Linux
2.16K subscribers
4K photos
20 videos
17.1K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
Zapscape - уязвимость в гипервизоре KVM, позволяющая получить root-доступ к хост-системе

Раскрыта информация об уязвимости (CVE-2026-64561) в гипервизоре KVM, позволяющей получить доступ с правами root к хост-окружению при наличии доступа с правами root в гостевой системе. Проблема также может применяться для локального повышения своих привилегий при наличии доступа к устройству /dev/kvm (например, в RHEL подобный доступ предоставляется всем пользователям). Для загрузки доступен прототип экспоита. Проблеме присвоено кодовое имя Zapscape.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66044
TONTOU - атака на CPU Intel и AMD, позволяющая обойти защиту от уязвимостей Spectre v2

Исследователи из массачусетского технологического института выявили технику атаки TONTOU (Time-of-Neutralization to Time-of-Use), предлагающую новый способ эксплуатации микроархитектурных уязвимостей класса Spectre v2. Уязвимость даёт возможность определить содержимое памяти ядра при выполнении эксплоита в пространстве пользователя. Код для блокирования эксплуатации уязвимости принят в состав ядра Linux 5 августа и включён в состав выпусков 7.1.7, 6.18.43, 6.18.43, 6.12.102, 6.6.149, 6.1.181, 5.15.214 и 5.10.263.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66045
20 Linux Networking Interview Questions and Answers for 2026

The post 20 Linux Networking Interview Questions and Answers for 2026 first appeared on Tecmint: Linux Howtos, Tutorials & Guides .You’ve probably memorized networking definitions like “What is DNS?” or “What is a subnet?” for interviews. But real interviews often
The post 20 Linux Networking Interview Questions and Answers for 2026 first appeared on Tecmint: Linux Howtos, Tutorials & Guides.

👉@sysadminoff

https://www.tecmint.com/networking-interview-questions/
📰 HWall Is a Promising New Hardware Monitor Built Specifically for Linux

HWall is a new Rust-based Linux hardware monitor with detailed system information, live sensors, charts, alerts, and GTK and terminal interfaces.

🔗 Source:

#linux

👉@sysadminoff

https://linuxiac.com/hwall-is-a-promising-new-hardware-monitor-built-specifically-for-linux/
В freenginx и nginx добавили проверку размера текстовой переменной перед тем как записывать в неё данные (+ CVE)

TL;DR: Столкнувшись с третьим обнаруженным за 2026 год переполнением буфера (и, по версии F5, RCE если нет ASLR) при работе с регэкспами и переменными, разработчик freenginx Максим Дунин решил, что пора это прекращать, и добавил в свой продукт проверку размера переменной перед тем как записывать в неё данные. Оттуда это нововведение утащили к себе и nginx, что даёт надежду на прекращение новых CVE на эту тему.Теперь подробности.( читать дальше... )Уязвимость появилась в версии nginx 0.9.6, исправления попали в версии freenginx 1.31.3, nginx 1.30.4, nginx 1.31.3.( читать дальше... )



 buffer overflow, freenginx, nginx, уязвимость

👉@sysadminoff

https://www.linux.org.ru/news/security/18354205
NatJack finds every tested NAT implementation vulnerable to attack

NatJack research presented at Black Hat USA 2026 found exploitable behavior in all 32 tested NAT products and configurations, spanning Windows, Linux, and macOS. The attack class can hijack active connections, poison DNS responses, or disable connectivity without requiring IP spoofing or Layer 2 access.
Source

👉@sysadminoff

https://4sysops.com/archives/natjack-finds-every-tested-nat-implementation-vulnerable-to-attack/
📰 Proxmox VE Officially Expands Beyond x86 With Arm64 Support

Proxmox VE gains its first official Arm64 edition, bringing KVM, LXC, ZFS, Ceph, clustering, and enterprise support to Arm servers.

🔗 Source:

#arm

👉@sysadminoff

https://linuxiac.com/proxmox-ve-officially-expands-beyond-x86-with-arm64-support/
ByteDance is training a 10 trillion-parameter AI model, the largest ever built

ByteDance, the Chinese tech company behind TikTok and other content platforms, is developing a potential AI model with 10 trillion parameters, making it roughly 2 trillion parameters larger than Anthropic's Mythos, according to sources familiar with the project.
Source

👉@sysadminoff

https://4sysops.com/archives/bytedance-is-training-a-10-trillion-parameter-ai-model-the-largest-ever-built/
📰 Zapscape Is The Latest Linux Vulnerability For KVM Guest-To-Host Escape, LPE

Made public earlier today is Zapscape as a guest-to-host escape vulnerability affecting the Linux KVM x86 code for the past six years. This 2020 kernel change to KVM x86 can also be used as a local privilege escalation (LPE) exploit too where /dev/kvm is world-writable on some Linux distributions like RHEL...

🔗 Source:

#kernel #linux

👉@sysadminoff

https://www.phoronix.com/news/Linux-Zapscape-Vulnerability
📰 Calibre 9.13 E-Book Manager Improves PDF Output, Content Server, and More

Calibre 9.13 open-source ebook manager is now available for download as a bugfix release that addresses various regressions introduced in the previous release and other issues.

