<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 09 May 2026 00:00:24 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Linux Action News - Episodes Tagged with “Vulnerability”</title>
    <link>https://linuxactionnews.com/tags/vulnerability</link>
    <pubDate>Thu, 05 Jan 2023 08:15:00 -0800</pubDate>
    <description>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Our weekly take on the free and open source world.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Weekly Linux news and analysis by Chris and Wes. The show every week we hope you'll go to when you want to hear an informed discussion about what’s happening.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Linux Action News 274</title>
  <link>https://linuxactionnews.com/274</link>
  <guid isPermaLink="false">265a70d2-c9ab-4dc8-8aea-e83fa23860f3</guid>
  <pubDate>Thu, 05 Jan 2023 08:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/265a70d2-c9ab-4dc8-8aea-e83fa23860f3.mp3" length="14308071" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</itunes:subtitle>
  <itunes:duration>17:01</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>&lt;p&gt;Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along. &lt;/p&gt;
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Google, Android, RISC-V, Arm, Linux, tooling, 64-bit, Apache Licensed, open source vulnerability database, OpenSSF, OSV format, commit hashes, dependencies, manifests, software bill of materials (SBOMs), Rust, Javascript, PHP, Ruby, Go, Elixir, Python, Flutter, Java, Gradle, Debian packages, docker container, OpensSSF Scorecard, vulnerability prevention, OSV-Scanner, OpenSSF Scorecard's Vulnerabilities check, OSV project, OSV schema, vulnerability databases, OSV database, supply chain practices, open-source projects,Ubuntu, installer, Lunar Lobster, UI, ZFS, Btrfs, Subiquity, Flutter, darktheme, lighttheme, HDR, Linux, SteamPlay, gamescope, Valve, RedHat, Nvidia, Collabora, GNOME, Mutter, VKD3D-Proton, Linode, Kolide, Google Home, bug, Matt Kunze, smartspeaker, IoT, smart home,  backdoor, mic, vulnerability</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Android Gets RISC-Y" rel="nofollow" href="https://arstechnica.com/gadgets/2023/01/google-announces-official-android-support-for-risc-v/">Android Gets RISC-Y</a> &mdash; Google's keynote at the RISC-V Summit promises official, polished support. </li><li><a title="Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering" rel="nofollow" href="https://www.youtube.com/watch?v=70O_RmTWP58">Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering</a></li><li><a title="New Google Tool Goes Open" rel="nofollow" href="https://www.infoq.com/news/2022/12/google-osv-scanner/">New Google Tool Goes Open</a> &mdash; The OSV database is a distributed, open-source database that stores vulnerability information in the OSV format. The OSV-Scanner assesses a project's dependencies against the OSV database showing all vulnerabilities relating to the project.</li><li><a title="Ubuntu’s New Installer Milestone" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-23.04-New-Installer-Jan">Ubuntu’s New Installer Milestone</a> &mdash; With Ubuntu 23.04 "Lunar Lobster" in April that new desktop installer is poised to finally be used by default. </li><li><a title="HDR Beginning To Work For Linux Gaming" rel="nofollow" href="https://www.phoronix.com/news/Valve-HDR-Linux-Gaming-Begins">HDR Beginning To Work For Linux Gaming</a> &mdash; "New Linux gaming milestone: with the latest work from Josh Ashton, HDR can now be enabled for real games! Tested it tonight on my AMD desktop with Halo Infinite, Deep Rock Galactic, DEATH STRANDING DC. Very early and will still need some time to bake to be useful to most."</li><li><a title="Red Hat Planning HDR Hackfest" rel="nofollow" href="https://wiki.gnome.org/Hackfests/ShellDisplayNext2023">Red Hat Planning HDR Hackfest</a></li><li><a title="GNOME Shell + Mutter 43 Alpha Released" rel="nofollow" href="https://www.phoronix.com/news/GNOME-Shell-Mutter-43-Alpha">GNOME Shell + Mutter 43 Alpha Released</a></li><li><a title="VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes" rel="nofollow" href="https://www.phoronix.com/news/VKD3D-Proton-2.7-Released">VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes</a></li><li><a title="Google Home speakers allowed hackers to snoop on conversations" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/google-home-speakers-allowed-hackers-to-snoop-on-conversations/">Google Home speakers allowed hackers to snoop on conversations</a> &mdash; A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Android is getting RISC-Y, the handy new Google tool going open source, the next nail in the coffin for ZFS on Ubuntu, and why you were right about smart speakers all along.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Android Gets RISC-Y" rel="nofollow" href="https://arstechnica.com/gadgets/2023/01/google-announces-official-android-support-for-risc-v/">Android Gets RISC-Y</a> &mdash; Google's keynote at the RISC-V Summit promises official, polished support. </li><li><a title="Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering" rel="nofollow" href="https://www.youtube.com/watch?v=70O_RmTWP58">Keynote: The Android Open Source Project and RISC-V - Lars Bergstrom, Google Director of Engineering</a></li><li><a title="New Google Tool Goes Open" rel="nofollow" href="https://www.infoq.com/news/2022/12/google-osv-scanner/">New Google Tool Goes Open</a> &mdash; The OSV database is a distributed, open-source database that stores vulnerability information in the OSV format. The OSV-Scanner assesses a project's dependencies against the OSV database showing all vulnerabilities relating to the project.</li><li><a title="Ubuntu’s New Installer Milestone" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-23.04-New-Installer-Jan">Ubuntu’s New Installer Milestone</a> &mdash; With Ubuntu 23.04 "Lunar Lobster" in April that new desktop installer is poised to finally be used by default. </li><li><a title="HDR Beginning To Work For Linux Gaming" rel="nofollow" href="https://www.phoronix.com/news/Valve-HDR-Linux-Gaming-Begins">HDR Beginning To Work For Linux Gaming</a> &mdash; "New Linux gaming milestone: with the latest work from Josh Ashton, HDR can now be enabled for real games! Tested it tonight on my AMD desktop with Halo Infinite, Deep Rock Galactic, DEATH STRANDING DC. Very early and will still need some time to bake to be useful to most."</li><li><a title="Red Hat Planning HDR Hackfest" rel="nofollow" href="https://wiki.gnome.org/Hackfests/ShellDisplayNext2023">Red Hat Planning HDR Hackfest</a></li><li><a title="GNOME Shell + Mutter 43 Alpha Released" rel="nofollow" href="https://www.phoronix.com/news/GNOME-Shell-Mutter-43-Alpha">GNOME Shell + Mutter 43 Alpha Released</a></li><li><a title="VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes" rel="nofollow" href="https://www.phoronix.com/news/VKD3D-Proton-2.7-Released">VKD3D-Proton 2.7 Released With Eight Months Worth Of Changes</a></li><li><a title="Google Home speakers allowed hackers to snoop on conversations" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/google-home-speakers-allowed-hackers-to-snoop-on-conversations/">Google Home speakers allowed hackers to snoop on conversations</a> &mdash; A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 260</title>
