<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Thu, 09 Apr 2026 12:17:16 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Linux Action News - Episodes Tagged with “Responsible Disclosure”</title>
    <link>https://linuxactionnews.com/tags/responsible%20disclosure</link>
    <pubDate>Thu, 30 Mar 2023 12:30:00 -0700</pubDate>
    <description>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Our weekly take on the free and open source world.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Linux Action News 286</title>
  <link>https://linuxactionnews.com/286</link>
  <guid isPermaLink="false">bfb01254-4fad-4e00-a759-6a8c5cb5975e</guid>
  <pubDate>Thu, 30 Mar 2023 12:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/bfb01254-4fad-4e00-a759-6a8c5cb5975e.mp3" length="17532208" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>What we're liking about GNOME 44, how Microsoft's Linux distro is trying to attract more users, and we bust a CentOS myth.</itunes:subtitle>
  <itunes:duration>20:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>What we're liking about GNOME 44, how Microsoft's Linux distro is trying to attract more users, and we bust a CentOS myth. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, GNOME 44, Linux desktop, Wayland, GTK4, File Chooser, Device Security, background apps, background app portal, Clutter, Mutter, OpenGL, Quick Settings, GNOME Software, Flatpak, Maps, Console, open source, Ubuntu Touch, OTA-1 Focal, Focal Fossa, UBPorts, Mobile, Linux Mint, Lomiri, Unity8, systemd, notifications, Waydroid, Android, GCC, Qt, Ubuntu, LTS, Ubuntu Cinnamon Remix, Ubuntu Flavor, Ubuntu Cinnamon, Cinnamon, Desktop Environment, Canonical, Lunar Lobster, Ubuntu 23.04, Ubuntu Unity, Microsoft, CBL Mariner, Python, Perl, Freefont, security, Rust, Vim, Apache, Redis, GitHub, Azure, WSL, Docker, Free Teams, Docker Hub, Docker-Sponsored Open Source, programming, Google, Project Zero, Linux, CentOS, RedHat, RHEL, kernel, vulnerabilities, patches, upstream, distros, bug, CVE, severity, enterprise, rolling release, Nix, Arch, Jann Horn, backporting, backports, CentOS Stream 9, Alma Linux, Rocky Linux, Enterprise Linux, Bugzilla, responsible disclosure, stable kernel, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>What we&#39;re liking about GNOME 44, how Microsoft&#39;s Linux distro is trying to attract more users, and we bust a CentOS myth.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 44 Released" rel="nofollow" href="https://release.gnome.org/44/">GNOME 44 Released</a> &mdash; GNOME 44 is code-named “Kuala Lumpur”, in recognition of the work done by the organizers of GNOME.Asia 2022.</li><li><a title="GNOME 44 Released With Many Desktop Enhancements" rel="nofollow" href="https://www.phoronix.com/news/GNOME-44-Released">GNOME 44 Released With Many Desktop Enhancements</a></li><li><a title="GNOME 44 Getting New Background Apps UI" rel="nofollow" href="https://www.omglinux.com/gnome-shell-background-apps-ui/">GNOME 44 Getting New Background Apps UI</a></li><li><a title="Ubuntu Touch OTA-1 Focal Release " rel="nofollow" href="https://ubports.com/blog/ubports-news-1/post/ubuntu-touch-ota-1-focal-release-3888">Ubuntu Touch OTA-1 Focal Release </a> &mdash; This is the first OTA for Ubuntu 20.04 (Focal) with major features, this is an Opt-In and not mandatory update. </li><li><a title="First Ubuntu Touch OTA Release Based on Ubuntu 20.04 LTS Is Out Now" rel="nofollow" href="https://9to5linux.com/first-ubuntu-touch-ota-release-based-on-ubuntu-20-04-lts-is-out-now">First Ubuntu Touch OTA Release Based on Ubuntu 20.04 LTS Is Out Now</a></li><li><a title="Ubuntu Cinnamon Flavor Status Announcement" rel="nofollow" href="https://ubuntucinnamon.org/ubuntu-cinnamon-flavor-status-announcement/">Ubuntu Cinnamon Flavor Status Announcement</a> &mdash; Ubuntu Cinnamon started as a