<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Mon, 06 Apr 2026 06:46:10 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Linux Action News - Episodes Tagged with “Log4shell”</title>
    <link>https://linuxactionnews.com/tags/log4shell</link>
    <pubDate>Sun, 19 Dec 2021 19:15:00 -0800</pubDate>
    <description>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Our weekly take on the free and open source world.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Linux Action News 220</title>
  <link>https://linuxactionnews.com/220</link>
  <guid isPermaLink="false">651592ed-dade-454a-a899-a738704321f5</guid>
  <pubDate>Sun, 19 Dec 2021 19:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/651592ed-dade-454a-a899-a738704321f5.mp3" length="14362145" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The nasty Log4Shell vulnerability isn't solved yet, this week saw a new round of attacks and patches.</itunes:subtitle>
  <itunes:duration>19:56</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>The nasty Log4Shell vulnerability isn't solved yet, this week saw a new round of attacks and patches. 
Plus how the work to port Linux to the Apple M1 resulted in fixing a bug that impacted all Linux distros. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Log4Shell, Log4j, Java, Apache, Check Point, Alibaba Cloud Security Team, Steam, iCloud, Jen Easterly, CISA, Cybersecurity, CrowdStrike, Mandiant, CVE-2021-45046, PipeWire, JACK, OBS, WirePlumber, AirPlay, echo-cancel module, EXT4, Mount API, Christian Brauner, Linux 5.17, Hector Martin, ARM SMMU, M1, macOS 12.1, raw image mode, Asahi, Podcast Index, Podcasting 2.0, Dave Jones</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The nasty Log4Shell vulnerability isn&#39;t solved yet, this week saw a new round of attacks and patches. </p>

<p>Plus how the work to port Linux to the Apple M1 resulted in fixing a bug that impacted all Linux distros.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Log4j 2.15.0 and previously suggested mitigations may not be enough" rel="nofollow" href="https://isc.sans.edu/diary/Log4j+2.15.0+and+previously+suggested+mitigations+may+not+be+enough/28134">Log4j 2.15.0 and previously suggested mitigations may not be enough</a> &mdash; It was discovered that version 2.15.0 would still be vulnerable when the configuration has a pattern layout containing a Context Lookup.</li><li><a title="Statement from CISA Director Easterly on “Log4j” Vulnerability" rel="nofollow" href="https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability">Statement from CISA Director Easterly on “Log4j” Vulnerability</a></li><li><a title="PipeWire 0.3.41 Offers Improved Flatpak &amp; JACK Compatibility, Apple AirPlay Streaming" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=PipeWire-0.3.41-Released">PipeWire 0.3.41 Offers Improved Flatpak &amp; JACK Compatibility, Apple AirPlay Streaming</a> &mdash; PipeWire 0.3.41 also adds a new RAOP module (raop-sink and raop-discover) that can be used for streaming to Apple AirPlay devices. </li><li><a title="EXT4 Prepared To Switch To Linux’s New Mount API" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=EXT4-New-Mount-API-Usage">EXT4 Prepared To Switch To Linux’s New Mount API</a> &mdash; Linux's new mount API is what came about in recent times as a set of system calls offering more flexibility than the long-standing mount syscall that is a one-shot effort while this new multi-step mounting procedure allows for more options. </li><li><a title="The End-Of-Year 2021 State Of Linux On Apple’s M1 SoC" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Apple-M1-Silicon-EO-2021">The End-Of-Year 2021 State Of Linux On Apple’s M1 SoC</a> &mdash; The Asahi Linux project has published their October and November status update to provide an overview of where the Apple Silicon / Apple M1 open-source support is now at as we approach the end of 2021.</li><li><a title="Asahi Linux looks forward to exciting 2022 on Apple silicon" rel="nofollow" href="https://www.theregister.com/2021/12/16/asahi_linux_2022/">Asahi Linux looks forward to exciting 2022 on Apple silicon</a></li><li><a title="Hector Martin on Twitter" rel="nofollow" href="https://twitter.com/marcan42/status/1471799568807636994">Hector Martin on Twitter</a> &mdash; Looks like Apple changed the requirements for Mach-O kernel files in 12.1, breaking our existing installation process... and they *also* added a raw image mode that will never break again and doesn't require Mach-Os.