  <link>https://linuxactionnews.com/260</link>
  <guid isPermaLink="false">aadf35cb-e69e-4206-8c33-3a81732bc066</guid>
  <pubDate>Thu, 29 Sep 2022 05:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/aadf35cb-e69e-4206-8c33-3a81732bc066.mp3" length="17320825" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The controversial change for the GNU Toolchain, critical vulnerabilities in popular Matrix clients, and the significant milestone for the Ingenuity LinuxCopter this week.</itunes:subtitle>
  <itunes:duration>20:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>&lt;p&gt;The controversial change for the GNU Toolchain, critical vulnerabilities in popular Matrix clients, and the significant milestone for the Ingenuity LinuxCopter this week. &lt;/p&gt;
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, GNU Toolchain Infrastructure Project, GTI, Linux Foundation, GCC, glibc, Red Hat, kernel, sourceware, SFC, Software Freedom Conservancy, Plasma Mobile Gear, 22.09, mobile Linux, podcasts, sleep timer, call screening, call blocking, DRM, Rust, Apple M, Asahi Linux, HDMI, Asahi Lina, Wayland, E2EE, Matrix, Element, SDK, matrix-js-sdk, vulnerability, security, encryption, MARS 2020, Perseverance, Ingenuity, MarsHelicopter, LinuxCopter, Flight 33, JPL, NASA, aerospace, space exploration, DART, asteroid, Dimorphos, kinetic impact, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The controversial change for the GNU Toolchain, critical vulnerabilities in popular Matrix clients, and the significant milestone for the Ingenuity LinuxCopter this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Announcing the GNU Toolchain Infrastructure Project" rel="nofollow" href="https://lwn.net/Articles/909704/">Announcing the GNU Toolchain Infrastructure Project</a> &mdash; Linux Foundation IT services plans for the GNU Toolchain include Git repositories, mailing lists, issue tracking, web sites, and CI/CD, implemented with strong authentication, attestation, and security posture. Utilizing the experience and infrastructure of the LF IT team that is already used by the Linux kernel community will provide the most effective solution and best experience for the GNU Toolchain developer community.</li><li><a title="Sourceware.org" rel="nofollow" href="http://sourceware.org/">Sourceware.org</a></li><li><a title="GNU Toolchain Plans Move To The Linux Foundation’s Infrastructure" rel="nofollow" href="https://www.phoronix.com/news/GNU-Toolchain-Infrastructure">GNU Toolchain Plans Move To The Linux Foundation’s Infrastructure</a></li><li><a title="Two visions for the future of sourceware.org" rel="nofollow" href="https://lwn.net/Articles/908638/">Two visions for the future of sourceware.org</a></li><li><a title="Plasma Mobile Gear Update" rel="nofollow" href="https://plasma-mobile.org/2022/09/27/plasma-mobile-gear-22-09/">Plasma Mobile Gear Update</a> &mdash; The Plasma Mobile team is happy to announce the developments integrated into Plasma Mobile between July-September 2022.</li><li><a title="The Work-In-Progress Rust-Written Apple DRM Driver Manages To Start Wayland’s Weston" rel="nofollow" href="https://www.phoronix.com/news/Rust-Apple-DRM-Starts-Weston">The Work-In-Progress Rust-Written Apple DRM Driver Manages To Start Wayland’s Weston</a> &mdash; After passing the initial spinning cube milestone this past weekend, Asahi Lina has been working on bringing up more of this reverse-engineered kernel DRM/KMS driver.</li><li><a title="Asahi Lina on Twitter" rel="nofollow" href="https://twitter.com/LinaAsahi/status/1575100421823115264">Asahi Lina on Twitter</a> &mdash; 🚀 Weston/Wayland works!!! 🚀 KDE doesn’t start all the way yet, but on X at least it showed the splash screen ^^ </li><li><a title="Upgrade now to address E2EE vulnerabilities in matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2" rel="nofollow" href="https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients">Upgrade now to address E2EE vulnerabilities in matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2</a> &mdash; Two critical severity vulnerabilities in end-to-end encryption were found in the SDKs which power Element, Beeper, Cinny, SchildiChat, Circuli, Synod.im and any other clients based on matrix-js-sdk, matrix-ios-sdk or matrix-android-sdk2.</li><li><a title="Akamai Turns Linode Up Past 11 " rel="nofollow" href="https://www.linode.com/blog/linode/akamai-turns-linode-up-past-11">Akamai Turns Linode Up Past 11 </a></li><li><a title="Over the weekend, #MarsHelicopter successfully completed Flight 33" rel="nofollow" href="https://twitter.com/NASAJPL/status/1574899348197949440">Over the weekend, #MarsHelicopter successfully completed Flight 33</a> &mdash; The rotorcraft reached an altitude of 10 meters (33 ft) and traveled 111.24 meters (365 ft) in 55.2 seconds.</li><li><a title="There will be up to five flights in the 31-day test period. " rel="nofollow" href="https://twitter.com/NASAJPL/status/1380938444927508484">There will be up to five flights in the 31-day test period. </a> &mdash; The NASAPersevere rover will attempt to capture video of those flights.</li><li><a title="NASA’s Asteroid-Striking DART Mission Team Has JPL Members" rel="nofollow" href="https://www.jpl.nasa.gov/news/nasas-asteroid-striking-dart-mission-team-has-jpl-members">NASA’s Asteroid-Striking DART Mission Team Has JPL Members</a> &mdash; JPL’s navigation section is experienced at getting spacecraft to faraway locations accurately.</li><li><a title="How JPL’s role in NASA’s DART asteroid impact could save the earth one day – Pasadena Star News" rel="nofollow" href="https://www.pasadenastarnews.com/2022/09/26/how-jpls-role-in-nasas-dart-asteroid-impact-could-save-the-earth-one-day/">How JPL’s role in NASA’s DART asteroid impact could save the earth one day – Pasadena Star News</a></li><li><a title="DART’s Impact with Asteroid Dimorphos (Official NASA Broadcast)" rel="nofollow" href="https://youtu.be/4RA8Tfa6Sck?t=4604">DART’s Impact with Asteroid Dimorphos (Official NASA Broadcast)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The controversial change for the GNU Toolchain, critical vulnerabilities in popular Matrix clients, and the significant milestone for the Ingenuity LinuxCopter this week.