small idea in my head, in 2019. I was ELEVEN. </li><li><a title="ItzSwirlz (Joshua Peisach)" rel="nofollow" href="https://github.com/ItzSwirlz">ItzSwirlz (Joshua Peisach)</a></li><li><a title="Ubuntu Cinnamon Remix Becomes Official Ubuntu Flavor" rel="nofollow" href="https://9to5linux.com/ubuntu-cinnamon-remix-becomes-official-ubuntu-flavor">Ubuntu Cinnamon Remix Becomes Official Ubuntu Flavor</a></li><li><a title="Microsoft’s CBL-Mariner Linux Distribution Continues Cultivating More Packages" rel="nofollow" href="https://www.phoronix.com/news/MS-CBL-Mariner-2.0.20230321">Microsoft’s CBL-Mariner Linux Distribution Continues Cultivating More Packages</a> &mdash;  With today's CBL-Mariner 2.0.20230321 they have continued cultivating more packages for the distribution. </li><li><a title="CBL-Mariner GitHub" rel="nofollow" href="https://github.com/microsoft/CBL-Mariner">CBL-Mariner GitHub</a></li><li><a title="We’re no longer sunsetting the Free Team plan" rel="nofollow" href="https://www.docker.com/blog/no-longer-sunsetting-the-free-team-plan/">We’re no longer sunsetting the Free Team plan</a> &mdash; After listening to feedback and consulting our community, it’s clear that we made the wrong decision in sunsetting our Free Team plan.</li><li><a title="Google discloses CentOS Linux kernel vulnerabilities following failure to issue timely fixes" rel="nofollow" href="https://www.neowin.net/news/google-discloses-centos-linux-kernel-vulnerabilities-following-failure-to-issue-timely-fixes/">Google discloses CentOS Linux kernel vulnerabilities following failure to issue timely fixes</a> &mdash; Google Project Zero's security researcher Jann Horn learned that kernel fixes made to stable trees are not backported to many enterprise versions of Linux. </li><li><a title="Google Security Researchers Accuse CentOS of Failing to Backport Kernel Fixes" rel="nofollow" href="https://tech.slashdot.org/story/23/03/25/2133226/google-security-researchers-accuse-centos-of-failing-to-backport-kernel-fixes">Google Security Researchers Accuse CentOS of Failing to Backport Kernel Fixes</a></li><li><a title="Project Zero Mailing List Thread on CentOS Kernel Patches" rel="nofollow" href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2439&amp;can=2&amp;q=&amp;colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&amp;cells=ids">Project Zero Mailing List Thread on CentOS Kernel Patches</a></li><li><a title="CVE-2023-0590" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2165741">CVE-2023-0590</a></li><li><a title="kernel-5.14.0-277.el9" rel="nofollow" href="https://kojihub.stream.centos.org/koji/buildinfo?buildID=30576">kernel-5.14.0-277.el9</a></li><li><a title="CVE-2023-1249" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2169719">CVE-2023-1249</a></li><li><a title="CVE-2023-1252" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2176140">CVE-2023-1252</a></li><li><a title="Berlin Meet Up #2 - Nextcloud Hackfest &amp; Dev Community Introduction, Fri, Mar 31, 2023" rel="nofollow" href="https://www.meetup.com/jupiterbroadcasting/events/292533810/">Berlin Meet Up #2 - Nextcloud Hackfest &amp; Dev Community Introduction, Fri, Mar 31, 2023</a> &mdash; NOTE: the time detailed on Meetup.com is strictly set to PST, so don't be confused by the interface!</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>What we&#39;re liking about GNOME 44, how Microsoft&#39;s Linux distro is trying to attract more users, and we bust a CentOS myth.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 44 Released" rel="nofollow" href="https://release.gnome.org/44/">GNOME 44 Released</a> &mdash; GNOME 44 is code-named “Kuala Lumpur”, in recognition of the work done by the organizers of GNOME.Asia 2022.