And people said they wouldn't help. This is intended for us.</li><li><a title="Podcastindex.org" rel="nofollow" href="https://podcastindex.org/">Podcastindex.org</a> &mdash; The Podcast Index is here to preserve, protect and extend the open, independent podcasting ecosystem.</li><li><a title="Linux Action News on Podcastindex.org" rel="nofollow" href="https://podcastindex.org/podcast/203827">Linux Action News on Podcastindex.org</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The nasty Log4Shell vulnerability isn&#39;t solved yet, this week saw a new round of attacks and patches. </p>

<p>Plus how the work to port Linux to the Apple M1 resulted in fixing a bug that impacted all Linux distros.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Log4j 2.15.0 and previously suggested mitigations may not be enough" rel="nofollow" href="https://isc.sans.edu/diary/Log4j+2.15.0+and+previously+suggested+mitigations+may+not+be+enough/28134">Log4j 2.15.0 and previously suggested mitigations may not be enough</a> &mdash; It was discovered that version 2.15.0 would still be vulnerable when the configuration has a pattern layout containing a Context Lookup.</li><li><a title="Statement from CISA Director Easterly on “Log4j” Vulnerability" rel="nofollow" href="https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability">Statement from CISA Director Easterly on “Log4j” Vulnerability</a></li><li><a title="PipeWire 0.3.41 Offers Improved Flatpak &amp; JACK Compatibility, Apple AirPlay Streaming" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=PipeWire-0.3.41-Released">PipeWire 0.3.41 Offers Improved Flatpak &amp; JACK Compatibility, Apple AirPlay Streaming</a> &mdash; PipeWire 0.3.41 also adds a new RAOP module (raop-sink and raop-discover) that can be used for streaming to Apple AirPlay devices. </li><li><a title="EXT4 Prepared To Switch To Linux’s New Mount API" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=EXT4-New-Mount-API-Usage">EXT4 Prepared To Switch To Linux’s New Mount API</a> &mdash; Linux's new mount API is what came about in recent times as a set of system calls offering more flexibility than the long-standing mount syscall that is a one-shot effort while this new multi-step mounting procedure allows for more options. </li><li><a title="The End-Of-Year 2021 State Of Linux On Apple’s M1 SoC" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Apple-M1-Silicon-EO-2021">The End-Of-Year 2021 State Of Linux On Apple’s M1 SoC</a> &mdash; The Asahi Linux project has published their October and November status update to provide an overview of where the Apple Silicon / Apple M1 open-source support is now at as we approach the end of 2021.</li><li><a title="Asahi Linux looks forward to exciting 2022 on Apple silicon" rel="nofollow" href="https://www.theregister.com/2021/12/16/asahi_linux_2022/">Asahi Linux looks forward to exciting 2022 on Apple silicon</a></li><li><a title="Hector Martin on Twitter" rel="nofollow" href="https://twitter.com/marcan42/status/1471799568807636994">Hector Martin on Twitter</a> &mdash; Looks like Apple changed the requirements for Mach-O kernel files in 12.1, breaking our existing installation process... and they *also* added a raw image mode that will never break again and doesn't require Mach-Os.

And people said they wouldn't help. This is intended for us.</li><li><a title="Podcastindex.org" rel="nofollow" href="https://podcastindex.org/">Podcastindex.org</a> &mdash; The Podcast Index is here to preserve, protect and extend the open, independent podcasting ecosystem.</li><li><a title="Linux Action News on Podcastindex.org" rel="nofollow" href="https://podcastindex.org/podcast/203827">Linux Action News on Podcastindex.org</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 219</title>
  <link>https://linuxactionnews.com/219</link>
  <guid isPermaLink="false">5d1dfafe-be8f-4fb6-b463-856095effbf2</guid>
  <pubDate>Sun, 12 Dec 2021 19:30:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/5d1dfafe-be8f-4fb6-b463-856095effbf2.mp3" length="12259392" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The Log4Shell vulnerability is making waves this week; we'll explain why and break down how it works.</itunes:subtitle>
  <itunes:duration>17:01</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>The Log4Shell vulnerability is making waves this week; we'll explain why and break down how it works. 
Plus, some good news for the Desktop and systemd-homed gets one step closer. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, GNOME 42, Input Events, Refresh Rate, 144hz, GNOME Shell, FreeBSD 12.3, systemd 250, systemd-homed, UID mapped mounts, Log4Shell, log4j2, JNDI, Java Naming and Directory Interface,  Steam, Apple iCloud, Minecraft, Apache, Java, JVM, formatMsgNoLookups, Exploit, vulnerability, open source funding, Apache Struts</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The Log4Shell vulnerability is making waves this week; we&#39;ll explain why and break down how it works. </p>