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Announcing the GNU Toolchain Infrastructure Project" rel="nofollow" href="https://lwn.net/Articles/909704/">Announcing the GNU Toolchain Infrastructure Project</a> &mdash; Linux Foundation IT services plans for the GNU Toolchain include Git repositories, mailing lists, issue tracking, web sites, and CI/CD, implemented with strong authentication, attestation, and security posture. Utilizing the experience and infrastructure of the LF IT team that is already used by the Linux kernel community will provide the most effective solution and best experience for the GNU Toolchain developer community.</li><li><a title="Sourceware.org" rel="nofollow" href="http://sourceware.org/">Sourceware.org</a></li><li><a title="GNU Toolchain Plans Move To The Linux Foundation’s Infrastructure" rel="nofollow" href="https://www.phoronix.com/news/GNU-Toolchain-Infrastructure">GNU Toolchain Plans Move To The Linux Foundation’s Infrastructure</a></li><li><a title="Two visions for the future of sourceware.org" rel="nofollow" href="https://lwn.net/Articles/908638/">Two visions for the future of sourceware.org</a></li><li><a title="Plasma Mobile Gear Update" rel="nofollow" href="https://plasma-mobile.org/2022/09/27/plasma-mobile-gear-22-09/">Plasma Mobile Gear Update</a> &mdash; The Plasma Mobile team is happy to announce the developments integrated into Plasma Mobile between July-September 2022.</li><li><a title="The Work-In-Progress Rust-Written Apple DRM Driver Manages To Start Wayland’s Weston" rel="nofollow" href="https://www.phoronix.com/news/Rust-Apple-DRM-Starts-Weston">The Work-In-Progress Rust-Written Apple DRM Driver Manages To Start Wayland’s Weston</a> &mdash; After passing the initial spinning cube milestone this past weekend, Asahi Lina has been working on bringing up more of this reverse-engineered kernel DRM/KMS driver.</li><li><a title="Asahi Lina on Twitter" rel="nofollow" href="https://twitter.com/LinaAsahi/status/1575100421823115264">Asahi Lina on Twitter</a> &mdash; 🚀 Weston/Wayland works!!! 🚀 KDE doesn’t start all the way yet, but on X at least it showed the splash screen ^^ </li><li><a title="Upgrade now to address E2EE vulnerabilities in matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2" rel="nofollow" href="https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients">Upgrade now to address E2EE vulnerabilities in matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2</a> &mdash; Two critical severity vulnerabilities in end-to-end encryption were found in the SDKs which power Element, Beeper, Cinny, SchildiChat, Circuli, Synod.im and any other clients based on matrix-js-sdk, matrix-ios-sdk or matrix-android-sdk2.</li><li><a title="Akamai Turns Linode Up Past 11 " rel="nofollow" href="https://www.linode.com/blog/linode/akamai-turns-linode-up-past-11">Akamai Turns Linode Up Past 11 </a></li><li><a title="Over the weekend, #MarsHelicopter successfully completed Flight 33" rel="nofollow" href="https://twitter.com/NASAJPL/status/1574899348197949440">Over the weekend, #MarsHelicopter successfully completed Flight 33</a> &mdash; The rotorcraft reached an altitude of 10 meters (33 ft) and traveled 111.24 meters (365 ft) in 55.2 seconds.</li><li><a title="There will be up to five flights in the 31-day test period. " rel="nofollow" href="https://twitter.com/NASAJPL/status/1380938444927508484">There will be up to five flights in the 31-day test period. </a> &mdash; The NASAPersevere rover will attempt to capture video of those flights.</li><li><a title="NASA’s Asteroid-Striking DART Mission Team Has JPL Members" rel="nofollow" href="https://www.jpl.nasa.gov/news/nasas-asteroid-striking-dart-mission-team-has-jpl-members">NASA’s Asteroid-Striking DART Mission Team Has JPL Members</a> &mdash; JPL’s navigation section is experienced at getting spacecraft to faraway locations accurately.</li><li><a title="How JPL’s role in NASA’s DART asteroid impact could save the earth one day – Pasadena Star News" rel="nofollow" href="https://www.pasadenastarnews.com/2022/09/26/how-jpls-role-in-nasas-dart-asteroid-impact-could-save-the-earth-one-day/">How JPL’s role in NASA’s DART asteroid impact could save the earth one day – Pasadena Star News</a></li><li><a title="DART’s Impact with Asteroid Dimorphos (Official NASA Broadcast)" rel="nofollow" href="https://youtu.be/4RA8Tfa6Sck?t=4604">DART’s Impact with Asteroid Dimorphos (Official NASA Broadcast)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 258</title>
  <link>https://linuxactionnews.com/258</link>
  <guid isPermaLink="false">c5c0ebc1-87cf-4e39-9d90-7718590f28bc</guid>
  <pubDate>Thu, 15 Sep 2022 03:00:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/c5c0ebc1-87cf-4e39-9d90-7718590f28bc.mp3" length="19777328" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The Linux Foundation takes a victory lap, Google kills another community-loved project, and key moments from the Linux Plumbers Conference.</itunes:subtitle>
  <itunes:duration>23:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>&lt;p&gt;The Linux Foundation takes a victory lap, Google kills another community-loved project, and key moments from the Linux Plumbers Conference. &lt;/p&gt;
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, malware, virus, Shikitega, AT&amp;T, Alien Labs, Shikata ga Nai, polymorphic encoder, shellcode, Mettle Metasploit, interpreter, vulnerability, security, XMRig, cryptocurrency miner, reverse shell, EDR, OpenWrt 22.03, nftables, iptables, router, firewall, embedded devices, WiFi 6, musl, busybox, 2038 problem, dark mode, Linux Foundation, OpenWallet Foundation, OWF, digital wallets, Open Source Summit Europe, Linux Foundation Europe, Open Source, PyTorch, AI, ML, Facebook, Meta, Google, Pixelbook, Chromebook, ChromeOS, Linux Plumbers Conference, LPC, Rust, Western Digital, NVMe, performance, openCL, io_uring, eBPF, async I/O, LPC, Josh Triplett, fork, vfork, posix_spawn, Jens Axboe, optimization, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The Linux Foundation takes a victory lap, Google kills another community-loved project, and key moments from the Linux Plumbers Conference.