Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) https://lobste.rs/s/nwdn3w #linux #security
https://cdn2.qualys.com/advisory/2026/05/20/cve-2026-46333-ptrace.txt
linux
It's been a while since I posted here, and at this point all of my previous posts have auto-deleted. Might as well reintroduce myself.
I am Gabriel, and I am based in Costa Rica. I work as an independent software developer and systems administrator.
As of late, my computer interests lie in #selfhosting, #Linux, and #containers. I care a lot about #privacy and ownership of our data and devices.
I am also passionate about #permaculture, #reading, #cycling, #fermentation, and #synthesizers.
inxi (1) - Command line system information script for console and IRC
I am a human, but my little bot posts a random Linux command daily. If you don't want to see it you can mute the LinuxLexiconBot hashtag.
Happy hacking!
linux32 (1) - change reported architecture in new program environment and set personality flags
I am a human, but my little bot posts a random Linux command daily. If you don't want to see it you can mute the LinuxLexiconBot hashtag.
Happy hacking!
Dirty Frag: Universal Linux LPE via @lattera https://lobste.rs/s/lu4efg #linux #security
https://www.openwall.com/lists/oss-security/2026/05/07/8
#Linux kernel exploit mitigation:
rm -rf /boot /lib/modules && reboot
Will mitigate all exploits, not just #DirtyFrag 🧐☝️
termcap. Fascinating how much modern terminal software still
inherits ideas from this era.
vi depended heavily on terminal capability databases to remain
portable across different hardware terminals. Bill Joy originally
wired vi only for Lear Siegler ADM-3A terminals, and termcap was
born from the flood of requests for support on other hardware.
"Termcap Unveiled" by Douglas R. Merritt, pages 42-48.
https://archive.org/details/Unix_Review_1984_Sep.pdf/page/n43/mode/2up
Also updated my nvi notes with a small historical section about
termcap/curses and terminal portability.
https://repo.or.cz/code-notes.git/blob_plain/HEAD:/notes/NVI_Editor_Guide.txt
#vi #unix #termcap #nvi #linux
You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE) https://lobste.rs/s/0vmsbe #linux #security
https://ze3tar.github.io/post-zcrx.html
My Accessibility Stack and the future on Wayland https://lobste.rs/s/giktao #a11y #linux
https://nocoffei.com/?p=451
grub-file (1) - check file type
I am a human, but my little bot posts a random Linux command daily. If you don't want to see it you can mute the LinuxLexiconBot hashtag.
Happy hacking!
Releasing a universal #Linux #kernel #exploit with very little or even no previous time to distribute a patch through distributions is not cool. Doing it on the day before a weekend - on two weekends in a row - is just being an asshole. Looking at you, #CopyFail and #DirtyFrag.
You may think it helps your PR, that people will queue to use your cool new AI/agentic/whatever tool because you found the bug. You may think that releasing the full exploit because somebody else was even quicker with "leaking" your cool find makes it right. You're wrong. This is neither responsible nor coordinated disclosure. In security, we've tried to learn the hard lessons on keeping in-production, live systems on a global scale safer.
Yes, those bugs have existed for a long time in the kernel source. Yes, other bad actors may already have found them. But you're shining a light on it *and* giving every script kiddie in the world a working exploit to point their mass scans at. That's dangerous. There's a reason why the normal process is to reach out at least to the most widely installed distributions before releasing the bug details publicly. There's a reason why 90 days is a good default - it allows downstream percolation of patches. You can still get the credit. This way, you only create stress for admins.