<p>Plus, some good news for the Desktop and systemd-homed gets one step closer.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 42 To Finally Allow Input Events To Happen Full-Rate" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=GNOME-42-Input-Rate">GNOME 42 To Finally Allow Input Events To Happen Full-Rate</a> &mdash; Up to now GNOME Shell has been compressing pointer motion events so they are synchronized to the monitor refresh rate, which can be anywhere from around 30 to 144 events per second depending upon display.</li><li><a title="An Eventful Instant – GNOME Shell &amp; Mutter" rel="nofollow" href="https://blogs.gnome.org/shell-dev/2021/12/08/an-eventful-instant/">An Eventful Instant – GNOME Shell &amp; Mutter</a></li><li><a title="Do not throttle input in wayland event delivery" rel="nofollow" href="https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1915/diffs">Do not throttle input in wayland event delivery</a></li><li><a title="FreeBSD 12.3-RELEASE Announcement" rel="nofollow" href="https://www.freebsd.org/releases/12.3R/announce/">FreeBSD 12.3-RELEASE Announcement</a> &mdash; The FreeBSD Release Engineering Team is pleased to announce the availability of FreeBSD 12.3-RELEASE. This is the fourth release of the stable/12 branch.</li><li><a title="systemd 250 Is Coming With A Boat Load Of New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=systemd-250-RC">systemd 250 Is Coming With A Boat Load Of New Features</a> &mdash; systemd 250 is packing a rather large number of new features and changes across the board for this dominant Linux init system and service manager.</li><li><a title="Log4Shell" rel="nofollow" href="https://www.lunasec.io/docs/blog/log4j-zero-day/">Log4Shell</a> &mdash; RCE 0-day exploit found in log4j2, a popular Java logging package</li><li><a title="Apache - The ASF on Twitter" rel="nofollow" href="https://twitter.com/TheASF/status/1400875147163279374">Apache - The ASF on Twitter</a> &mdash; “Did you know that Ingenuity, the Mars 2020 Helicopter mission, is powered by Apache Log4j? https://t.co/gV0uyE1ylk #Apache #OpenSource #innovation #community #logging #services</li><li><a title="Tom (^-^) on Twitter" rel="nofollow" href="https://twitter.com/tomlawrencetech/status/1469647697380622342?s=12">Tom (^-^) on Twitter</a></li><li><a title="Kevin Beaumont on Twitter" rel="nofollow" href="https://twitter.com/GossiTheDog/status/1469248250670727169">Kevin Beaumont on Twitter</a> &mdash; “Starting a new thread for log4j security vulnerability and fallout. Spoiler: although this emerged as a Minecraft issue (lol) there is going to be impacts across a wide range of enterprise software for some time.”</li><li><a title="Log4jAttackSurface MEMES" rel="nofollow" href="https://github.com/YfryTchsGD/Log4jAttackSurface/blob/master/pages/MEME.md">Log4jAttackSurface MEMES</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The Log4Shell vulnerability is making waves this week; we&#39;ll explain why and break down how it works. </p>

<p>Plus, some good news for the Desktop and systemd-homed gets one step closer.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 42 To Finally Allow Input Events To Happen Full-Rate" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=GNOME-42-Input-Rate">GNOME 42 To Finally Allow Input Events To Happen Full-Rate</a> &mdash; Up to now GNOME Shell has been compressing pointer motion events so they are synchronized to the monitor refresh rate, which can be anywhere from around 30 to 144 events per second depending upon display.</li><li><a title="An Eventful Instant – GNOME Shell &amp; Mutter" rel="nofollow" href="https://blogs.gnome.org/shell-dev/2021/12/08/an-eventful-instant/">An Eventful Instant – GNOME Shell &amp; Mutter</a></li><li><a title="Do not throttle input in wayland event delivery" rel="nofollow" href="https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1915/diffs">Do not throttle input in wayland event delivery</a></li><li><a title="FreeBSD 12.3-RELEASE Announcement" rel="nofollow" href="https://www.freebsd.org/releases/12.3R/announce/">FreeBSD 12.3-RELEASE Announcement</a> &mdash; The FreeBSD Release Engineering Team is pleased to announce the availability of FreeBSD 12.3-RELEASE. This is the fourth release of the stable/12 branch.</li><li><a title="systemd 250 Is Coming With A Boat Load Of New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=systemd-250-RC">systemd 250 Is Coming With A Boat Load Of New Features</a> &mdash; systemd 250 is packing a rather large number of new features and changes across the board for this dominant Linux init system and service manager.</li><li><a title="Log4Shell" rel="nofollow" href="https://www.lunasec.io/docs/blog/log4j-zero-day/">Log4Shell</a> &mdash; RCE 0-day exploit found in log4j2, a popular Java logging package</li><li><a title="Apache - The ASF on Twitter" rel="nofollow" href="https://twitter.com/TheASF/status/1400875147163279374">Apache - The ASF on Twitter</a> &mdash; “Did you know that Ingenuity, the Mars 2020 Helicopter mission, is powered by Apache Log4j? https://t.co/gV0uyE1ylk #Apache #OpenSource #innovation #community #logging #services</li><li><a title="Tom (^-^) on Twitter" rel="nofollow" href="https://twitter.com/tomlawrencetech/status/1469647697380622342?s=12">Tom (^-^) on Twitter</a></li><li><a title="Kevin Beaumont on Twitter" rel="nofollow" href="https://twitter.com/GossiTheDog/status/1469248250670727169">Kevin Beaumont on Twitter</a> &mdash; “Starting a new thread for log4j security vulnerability and fallout. Spoiler: although this emerged as a Minecraft issue (lol) there is going to be impacts across a wide range of enterprise software for some time.”</li><li><a title="Log4jAttackSurface MEMES" rel="nofollow" href="https://github.com/YfryTchsGD/Log4jAttackSurface/blob/master/pages/MEME.md">Log4jAttackSurface MEMES</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