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Shikitega -  AT&amp;T Alien Labs" rel="nofollow" href="https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux">Shikitega -  AT&amp;T Alien Labs</a> &mdash; New stealthy malware targeting Linux </li><li><a title="LINUX Unplugged 474: Linux’s Malware Inevitability" rel="nofollow" href="https://linuxunplugged.com/474">LINUX Unplugged 474: Linux’s Malware Inevitability</a></li><li><a title="New Linux malware combines unusual stealth with a full suite of capabilities" rel="nofollow" href="https://arstechnica.com/information-technology/2022/09/new-linux-malware-combines-unusual-stealth-with-a-full-suite-of-capabilities/">New Linux malware combines unusual stealth with a full suite of capabilities</a> &mdash; "Threat actors continue to search for ways to deliver malware in new ways to stay under the radar and avoid detection," AT&amp;T Alien Labs researcher Ofer Caspi wrote.</li><li><a title="New Linux malware evades detection using multi-stage deployment" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/new-linux-malware-evades-detection-using-multi-stage-deployment/">New Linux malware evades detection using multi-stage deployment</a></li><li><a title="Shape-shifting cryptominer savaging Linux endpoints and IoT" rel="nofollow" href="https://www.theregister.com/2022/09/10/in_brief_security/">Shape-shifting cryptominer savaging Linux endpoints and IoT</a> &mdash; The malware was dubbed "Shikitega" for its extensive use of the popular Shikata Ga Nai polymorphic encoder, which allows the malware to "mutate" its code to avoid detection. Shikitega alters its code each time it runs through one of several decoding loops that AT&amp;T said each deliver multiple attacks, beginning with an ELF file that's just 370 bytes. </li><li><a title="Next-Gen Linux Malware Takes Over Devices With Unique Tool Set" rel="nofollow" href="https://www.darkreading.com/vulnerabilities-threats/next-gen-linux-malware-takes-over-devices-unique-toolset">Next-Gen Linux Malware Takes Over Devices With Unique Tool Set</a></li><li><a title="OpenWrt 22.03 Released With Updated Firewall, Support For 180+ New Devices - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/OpenWrt-22.03-Released">OpenWrt 22.03 Released With Updated Firewall, Support For 180+ New Devices - Phoronix</a></li><li><a title="[OpenWrt Wiki] OpenWrt 22.03.0 - First Stable Release - 6 September 2022" rel="nofollow" href="https://openwrt.org/releases/22.03/notes-22.03.0">[OpenWrt Wiki] OpenWrt 22.03.0 - First Stable Release - 6 September 2022</a></li><li><a title="Linux Foundation Announces Open Wallet Foundation" rel="nofollow" href="https://www.linuxfoundation.org/press/linux-foundation-announces-an-intent-to-form-the-openwallet-foundation">Linux Foundation Announces Open Wallet Foundation</a> &mdash; The Linux Foundation, a global nonprofit organization enabling innovation through open source, today announced the intention to form the OpenWallet Foundation (OWF), a new collaborative effort to develop open source software to support interoperability for a wide range of wallet use cases.</li><li><a title="Linux Foundation announces the OpenWallet Foundation to develop interoperable digital wallets" rel="nofollow" href="https://techcrunch.com/2022/09/13/linux-foundation-announces-the-openwallet-foundation-to-develop-interoperable-digital-wallets/">Linux Foundation announces the OpenWallet Foundation to develop interoperable digital wallets</a></li><li><a title="Welcoming PyTorch to the Linux Foundation" rel="nofollow" href="https://www.linuxfoundation.org/blog/blog/welcoming-pytorch-to-the-linux-foundation">Welcoming PyTorch to the Linux Foundation</a></li><li><a title="Facebook Transfers PyTorch AI Framework to Linux Foundation for Governance" rel="nofollow" href="https://debugpointnews.com/meta-pytorch-linux/">Facebook Transfers PyTorch AI Framework to Linux Foundation for Governance</a> &mdash; Today we are more than thrilled to welcome PyTorch to the Linux Foundation. Honestly, it’s hard to capture how big a deal this is for us in a single post but I’ll try. </li><li><a title="PyTorch strengthens its governance by joining the Linux Foundation" rel="nofollow" href="https://pytorch.org/blog/PyTorchfoundation/">PyTorch strengthens its governance by joining the Linux Foundation</a></li><li><a title="Google Pixelbook is no more, proving the world wasn’t ready for premium Chromebooks | TechRadar" rel="nofollow" href="https://www.techradar.com/news/google-pixelbook-is-no-more-proving-the-world-wasnt-ready-for-premium-chromebooks">Google Pixelbook is no more, proving the world wasn’t ready for premium Chromebooks | TechRadar</a></li><li><a title="Linux Plumbers Conference - YouTube" rel="nofollow" href="https://www.youtube.com/c/LinuxPlumbersConference/videos?app=desktop&amp;view=2&amp;flow=list&amp;live_view=501&amp;cbrd=1">Linux Plumbers Conference - YouTube</a></li><li><a title="LPC 2022: Rust Linux Drivers Capable Of Achieving Performance Comparable To C Code - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/LPC-2022-Rust-Linux">LPC 2022: Rust Linux Drivers Capable Of Achieving Performance Comparable To C Code - Phoronix</a></li><li><a title="IO_uring Continues To Prove Very Exciting: Promising io_uring_spawn Announced" rel="nofollow" href="https://www.phoronix.com/news/Linux-LPC2022-io_uring_spawn">IO_uring Continues To Prove Very Exciting: Promising io_uring_spawn Announced</a> &mdash; It also continues to be relentlessly optimized by Jens Axboe and others for maximum performance potential. The latest innovation around IO_uring that was announced this week at Linux Plumbers Conference 2022 in Dublin is io_uring_spawn.</li><li><a title="An io_uring-based user-space block driver" rel="nofollow" href="https://lwn.net/Articles/903855/">An io_uring-based user-space block driver</a></li><li><a title="A pair of Rust kernel modules" rel="nofollow" href="https://lwn.net/Articles/907685/">A pair of Rust kernel modules</a></li><li><a title="Compiling Rust with GCC: an update" rel="nofollow" href="https://lwn.net/Articles/907405/">Compiling Rust with GCC: an update</a></li><li><a title="Mesa’s Rust OpenCL Implementation Merged" rel="nofollow" href="https://www.phoronix.com/news/Mesa-Rust-OpenCL-Merging-Soon">Mesa’s Rust OpenCL Implementation Merged</a></li><li><a title="Adding rusticl (!15439) · Merge requests · Mesa / mesa · GitLab" rel="nofollow" href="https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/15439">Adding rusticl (!15439) · Merge requests · Mesa / mesa · GitLab</a></li><li><a title="LPC 2022 - Kernel Summit - Lansdowne - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=e2SZoUPhDRg">LPC 2022 - Kernel Summit - Lansdowne - YouTube</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The Linux Foundation takes a victory lap, Google kills another community-loved project, and key moments from the Linux Plumbers Conference.