[For a little relief, refer to https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken for a quick mitigation, because updating kernels and rebooting a fleet of hosts just takes time, weekend or not. #HugOps]
Help us test @Podman_io 6.0! Test Days will be from May 11-15. This release will bring modern networking, simplified architecture, and a cleaner configuration. :)
How to participate: https://communityblog.fedoraproject.org/join-us-for-podman-6-0-test-days-may-11-15-2026/
Piping terminal output to the browser using systemfd https://lobste.rs/s/pdhf7w #browsers #linux #practices #web
https://blog.izissise.net/posts/webdev-livecompile/
SN Operator from Epilogue brings SNES carts to modern PCs and its now up for order https://www.gamingonlinux.com/2026/05/sn-operator-from-epilogue-brings-snes-carts-to-modern-pcs-and-its-now-up-for-order/
Eine Nachlese zum #Linux-Treff Nord am 07.05. Dieser war mit in der Summe 26 Personen, davon 4 neue Gäste gut besucht.
Vielen Dank dafür.
Es gab u.a :
- Hardwarespende Werkzeug, vielen Dank dafür,
- Beantwortung Anwenderfragen,
- #lpd am 16.05. beim Theo,
- Review Besuch Augsburger Linuxtag.
War wieder ein interessanter Abend.
Das nächste Treffen findet wieder virtuell am 14.05.2026 statt.
Wer teilnehmen möchte, einfach eine Mail an kontakt@lug-noris.de schreiben.
Am 07.05. findet der Linux-Treff Nord beim Theo in der Schnepfenreuther Hauptstraße 19 statt.
Hier gibt es ab 18:00 Uhr gutes Essen und dann ab ca. 19:30 Uhr geht es mit #Linux und freier Software weiter.
Es steht u.a. folgendes an:
- Bericht Augsburger Linuxtag,
- wir installieren Linux, gerade auch auf alte Rechner,
- #endof10,
- #lpd,
- und wer sonst noch etwas mitbringt.
Wieder im großen Saal.
Wenn Dich freie Software und Linux interessiert komm doch vorbei.
#ltn #nürnberg #lug
Linux and open source getting age checking exemptions could be problematic https://www.gamingonlinux.com/2026/05/linux-and-open-source-getting-age-checking-exemptions-could-be-problematic/
Changes/UseKmsconVTConsole https://lobste.rs/s/8n2pnd #graphics #linux
https://fedoraproject.org/wiki/Changes/UseKmsconVTConsole
Linux Compromises, Broken Embargoes, and the Shrinking Patch Window https://lobste.rs/s/mithjg #linux
https://www.askbaize.com/blog/linux-compromises-broken-embargoes-and-the-shrinking-patch-window
Fedora’s AI Developer Desktop proposal is now blocked after two Council members reversed their initial approvals.
https://linuxiac.com/fedora-ai-desktop-initiative-blocked-after-council-vote-reversal/
Habe ich mal erwähnt, dass ich die Entscheidung meinen Router zu virtualisieren in einem Mini-PC extrem abfeiere?
Das System läuft jetzt seit gut 1,5 Jahren extrem zuverlässig, lässt sich per Snapshot sichern, ist extrem flexibel konfigurier- und erweiterbar…
Und wenn i h die Hardware wechseln will brauche ich auch nur die virtuelle Machine zu übertragen und behalte alle Konfigurationen…
#OpenWRT #Proxmox #Linux #Router
Kavic Marabush's Pocket Guide to Computers
#unix_surrealism #magnetic_nymph #comic #computers #linux #runbsd #foss #programming
Happy International Day for Biological Diversity! 🌱
A diverse ecosystem is a strong ecosystem. In the tech world, NetBSD brings vital diversity by proving that clean, portable, and secure code can run on virtually any architecture. This adaptability keeps computing open and accessible to everyone.
Let's keep the digital ecosystem diverse. Consider supporting the NetBSD Foundation today by contributing code, writing documentation, or making a donation! 💻🚩
#NetBSD #BiodiversityDay #OpenSource #TechDiversity #FOSS #RetroComputing #Sustainability #Linux #RunBSD #FreeBSD #OpenBSD
grep/find/sed/awk/make/ssh/git/nvi often compose better than many modern “integrated” environments.
Small programs connected together still scale surprisingly well.
https://repo.or.cz/code-notes.git/blob_plain/HEAD:/notes/Unix_As_An_IDE.txt
#unix #linux #slackware #vi
🇺🇦
