or Lightly Loaded</a> &mdash; The short story for Linux end-users is the Lazy RCU work can provide 5~10% power-savings for idle or lightly-loaded systems by this lazy/batching functionality.</li><li><a title="Linux 6.2 Picking Up Mainline Support For Apple M1 Pro/Max/Ultra Hardware" rel="nofollow" href="https://www.phoronix.com/news/Linux-62-Apple-M1-Pro-Max-Ultra">Linux 6.2 Picking Up Mainline Support For Apple M1 Pro/Max/Ultra Hardware</a> &mdash; This gets the high-end Mac Studio systems with those premium SoCs now compatible with the mainline kernel.</li><li><a title="Hector&#39;s Deleted Tweet" rel="nofollow" href="http://webcache.googleusercontent.com/search?q=cache:https://twitter.com/marcan42/status/1587010094197506048">Hector's Deleted Tweet</a> &mdash; I'm getting tired of arguing with kernel maintainers. The other day I spent 6 hours arguing on IRC about what should've been a 30 minute fix patch.</li><li><a title="Hector Martin on Twitter Follow Up Tweet" rel="nofollow" href="https://twitter.com/marcan42/status/1587011361753960448">Hector Martin on Twitter Follow Up Tweet</a> &mdash; Like dude, if you aren't going to step into my world and actually understand what I'm trying to do here, just suck it up and ack my patch. It is not my job to drag you kicking and screaming until you either give up or have a lightbulb moment.</li><li><a title="Seems some Kernel Maintainers Noticed the Twitter Rant" rel="nofollow" href="https://twitter.com/marcan42/status/1587285684800606208">Seems some Kernel Maintainers Noticed the Twitter Rant</a> &mdash; Well they saw my tweets and apparently didn't like them 🤷‍♂️
</li><li><a title="Bcachefs Rolling Out New Allocator, Performance Continues Improving" rel="nofollow" href="https://www.phoronix.com/news/Bcachefs-Linux-October-2022">Bcachefs Rolling Out New Allocator, Performance Continues Improving</a> &mdash; Bcachefs developer Kent Overstreet on Friday published a new status update on this original file-system born out of Linux's block cache (BCache) code.</li><li><a title="FreeBSD Re-Introduces WireGuard Support Into Its Kernel" rel="nofollow" href="https://www.phoronix.com/news/FreeBSD-WireGuard-Lands-2022">FreeBSD Re-Introduces WireGuard Support Into Its Kernel</a> &mdash; As of Friday, a new WireGuard driver implementation has been re-introduced with many fixes/improvements over the code state from 2020.</li><li><a title="Open Letter to Gitea - Restoring Trust in the Gitea Project" rel="nofollow" href="https://gitea-open-letter.coding.social/">Open Letter to Gitea - Restoring Trust in the Gitea Project</a> &mdash; This unfortunately concludes the Gitea Open Letter has failed and there is no alternative but forking the project under a new name, with a healthy democratic governance.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>What you need to know about that new OpenSSL vulnerability, the big bcachefs update we&#39;ve been waiting for, and why the community is creating a Gitea fork.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="OpenSSL 3.0.7 Released Fixing Critical Flaw" rel="nofollow" href="https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/">OpenSSL 3.0.7 Released Fixing Critical Flaw</a> &mdash; Today we published an advisory about CVE-2022-3786 (“X.509 Email Address Variable Length Buffer Overflow”) and CVE-2022-3602 (“X.509 Email Address 4-byte Buffer Overflow”).</li><li><a title="OpenSSL version 3.0.7 published" rel="nofollow" href="https://mta.openssl.org/pipermail/openssl-announce/2022-November/000241.html">OpenSSL version 3.0.7 published</a></li><li><a title="/news/openssl-3.0-notes.html" rel="nofollow" href="https://www.openssl.org/news/openssl-3.0-notes.html">/news/openssl-3.0-notes.html</a></li><li><a title="Fedora 37 Release Delayed To Mid-November Over Critical OpenSSL Vulnerability" rel="nofollow" href="https://www.phoronix.com/news/Fedora-37-November-Delay">Fedora 37 Release Delayed To Mid-November Over Critical OpenSSL Vulnerability</a></li><li><a title="Linux 6.2 Power-Savings While Idle Or Lightly Loaded" rel="nofollow" href="https://www.phoronix.com/news/Lazy-RCU-Likely-For-Linux-6.2">Linux 6.2 Power-Savings While Idle Or Lightly Loaded</a> &mdash; The short story for Linux end-users is the Lazy RCU work can provide 5~10% power-savings for idle or lightly-loaded systems by this lazy/batching functionality.</li><li><a title="Linux 6.2 Picking Up Mainline Support For Apple M1 Pro/Max/Ultra Hardware" rel="nofollow" href="https://www.phoronix.com/news/Linux-62-Apple-M1-Pro-Max-Ultra">Linux 6.2 Picking Up Mainline Support For Apple M1 Pro/Max/Ultra Hardware</a> &mdash; This gets the high-end Mac Studio systems with those premium SoCs now compatible with the mainline kernel.</li><li><a title="Hector&#39;s Deleted Tweet" rel="nofollow" href="http://webcache.googleusercontent.com/search?q=cache:https://twitter.com/marcan42/status/1587010094197506048">Hector's Deleted Tweet</a> &mdash; I'm getting tired of arguing with kernel maintainers. The other day I spent 6 hours arguing on IRC about what should've been a 30 minute fix patch.</li><li><a title="Hector Martin on Twitter Follow Up Tweet" rel="nofollow" href="https://twitter.com/marcan42/status/1587011361753960448">Hector Martin on Twitter Follow Up Tweet</a> &mdash; Like dude, if you aren't going to step into my world and actually understand what I'm trying to do here, just suck it up and ack my patch. It is not my job to drag you kicking and screaming until you either give up or have a lightbulb moment.</li><li><a title="Seems some Kernel Maintainers Noticed the Twitter Rant" rel="nofollow" href="https://twitter.com/marcan42/status/1587285684800606208">Seems some Kernel Maintainers Noticed the Twitter Rant</a> &mdash; Well they saw my tweets and apparently didn't like them 🤷‍♂️
</li><li><a title="Bcachefs Rolling Out New Allocator, Performance Continues Improving" rel="nofollow" href="https://www.phoronix.com/news/Bcachefs-Linux-October-2022">Bcachefs Rolling Out New Allocator, Performance Continues Improving</a> &mdash; Bcachefs developer Kent Overstreet on Friday published a new status update on this original file-system born out of Linux's block cache (BCache) code.</li><li><a title="FreeBSD Re-Introduces WireGuard Support Into Its Kernel" rel="nofollow" href="https://www.phoronix.com/news/FreeBSD-WireGuard-Lands-2022">FreeBSD Re-Introduces WireGuard Support Into Its Kernel</a> &mdash; As of Friday, a new WireGuard driver implementation has been re-introduced with many fixes/improvements over the code state from 2020.</li><li><a title="Open Letter to Gitea - Restoring Trust in the Gitea Project" rel="nofollow" href="https://gitea-open-letter.coding.social/">Open Letter to Gitea - Restoring Trust in the Gitea Project</a> &mdash; This unfortunately concludes the Gitea Open Letter has failed and there is no alternative but forking the project under a new name, with a healthy democratic governance.</li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