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide</a>: <a rel="nofollow" href="https://l.kolide.co/3klbWzr">Kolide can help you nail third-party audits and internal compliance goals with endpoint security for your entire fleet. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Shikitega -  AT&amp;T Alien Labs" rel="nofollow" href="https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux">Shikitega -  AT&amp;T Alien Labs</a> &mdash; New stealthy malware targeting Linux </li><li><a title="LINUX Unplugged 474: Linux’s Malware Inevitability" rel="nofollow" href="https://linuxunplugged.com/474">LINUX Unplugged 474: Linux’s Malware Inevitability</a></li><li><a title="New Linux malware combines unusual stealth with a full suite of capabilities" rel="nofollow" href="https://arstechnica.com/information-technology/2022/09/new-linux-malware-combines-unusual-stealth-with-a-full-suite-of-capabilities/">New Linux malware combines unusual stealth with a full suite of capabilities</a> &mdash; "Threat actors continue to search for ways to deliver malware in new ways to stay under the radar and avoid detection," AT&amp;T Alien Labs researcher Ofer Caspi wrote.</li><li><a title="New Linux malware evades detection using multi-stage deployment" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/new-linux-malware-evades-detection-using-multi-stage-deployment/">New Linux malware evades detection using multi-stage deployment</a></li><li><a title="Shape-shifting cryptominer savaging Linux endpoints and IoT" rel="nofollow" href="https://www.theregister.com/2022/09/10/in_brief_security/">Shape-shifting cryptominer savaging Linux endpoints and IoT</a> &mdash; The malware was dubbed "Shikitega" for its extensive use of the popular Shikata Ga Nai polymorphic encoder, which allows the malware to "mutate" its code to avoid detection. Shikitega alters its code each time it runs through one of several decoding loops that AT&amp;T said each deliver multiple attacks, beginning with an ELF file that's just 370 bytes. </li><li><a title="Next-Gen Linux Malware Takes Over Devices With Unique Tool Set" rel="nofollow" href="https://www.darkreading.com/vulnerabilities-threats/next-gen-linux-malware-takes-over-devices-unique-toolset">Next-Gen Linux Malware Takes Over Devices With Unique Tool Set</a></li><li><a title="OpenWrt 22.03 Released With Updated Firewall, Support For 180+ New Devices - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/OpenWrt-22.03-Released">OpenWrt 22.03 Released With Updated Firewall, Support For 180+ New Devices - Phoronix</a></li><li><a title="[OpenWrt Wiki] OpenWrt 22.03.0 - First Stable Release - 6 September 2022" rel="nofollow" href="https://openwrt.org/releases/22.03/notes-22.03.0">[OpenWrt Wiki] OpenWrt 22.03.0 - First Stable Release - 6 September 2022</a></li><li><a title="Linux Foundation Announces Open Wallet Foundation" rel="nofollow" href="https://www.linuxfoundation.org/press/linux-foundation-announces-an-intent-to-form-the-openwallet-foundation">Linux Foundation Announces Open Wallet Foundation</a> &mdash; The Linux Foundation, a global nonprofit organization enabling innovation through open source, today announced the intention to form the OpenWallet Foundation (OWF), a new collaborative effort to develop open source software to support interoperability for a wide range of wallet use cases.</li><li><a title="Linux Foundation announces the OpenWallet Foundation to develop interoperable digital wallets" rel="nofollow" href="https://techcrunch.com/2022/09/13/linux-foundation-announces-the-openwallet-foundation-to-develop-interoperable-digital-wallets/">Linux Foundation announces the OpenWallet Foundation to develop interoperable digital wallets</a></li><li><a title="Welcoming PyTorch to the Linux Foundation" rel="nofollow" href="https://www.linuxfoundation.org/blog/blog/welcoming-pytorch-to-the-linux-foundation">Welcoming PyTorch to the Linux Foundation</a></li><li><a title="Facebook Transfers PyTorch AI Framework to Linux Foundation for Governance" rel="nofollow" href="https://debugpointnews.com/meta-pytorch-linux/">Facebook Transfers PyTorch AI Framework to Linux Foundation for Governance</a> &mdash; Today we are more than thrilled to welcome PyTorch to the Linux Foundation. Honestly, it’s hard to capture how big a deal this is for us in a single post but I’ll try. </li><li><a title="PyTorch strengthens its governance by joining the Linux Foundation" rel="nofollow" href="https://pytorch.org/blog/PyTorchfoundation/">PyTorch strengthens its governance by joining the Linux Foundation</a></li><li><a title="Google Pixelbook is no more, proving the world wasn’t ready for premium Chromebooks | TechRadar" rel="nofollow" href="https://www.techradar.com/news/google-pixelbook-is-no-more-proving-the-world-wasnt-ready-for-premium-chromebooks">Google Pixelbook is no more, proving the world wasn’t ready for premium Chromebooks | TechRadar</a></li><li><a title="Linux Plumbers Conference - YouTube" rel="nofollow" href="https://www.youtube.com/c/LinuxPlumbersConference/videos?app=desktop&amp;view=2&amp;flow=list&amp;live_view=501&amp;cbrd=1">Linux Plumbers Conference - YouTube</a></li><li><a title="LPC 2022: Rust Linux Drivers Capable Of Achieving Performance Comparable To C Code - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/LPC-2022-Rust-Linux">LPC 2022: Rust Linux Drivers Capable Of Achieving Performance Comparable To C Code - Phoronix</a></li><li><a title="IO_uring Continues To Prove Very Exciting: Promising io_uring_spawn Announced" rel="nofollow" href="https://www.phoronix.com/news/Linux-LPC2022-io_uring_spawn">IO_uring Continues To Prove Very Exciting: Promising io_uring_spawn Announced</a> &mdash; It also continues to be relentlessly optimized by Jens Axboe and others for maximum performance potential. The latest innovation around IO_uring that was announced this week at Linux Plumbers Conference 2022 in Dublin is io_uring_spawn.</li><li><a title="An io_uring-based user-space block driver" rel="nofollow" href="https://lwn.net/Articles/903855/">An io_uring-based user-space block driver</a></li><li><a title="A pair of Rust kernel modules" rel="nofollow" href="https://lwn.net/Articles/907685/">A pair of Rust kernel modules</a></li><li><a title="Compiling Rust with GCC: an update" rel="nofollow" href="https://lwn.net/Articles/907405/">Compiling Rust with GCC: an update</a></li><li><a title="Mesa’s Rust OpenCL Implementation Merged" rel="nofollow" href="https://www.phoronix.com/news/Mesa-Rust-OpenCL-Merging-Soon">Mesa’s Rust OpenCL Implementation Merged</a></li><li><a title="Adding rusticl (!15439) · Merge requests · Mesa / mesa · GitLab" rel="nofollow" href="https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/15439">Adding rusticl (!15439) · Merge requests · Mesa / mesa · GitLab</a></li><li><a title="LPC 2022 - Kernel Summit - Lansdowne - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=e2SZoUPhDRg">LPC 2022 - Kernel Summit - Lansdowne - YouTube</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 219</title>