</li><li><a title="GNOME 44 Released With Many Desktop Enhancements" rel="nofollow" href="https://www.phoronix.com/news/GNOME-44-Released">GNOME 44 Released With Many Desktop Enhancements</a></li><li><a title="GNOME 44 Getting New Background Apps UI" rel="nofollow" href="https://www.omglinux.com/gnome-shell-background-apps-ui/">GNOME 44 Getting New Background Apps UI</a></li><li><a title="Ubuntu Touch OTA-1 Focal Release " rel="nofollow" href="https://ubports.com/blog/ubports-news-1/post/ubuntu-touch-ota-1-focal-release-3888">Ubuntu Touch OTA-1 Focal Release </a> &mdash; This is the first OTA for Ubuntu 20.04 (Focal) with major features, this is an Opt-In and not mandatory update. </li><li><a title="First Ubuntu Touch OTA Release Based on Ubuntu 20.04 LTS Is Out Now" rel="nofollow" href="https://9to5linux.com/first-ubuntu-touch-ota-release-based-on-ubuntu-20-04-lts-is-out-now">First Ubuntu Touch OTA Release Based on Ubuntu 20.04 LTS Is Out Now</a></li><li><a title="Ubuntu Cinnamon Flavor Status Announcement" rel="nofollow" href="https://ubuntucinnamon.org/ubuntu-cinnamon-flavor-status-announcement/">Ubuntu Cinnamon Flavor Status Announcement</a> &mdash; Ubuntu Cinnamon started as a small idea in my head, in 2019. I was ELEVEN. </li><li><a title="ItzSwirlz (Joshua Peisach)" rel="nofollow" href="https://github.com/ItzSwirlz">ItzSwirlz (Joshua Peisach)</a></li><li><a title="Ubuntu Cinnamon Remix Becomes Official Ubuntu Flavor" rel="nofollow" href="https://9to5linux.com/ubuntu-cinnamon-remix-becomes-official-ubuntu-flavor">Ubuntu Cinnamon Remix Becomes Official Ubuntu Flavor</a></li><li><a title="Microsoft’s CBL-Mariner Linux Distribution Continues Cultivating More Packages" rel="nofollow" href="https://www.phoronix.com/news/MS-CBL-Mariner-2.0.20230321">Microsoft’s CBL-Mariner Linux Distribution Continues Cultivating More Packages</a> &mdash;  With today's CBL-Mariner 2.0.20230321 they have continued cultivating more packages for the distribution. </li><li><a title="CBL-Mariner GitHub" rel="nofollow" href="https://github.com/microsoft/CBL-Mariner">CBL-Mariner GitHub</a></li><li><a title="We’re no longer sunsetting the Free Team plan" rel="nofollow" href="https://www.docker.com/blog/no-longer-sunsetting-the-free-team-plan/">We’re no longer sunsetting the Free Team plan</a> &mdash; After listening to feedback and consulting our community, it’s clear that we made the wrong decision in sunsetting our Free Team plan.</li><li><a title="Google discloses CentOS Linux kernel vulnerabilities following failure to issue timely fixes" rel="nofollow" href="https://www.neowin.net/news/google-discloses-centos-linux-kernel-vulnerabilities-following-failure-to-issue-timely-fixes/">Google discloses CentOS Linux kernel vulnerabilities following failure to issue timely fixes</a> &mdash; Google Project Zero's security researcher Jann Horn learned that kernel fixes made to stable trees are not backported to many enterprise versions of Linux. </li><li><a title="Google Security Researchers Accuse CentOS of Failing to Backport Kernel Fixes" rel="nofollow" href="https://tech.slashdot.org/story/23/03/25/2133226/google-security-researchers-accuse-centos-of-failing-to-backport-kernel-fixes">Google Security Researchers Accuse CentOS of Failing to Backport Kernel Fixes</a></li><li><a title="Project Zero Mailing List Thread on CentOS Kernel Patches" rel="nofollow" href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2439&amp;can=2&amp;q=&amp;colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&amp;cells=ids">Project Zero Mailing List Thread on CentOS Kernel Patches</a></li><li><a title="CVE-2023-0590" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2165741">CVE-2023-0590</a></li><li><a title="kernel-5.14.0-277.el9" rel="nofollow" href="https://kojihub.stream.centos.org/koji/buildinfo?buildID=30576">kernel-5.14.0-277.el9</a></li><li><a title="CVE-2023-1249" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2169719">CVE-2023-1249</a></li><li><a title="CVE-2023-1252" rel="nofollow" href="https://bugzilla.redhat.com/show_bug.cgi?id=2176140">CVE-2023-1252</a></li><li><a title="Berlin Meet Up #2 - Nextcloud Hackfest &amp; Dev Community Introduction, Fri, Mar 31, 2023" rel="nofollow" href="https://www.meetup.com/jupiterbroadcasting/events/292533810/">Berlin Meet Up #2 - Nextcloud Hackfest &amp; Dev Community Introduction, Fri, Mar 31, 2023</a> &mdash; NOTE: the time detailed on Meetup.com is strictly set to PST, so don't be confused by the interface!</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 276</title>