  <link>https://linuxactionnews.com/219</link>
  <guid isPermaLink="false">5d1dfafe-be8f-4fb6-b463-856095effbf2</guid>
  <pubDate>Sun, 12 Dec 2021 19:30:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/5d1dfafe-be8f-4fb6-b463-856095effbf2.mp3" length="12259392" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>The Log4Shell vulnerability is making waves this week; we'll explain why and break down how it works.</itunes:subtitle>
  <itunes:duration>17:01</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>&lt;p&gt;The Log4Shell vulnerability is making waves this week; we'll explain why and break down how it works. &lt;/p&gt;

&lt;p&gt;Plus, some good news for the Desktop and systemd-homed gets one step closer. &lt;/p&gt;
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, GNOME 42, Input Events, Refresh Rate, 144hz, GNOME Shell, FreeBSD 12.3, systemd 250, systemd-homed, UID mapped mounts, Log4Shell, log4j2, JNDI, Java Naming and Directory Interface,  Steam, Apple iCloud, Minecraft, Apache, Java, JVM, formatMsgNoLookups, Exploit, vulnerability, open source funding, Apache Struts</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The Log4Shell vulnerability is making waves this week; we&#39;ll explain why and break down how it works. </p>

<p>Plus, some good news for the Desktop and systemd-homed gets one step closer.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 42 To Finally Allow Input Events To Happen Full-Rate" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=GNOME-42-Input-Rate">GNOME 42 To Finally Allow Input Events To Happen Full-Rate</a> &mdash; Up to now GNOME Shell has been compressing pointer motion events so they are synchronized to the monitor refresh rate, which can be anywhere from around 30 to 144 events per second depending upon display.</li><li><a title="An Eventful Instant – GNOME Shell &amp; Mutter" rel="nofollow" href="https://blogs.gnome.org/shell-dev/2021/12/08/an-eventful-instant/">An Eventful Instant – GNOME Shell &amp; Mutter</a></li><li><a title="Do not throttle input in wayland event delivery" rel="nofollow" href="https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1915/diffs">Do not throttle input in wayland event delivery</a></li><li><a title="FreeBSD 12.3-RELEASE Announcement" rel="nofollow" href="https://www.freebsd.org/releases/12.3R/announce/">FreeBSD 12.3-RELEASE Announcement</a> &mdash; The FreeBSD Release Engineering Team is pleased to announce the availability of FreeBSD 12.3-RELEASE. This is the fourth release of the stable/12 branch.</li><li><a title="systemd 250 Is Coming With A Boat Load Of New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=systemd-250-RC">systemd 250 Is Coming With A Boat Load Of New Features</a> &mdash; systemd 250 is packing a rather large number of new features and changes across the board for this dominant Linux init system and service manager.</li><li><a title="Log4Shell" rel="nofollow" href="https://www.lunasec.io/docs/blog/log4j-zero-day/">Log4Shell</a> &mdash; RCE 0-day exploit found in log4j2, a popular Java logging package</li><li><a title="Apache - The ASF on Twitter" rel="nofollow" href="https://twitter.com/TheASF/status/1400875147163279374">Apache - The ASF on Twitter</a> &mdash; “Did you know that Ingenuity, the Mars 2020 Helicopter mission, is powered by Apache Log4j? https://t.co/gV0uyE1ylk #Apache #OpenSource #innovation #community #logging #services</li><li><a title="Tom (^-^) on Twitter" rel="nofollow" href="https://twitter.com/tomlawrencetech/status/1469647697380622342?s=12">Tom (^-^) on Twitter</a></li><li><a title="Kevin Beaumont on Twitter" rel="nofollow" href="https://twitter.com/GossiTheDog/status/1469248250670727169">Kevin Beaumont on Twitter</a> &mdash; “Starting a new thread for log4j security vulnerability and fallout. Spoiler: although this emerged as a Minecraft issue (lol) there is going to be impacts across a wide range of enterprise software for some time.”</li><li><a title="Log4jAttackSurface MEMES" rel="nofollow" href="https://github.com/YfryTchsGD/Log4jAttackSurface/blob/master/pages/MEME.md">Log4jAttackSurface MEMES</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The Log4Shell vulnerability is making waves this week; we&#39;ll explain why and break down how it works. </p>

<p>Plus, some good news for the Desktop and systemd-homed gets one step closer.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://linux.ting.com">Ting</a>: <a rel="nofollow" href="https://linux.ting.com">Save $25 off your first device, or $25 in service credit if you bring one!</a></li><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li><li><a rel="nofollow" href="http://jupiter.party">Jupiter Network Membership</a>: <a rel="nofollow" href="http://jupiter.party">Support the entire network, and get access to every member's special feed for every show on the network.</a> Promo Code: thesignal</li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="GNOME 42 To Finally Allow Input Events To Happen Full-Rate" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=GNOME-42-Input-Rate">GNOME 42 To Finally Allow Input Events To Happen Full-Rate</a> &mdash; Up to now GNOME Shell has been compressing pointer motion events so they are synchronized to the monitor refresh rate, which can be anywhere from around 30 to 144 events per second depending upon display.</li><li><a title="An Eventful Instant – GNOME Shell &amp; Mutter" rel="nofollow" href="https://blogs.gnome.org/shell-dev/2021/12/08/an-eventful-instant/">An Eventful Instant – GNOME Shell &amp; Mutter</a></li><li><a title="Do not throttle input in wayland event delivery" rel="nofollow" href="https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1915/diffs">Do not throttle input in wayland event delivery</a></li><li><a title="FreeBSD 12.3-RELEASE Announcement" rel="nofollow" href="https://www.freebsd.org/releases/12.3R/announce/">FreeBSD 12.3-RELEASE Announcement</a> &mdash; The FreeBSD Release Engineering Team is pleased to announce the availability of FreeBSD 12.3-RELEASE. This is the fourth release of the stable/12 branch.</li><li><a title="systemd 250 Is Coming With A Boat Load Of New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=systemd-250-RC">systemd 250 Is Coming With A Boat Load Of New Features</a> &mdash; systemd 250 is packing a rather large number of new features and changes across the board for this dominant Linux init system and service manager.