  <link>https://linuxactionnews.com/276</link>
  <guid isPermaLink="false">b0fdfcdd-3ec2-4c0e-93c0-7bbd81219973</guid>
  <pubDate>Thu, 19 Jan 2023 10:30:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/b0fdfcdd-3ec2-4c0e-93c0-7bbd81219973.mp3" length="14058654" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</itunes:subtitle>
  <itunes:duration>16:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week. 
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, netfilter, Linux, kernel, security, privilege escalation, packet filtering, networking, iptables, nftables, CVE-2023-0179, Linux 6.2, buffer overflow, auditing, stack overflow, responsible disclosure, unprivileged user namespaces, sysctl, nft_payload, VLAN,  Red Hat, oss-sec, libvirt 9.0, libvirt,  virtualization, QEMU, Daniel Berrange, Qumranet, Windows, macOS, C, Python, Perl, Go, PASST, emulated network, JFS, journaling filesystems, ReiserFS, snapshots, Christoph Hellwig, Mozilla, Firefox 109, Firefox, Manifest V3, Browser Extensions, WebRequest API, adblocking, uBlock Origin, AdBlock Plus, declarativeNetRequest, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="A new privilege escalation vulnerability in the Linux kernel" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/20">A new privilege escalation vulnerability in the Linux kernel</a> &mdash; The vulnerability consists of a stack buffer overflow due to an integer
underflow vulnerability inside the nft_payload_copy_vlan function, which is
invoked with nft_payload expressions as long as a VLAN tag is present in
the current skb.</li><li><a title="netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1" rel="nofollow" href="https://github.com/torvalds/linux/commit/f6ae9f1">netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1</a></li><li><a title="CVE-2023-0179" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2023-0179">CVE-2023-0179</a></li><li><a title="CVE-2023-0179- Red Hat Customer Portal" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2023-0179">CVE-2023-0179- Red Hat Customer Portal</a></li><li><a title="[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork" rel="nofollow" href="https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/">[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork</a></li><li><a title="oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/22">oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup</a></li><li><a title="libvirt 9.0 Released For Latest Linux Virtualization API" rel="nofollow" href="https://www.phoronix.com/news/libvirt-9.0">libvirt 9.0 Released For Latest Linux Virtualization API</a> &mdash; Libvirt 9.0 adds support for external snapshot deletion with QEMU using its existing API, libvirt 9.0 with QEMU now supports PASST as "Plug A Simple Socket Transport" for connecting an emulated network device to the host's network, QEMU external back-end support for SWTPM as a software Trusted Platform Module (TPM), support for passing file descriptors rather than passing files for the QEMU disk, and other additions. </li><li><a title="JFS Filesystem’s Days are Numbered" rel="nofollow" href="https://www.phoronix.com/news/Linux-Possible-Orphan-JFS">JFS Filesystem’s Days are Numbered</a> &mdash; IBM developed the JFS file-system originally in the 90's for AIX and the second-generation implementation then ported to Linux after it was made open-source. </li><li><a title="Firefox 109.0 Ships Manifest Version 3" rel="nofollow" href="https://www.mozilla.org/en-US/firefox/109.0/releasenotes/">Firefox 109.0 Ships Manifest Version 3</a> &mdash; Manifest Version 3 (MV3) extension support is now enabled by default (MV2 remains enabled/supported). This major update also ushers an exciting user interface change in the form of the new extensions button.</li><li><a title="Here’s what’s going on in the world of extensions" rel="nofollow" href="https://blog.mozilla.org/en/products/firefox/extensions-addons/heres-whats-going-on-in-the-world-of-extensions/">Here’s what’s going on in the world of extensions</a></li><li><a title="Manage your extensions using the extensions button in the toolbar" rel="nofollow" href="https://support.mozilla.org/en-US/kb/unified-extensions">Manage your extensions using the extensions button in the toolbar</a></li><li><a title="Manifest v3 signing available November 21 on Firefox Nightly" rel="nofollow" href="https://blog.mozilla.org/addons/2022/11/17/manifest-v3-signing-available-november-21-on-firefox-nightly/">Manifest v3 signing available November 21 on Firefox Nightly</a></li><li><a title="Google delays start of Manifest V2 Chrome extension deprecation" rel="nofollow" href="https://9to5google.com/2022/12/12/manifest-v2-chrome-extension/">Google delays start of Manifest V2 Chrome extension deprecation</a> &mdash; The original plan called for Chrome Beta, Dev, and Canary builds to start experiments that turned off Manifest V2 extension support. Additionally, Manifest V3 would be required to get the “Featured” badge in the Chrome Web Store. </li><li><a title="Firefox 109 Adds New Extensions Button, Manifest V3 Support" rel="nofollow" href="https://www.omgubuntu.co.uk/2023/01/firefox-109-released">Firefox 109 Adds New Extensions Button, Manifest V3 Support</a> &mdash; The biggest new feature is the new Unified Extensions button in the toolbar. </li><li><a title="Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed" rel="nofollow" href="https://arstechnica.com/gadgets/2022/12/chrome-delays-plan-to-limit-ad-blockers-new-timeline-coming-in-march">Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed</a></li><li><a title=" Chrome Users Beware: Manifest V3 is Deceitful and Threatening" rel="nofollow" href="https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening"> Chrome Users Beware: Manifest V3 is Deceitful and Threatening</a> &mdash; Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>A high-profile Linux kernel network flaw, we put JFS on a death watch, and break down the controversial Firefox update this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="A new privilege escalation vulnerability in the Linux kernel" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/20">A new privilege escalation vulnerability in the Linux kernel</a> &mdash; The vulnerability consists of a stack buffer overflow due to an integer
underflow vulnerability inside the nft_payload_copy_vlan function, which is
invoked with nft_payload expressions as long as a VLAN tag is present in
the current skb.</li><li><a title="netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1" rel="nofollow" href="https://github.com/torvalds/linux/commit/f6ae9f1">netfilter: nft_payload: add C-VLAN support · torvalds/linux@f6ae9f1</a></li><li><a title="CVE-2023-0179" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2023-0179">CVE-2023-0179</a></li><li><a title="CVE-2023-0179- Red Hat Customer Portal" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2023-0179">CVE-2023-0179- Red Hat Customer Portal</a></li><li><a title="[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork" rel="nofollow" href="https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/">[net,3/3] netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits - Patchwork</a></li><li><a title="oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup" rel="nofollow" href="https://seclists.org/oss-sec/2023/q1/22">oss-sec: Re: CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup</a></li><li><a title="libvirt 9.0 Released For Latest Linux Virtualization API" rel="nofollow" href="https://www.phoronix.com/news/libvirt-9.0">libvirt 9.0 Released For Latest Linux Virtualization API</a> &mdash; Libvirt 9.0 adds support for external snapshot deletion with QEMU using its existing API, libvirt 9.0 with QEMU now supports PASST as "Plug A Simple Socket Transport" for connecting an emulated network device to the host's network, QEMU external back-end support for SWTPM as a software Trusted Platform Module (TPM), support for passing file descriptors rather than passing files for the QEMU disk, and other additions. </li><li><a title="JFS Filesystem’s Days are Numbered" rel="nofollow" href="https://www.phoronix.com/news/Linux-Possible-Orphan-JFS">JFS Filesystem’s Days are Numbered</a> &mdash; IBM developed the JFS file-system originally in the 90's for AIX and the second-generation implementation then ported to Linux after it was made open-source. </li><li><a title="Firefox 109.0 Ships Manifest Version 3" rel="nofollow" href="https://www.mozilla.org/en-US/firefox/109.0/releasenotes/">Firefox 109.0 Ships Manifest Version 3</a> &mdash; Manifest Version 3 (MV3) extension support is now enabled by default (MV2 remains enabled/supported). This major update also ushers an exciting user interface change in the form of the new extensions button.</li><li><a title="Here’s what’s going on in the world of extensions" rel="nofollow" href="https://blog.mozilla.org/en/products/firefox/extensions-addons/heres-whats-going-on-in-the-world-of-extensions/">Here’s what’s going on in the world of extensions</a></li><li><a title="Manage your extensions using the extensions button in the toolbar" rel="nofollow" href="https://support.mozilla.org/en-US/kb/unified-extensions">Manage your extensions using the extensions button in the toolbar</a></li><li><a title="Manifest v3 signing available November 21 on Firefox Nightly" rel="nofollow" href="https://blog.mozilla.org/addons/2022/11/17/manifest-v3-signing-available-november-21-on-firefox-nightly/">Manifest v3 signing available November 21 on Firefox Nightly</a></li><li><a title="Google delays start of Manifest V2 Chrome extension deprecation" rel="nofollow" href="https://9to5google.com/2022/12/12/manifest-v2-chrome-extension/">Google delays start of Manifest V2 Chrome extension deprecation</a> &mdash; The original plan called for Chrome Beta, Dev, and Canary builds to start experiments that turned off Manifest V2 extension support. Additionally, Manifest V3 would be required to get the “Featured” badge in the Chrome Web Store. </li><li><a title="Firefox 109 Adds New Extensions Button, Manifest V3 Support" rel="nofollow" href="https://www.omgubuntu.co.uk/2023/01/firefox-109-released">Firefox 109 Adds New Extensions Button, Manifest V3 Support</a> &mdash; The biggest new feature is the new Unified Extensions button in the toolbar. </li><li><a title="Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed" rel="nofollow" href="https://arstechnica.com/gadgets/2022/12/chrome-delays-plan-to-limit-ad-blockers-new-timeline-coming-in-march">Chrome’s “Manifest V3” plan to limit ad-blocking extensions is delayed</a></li><li><a title=" Chrome Users Beware: Manifest V3 is Deceitful and Threatening" rel="nofollow" href="https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening"> Chrome Users Beware: Manifest V3 is Deceitful and Threatening</a> &mdash; Manifest V3, or Mv3 for short, is outright harmful to privacy efforts. It will restrict the capabilities of web extensions</li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