</li><li><a title="Log4Shell" rel="nofollow" href="https://www.lunasec.io/docs/blog/log4j-zero-day/">Log4Shell</a> &mdash; RCE 0-day exploit found in log4j2, a popular Java logging package</li><li><a title="Apache - The ASF on Twitter" rel="nofollow" href="https://twitter.com/TheASF/status/1400875147163279374">Apache - The ASF on Twitter</a> &mdash; “Did you know that Ingenuity, the Mars 2020 Helicopter mission, is powered by Apache Log4j? https://t.co/gV0uyE1ylk #Apache #OpenSource #innovation #community #logging #services</li><li><a title="Tom (^-^) on Twitter" rel="nofollow" href="https://twitter.com/tomlawrencetech/status/1469647697380622342?s=12">Tom (^-^) on Twitter</a></li><li><a title="Kevin Beaumont on Twitter" rel="nofollow" href="https://twitter.com/GossiTheDog/status/1469248250670727169">Kevin Beaumont on Twitter</a> &mdash; “Starting a new thread for log4j security vulnerability and fallout. Spoiler: although this emerged as a Minecraft issue (lol) there is going to be impacts across a wide range of enterprise software for some time.”</li><li><a title="Log4jAttackSurface MEMES" rel="nofollow" href="https://github.com/YfryTchsGD/Log4jAttackSurface/blob/master/pages/MEME.md">Log4jAttackSurface MEMES</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Linux Action News 174</title>
  <link>https://linuxactionnews.com/174</link>
  <guid isPermaLink="false">5d0d1622-0de4-41b3-a017-5ace4c96156d</guid>
  <pubDate>Sun, 31 Jan 2021 15:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/dec90738-e640-45e5-b375-4573052f4bf4/5d0d1622-0de4-41b3-a017-5ace4c96156d.mp3" length="15053345" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Google removes Matrix chat-client Element from the Play store, sudo has a major flaw with a long-tail, and Rocky Linux gets a boost.</itunes:subtitle>
  <itunes:duration>20:54</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/d/dec90738-e640-45e5-b375-4573052f4bf4/cover.jpg?v=6"/>
  <description>&lt;p&gt;Google removes Matrix chat-client Element from the Play store, sudo has a major flaw with a long-tail, and Rocky Linux gets a boost. &lt;/p&gt;
</description>
  <itunes:keywords>Linux News Podcast, Linux Action News, Matrix, Element, federated chat, Play Store, App Store, Telegram, Robinhood, wallstreetbets, GameStop, Google, sudo, security, vulnerability, CVE-2021-3156, Baron Samedit, root, software bug, Qualys, Debian, Ubuntu, Fedora, bleepingcomputer, Rocky Linux, CentOS, Gregory Kurtzer, Ctrl IQ, CloudLinux, AlmaLinux, HPC, Jim Salter, Ars Technica, AWS, Mattermost, The Register, Red Hat, AlmaLinux, Brian Exelbierd, Greg Kroah-Hartman, Linux 5.10, Broadcam, Scott Branden, LTS, Samsung,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Google removes Matrix chat-client Element from the Play store, sudo has a major flaw with a long-tail, and Rocky Linux gets a boost.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Element suspended on Google Play Store" rel="nofollow" href="https://element.io/blog/element-on-google-play-store/">Element suspended on Google Play Store</a> &mdash; At 2021-01-29 at 21:35 UTC Google suspended Element from the Play Store without warning or notification</li><li><a title="Element sees fivefold increase in signups after Whatsapp privacy debacle" rel="nofollow" href="https://sifted.eu/articles/element-whatsapp-exodus/">Element sees fivefold increase in signups after Whatsapp privacy debacle</a> &mdash; After Whatsapp’s announcement, rival app Telegram reported a 500% increase in users and Signal saw an 18-fold increase in download numbers, putting it on track to cross 1m new users each day. </li><li><a title="Element team waiting hours" rel="nofollow" href="https://twitter.com/element_hq/status/1355595359582638080">Element team waiting hours</a> &mdash; Update: we’re still waiting for a response from Google to our explanatory mail sent ~8 hours ago. Thanks all for your patience while we get this sorted...</li><li><a title="New Linux SUDO flaw lets local users gain root privileges" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/new-linux-sudo-flaw-lets-local-users-gain-root-privileges/">New Linux SUDO flaw lets local users gain root privileges</a> &mdash; The issue is a heap-based buffer overflow exploitable by any local user (normal users and system users, listed in the sudoers file or not), with attackers not being required to know the user's password to successfully exploit the flaw. The vulnerability was introduced in the Sudo program almost 9 years ago, in July 2011.</li><li><a title="10-year-old Sudo bug lets Linux users gain root-level access" rel="nofollow" href="https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/">10-year-old Sudo bug lets Linux users gain root-level access</a></li><li><a title="Buffer overflow in command line unescaping" rel="nofollow" href="https://www.sudo.ws/alerts/unescape_overflow.html">Buffer overflow in command line unescaping</a></li><li><a title="Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156) - Help Net Security" rel="nofollow" href="https://www.helpnetsecurity.com/2021/01/27/cve-2021-3156/">Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156) - Help Net Security</a> &mdash; "This vulnerability is perhaps the most significant sudo vulnerability in recent memory (both in terms of scope and impact) and has been hiding in plain sight for nearly 10 years."
</li><li><a title="New Linux Kernel Vulnerabilities Patched in All Supported Ubuntu Releases" rel="nofollow" href="https://9to5linux.com/new-linux-kernel-vulnerabilities-patched-in-all-supported-ubuntu-releases">New Linux Kernel Vulnerabilities Patched in All Supported Ubuntu Releases</a></li><li><a title="Mitre - CVE-2020-28374" rel="nofollow" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28374">Mitre - CVE-2020-28374</a></li><li><a title="Red Hat Customer Portal: CVE-2020-28374" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2020-28374">Red Hat Customer Portal: CVE-2020-28374</a></li><li><a title="Debian: CVE-2020-28374" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2020-28374">Debian: CVE-2020-28374</a></li><li><a title=" Ubuntu: CVE-2020-28374" rel="nofollow" href="https://ubuntu.com/security/CVE-2020-28374"> Ubuntu: CVE-2020-28374</a></li><li><a title="The killing of CentOS Linux: ‘The CentOS board doesn’t get to decide what Red Hat engineering teams do’" rel="nofollow" href="https://www.theregister.com/2021/01/26/killing_centos/">The killing of CentOS Linux: ‘The CentOS board doesn’t get to decide what Red Hat engineering teams do’</a> &mdash; Brian Exelbierd, responsible for Red Hat liaison with the CentOS project and a board member of that project, has told The Register that CentOS Linux is ending because Red Hat simply refused to invest in it.

</li><li><a title="Rocky Linux gets a new sponsor—Gregory Kurtzer’s startup, Ctrl IQ" rel="nofollow" href="https://arstechnica.com/gadgets/2021/01/rocky-linux-gets-a-parent-company-with-4m-series-a-funding/">Rocky Linux gets a new sponsor—Gregory Kurtzer’s startup, Ctrl IQ</a> &mdash; Rocky Linux is to be a beneficiary of Ctrl IQ's revenue, not its source—the company describes itself in its announcement as the suppliers of a "full technology stack integrating key capabilities of enterprise, hyper-scale, cloud and high-performance computing."</li><li><a title="Linux maintainer says long-term support for 5.10 will stay at two years unless biz world steps up and actually uses it" rel="nofollow" href="https://www.theregister.com/2021/01/28/long_term_support_for_linux_510/">Linux maintainer says long-term support for 5.10 will stay at two years unless biz world steps up and actually uses it</a> &mdash; Linux kernel maintainer Greg Kroah-Hartman has responded to complaints that the current promise of two years for 5.10 is not enough, explaining that support is not automatic but requires commercial help.
</li><li><a title="Rust Game Server One-Click App Linode" rel="nofollow" href="https://www.linode.com/marketplace/apps/linode/rust-game-server/">Rust Game Server One-Click App Linode</a> &mdash; A free-for-all battle in a harsh open-world environment.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Google removes Matrix chat-client Element from the Play store, sudo has a major flaw with a long-tail, and Rocky Linux gets a boost.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://linode.com/lan">Linode</a>: <a rel="nofollow" href="http://linode.com/lan">Sign up using the link on this page and receive a $100 60-day credit towards your new account. </a></li></ul><p><a rel="payment" href="https://www.jupiter.party/">Support Linux Action News</a></p><p>Links:</p><ul><li><a title="Element suspended on Google Play Store" rel="nofollow" href="https://element.io/blog/element-on-google-play-store/">Element suspended on Google Play Store</a> &mdash; At 2021-01-29 at 21:35 UTC Google suspended Element from the Play Store without warning or notification</li><li><a title="Element sees fivefold increase in signups after Whatsapp privacy debacle" rel="nofollow" href="https://sifted.eu/articles/element-whatsapp-exodus/">Element sees fivefold increase in signups after Whatsapp privacy debacle</a> &mdash; After Whatsapp’s announcement, rival app Telegram reported a 500% increase in users and Signal saw an 18-fold increase in download numbers, putting it on track to cross 1m new users each day. </li><li><a title="Element team waiting hours" rel="nofollow" href="https://twitter.com/element_hq/status/1355595359582638080">Element team waiting hours</a> &mdash; Update: we’re still waiting for a response from Google to our explanatory mail sent ~8 hours ago. Thanks all for your patience while we get this sorted...</li><li><a title="New Linux SUDO flaw lets local users gain root privileges" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/new-linux-sudo-flaw-lets-local-users-gain-root-privileges/">New Linux SUDO flaw lets local users gain root privileges</a> &mdash; The issue is a heap-based buffer overflow exploitable by any local user (normal users and system users, listed in the sudoers file or not), with attackers not being required to know the user's password to successfully exploit the flaw. The vulnerability was introduced in the Sudo program almost 9 years ago, in July 2011.</li><li><a title="10-year-old Sudo bug lets Linux users gain root-level access" rel="nofollow" href="https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/">10-year-old Sudo bug lets Linux users gain root-level access</a></li><li><a title="Buffer overflow in command line unescaping" rel="nofollow" href="https://www.sudo.ws/alerts/unescape_overflow.html">Buffer overflow in command line unescaping</a></li><li><a title="Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156) - Help Net Security" rel="nofollow" href="https://www.helpnetsecurity.com/2021/01/27/cve-2021-3156/">Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156) - Help Net Security</a> &mdash; "This vulnerability is perhaps the most significant sudo vulnerability in recent memory (both in terms of scope and impact) and has been hiding in plain sight for nearly 10 years."
</li><li><a title="New Linux Kernel Vulnerabilities Patched in All Supported Ubuntu Releases" rel="nofollow" href="https://9to5linux.com/new-linux-kernel-vulnerabilities-patched-in-all-supported-ubuntu-releases">New Linux Kernel Vulnerabilities Patched in All Supported Ubuntu Releases</a></li><li><a title="Mitre - CVE-2020-28374" rel="nofollow" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28374">Mitre - CVE-2020-28374</a></li><li><a title="Red Hat Customer Portal: CVE-2020-28374" rel="nofollow" href="https://access.redhat.com/security/cve/cve-2020-28374">Red Hat Customer Portal: CVE-2020-28374</a></li><li><a title="Debian: CVE-2020-28374" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2020-28374">Debian: CVE-2020-28374</a></li><li><a title=" Ubuntu: CVE-2020-28374" rel="nofollow" href="https://ubuntu.com/security/CVE-2020-28374"> Ubuntu: CVE-2020-28374</a></li><li><a title="The killing of CentOS Linux: ‘The CentOS board doesn’t get to decide what Red Hat engineering teams do’" rel="nofollow" href="https://www.theregister.com/2021/01/26/killing_centos/">The killing of CentOS Linux: ‘The CentOS board doesn’t get to decide what Red Hat engineering teams do’</a> &mdash; Brian Exelbierd, responsible for Red Hat liaison with the CentOS project and a board member of that project, has told The Register that CentOS Linux is ending because Red Hat simply refused to invest in it.

</li><li><a title="Rocky Linux gets a new sponsor—Gregory Kurtzer’s startup, Ctrl IQ" rel="nofollow" href="https://arstechnica.com/gadgets/2021/01/rocky-linux-gets-a-parent-company-with-4m-series-a-funding/">Rocky Linux gets a new sponsor—Gregory Kurtzer’s startup, Ctrl IQ</a> &mdash; Rocky Linux is to be a beneficiary of Ctrl IQ's revenue, not its source—the company describes itself in its announcement as the suppliers of a "full technology stack integrating key capabilities of enterprise, hyper-scale, cloud and high-performance computing."</li><li><a title="Linux maintainer says long-term support for 5.10 will stay at two years unless biz world steps up and actually uses it" rel="nofollow" href="https://www.theregister.com/2021/01/28/long_term_support_for_linux_510/">Linux maintainer says long-term support for 5.10 will stay at two years unless biz world steps up and actually uses it</a> &mdash; Linux kernel maintainer Greg Kroah-Hartman has responded to complaints that the current promise of two years for 5.10 is not enough, explaining that support is not automatic but requires commercial help.
</li><li><a title="Rust Game Server One-Click App Linode" rel="nofollow" href="https://www.linode.com/marketplace/apps/linode/rust-game-server/">Rust Game Server One-Click App Linode</a> &mdash; A free-for-all battle in a harsh open-world environment.</li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