🔗 Source: https://9to5linux.com/calibre-9-13-e-book-manager-improves-pdf-output-content-server-and-more

#opensource

👉@sysadminoff
📰 AMD Updates HDMI 2.1 VRR & ALLM Patches But Will Miss Out On Linux 7.3

Complementing the HDMI 2.1 Fixed Rate Link (FRL) support that AMD already upstreamed to the Linux kernel, AMD engineers have been further ironing out their HDMI 2.1 implementation for the open-source AMDGPU Linux kernel driver. The latest quest has been getting HDMI 2.1 variable rate refresh (VRR) support upstreamed along with HDMI Auto Low-Latency Mode (ALLM)...

🔗 Source:

#amd #kernel #linux #opensource

👉@sysadminoff

https://www.phoronix.com/news/AMD-HDMI-VRR-ALLM-v2
Calibre 9.13 fixes ebook search that wasn’t working in the content server

A new bug-fix release of Calibre, the open-source e-book manger, view and converter, is available for download. Calibre 9.13 resolves a number of PDF-related issues, including one for Linux distributions that ship an ‘ancient’ version of the libxml2 library. To avoid errors that could cause when converting PDFs on Linux, Calibre now preloads its html5-parser library. A comment in the file explains: “QtWebEngineProcess on some ancient Linux systems probes for GPU backends which loads swrast_dri.so which links against system libxml2, which overwrites or global libxml2 symbols. So we preload lxml and html5_parser as a workaround. Thankfully this is basically only […]
You're reading Calibre 9.13 fixes ebook search that wasn’t working in the content server, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

👉@sysadminoff

https://www.omgubuntu.co.uk/2026/08/calibre-9-13-bug-fix-update
Claude Opus 5 wipes a Windows profile after mistaking `/c/Users` for a backup path

A Claude Opus 5 session reportedly erased an entire Windows user profile after misreading a Unix-style `/c/Users/...` path and issuing `rm -rf` against it. The incident highlights how quickly an AI coding agent can turn a routine backup task into irreversible data loss when it has unrestricted filesystem access.
Source

👉@sysadminoff

https://4sysops.com/archives/claude-opus-5-wipes-a-windows-profile-after-mistaking-c-users-for-a-backup-path/
Microsoft finds another way to push Copilot into Outlook

Microsoft is adding a “Wrap up your day” prompt to New Outlook that launches Copilot without requiring users to start a chat. The feature scans recent email activity, produces an evening briefing, and suggests priorities for the next day—while offering no dedicated switch to disable the prompt.
Source

👉@sysadminoff

https://4sysops.com/archives/microsoft-finds-another-way-to-push-copilot-into-outlook/
Nearly three-quarters of European businesses now rate a potential US tech “kill switch” as a major threat

Nearly three-quarters of European businesses now rate a potential US tech “kill switch” as a threat comparable to ransomware. A Proton survey also found that 54.5% could operate for no more than one day without US cloud and digital services, while many are seeking sovereign alternatives for email and cloud storage.
Source

👉@sysadminoff

https://4sysops.com/archives/nearly-three-quarters-of-european-businesses-now-rate-a-potential-us-tech-kill-switch-as-a-major-threat/
📰 Intel Makes Progress On HDMI 2.1 FRL With Their Linux Driver For Meteor Lake & Newer

Following AMD making progress with HDMI Fixed Rate Link (FRL) and other HDMI 2.1 functionality for their open-source Linux kernel graphics driver, Intel is out today with a big set of 44 patches working on HDMI 2.1 FRL support for their kernel graphics driver with Meteor Lake hardware and newer...

🔗 Source:

#amd #intel #kernel #linux #opensource

👉@sysadminoff

https://www.phoronix.com/news/Intel-HDMI-2.1-FRL-Linux-2026
Windscribe’s deGDID script blocks Windows tracking—but can break Microsoft services

Windscribe has released deGDID, a free, open-source PowerShell script that removes Microsoft’s Global Device Identifier (GDID) from Windows and blocks the system from creating it again. The privacy tradeoff is significant: the protection can disrupt Xbox, Outlook, Microsoft Store, and other Microsoft-connected services.
Source

👉@sysadminoff

https://4sysops.com/archives/windscribes-degdid-script-blocks-windows-tracking-but-can-break-microsoft-services/
Use AI to analyze Windows performance traces (`.etl`) with ETW MCP and WPA MCP

When a PC is slow, hangs, or feels laggy, Windows can record a detailed performance trace while the problem occurs. A performance trace is a separate binary file (.etl) that captures fine-grained timing data about CPU, disk, memory, waits, and similar activity. Microsoft's early-preview tools ETW MCP and WPA MCP let an AI assistant ask questions about that .etl file in plain language, so you spend less time hunting through unfamiliar charts and tables.
Source

👉@sysadminoff

https://4sysops.com/archives/use-ai-to-analyze-windows-performance-traces-etl-with-etw-mcp-and-wpa-mcp/
Microsoft Edge sets 2026 deadline for killing uBlock Origin and other MV2 extensions

Microsoft Edge will begin disabling Manifest V2 extensions this month, putting uBlock Origin users on notice that the browser’s full phase-out is now scheduled for the end of 2026. Enterprise-managed devices get a longer runway, with Microsoft delaying their transition until early 2027.
Source

👉@sysadminoff

https://4sysops.com/archives/microsoft-edge-sets-2026-deadline-for-killing-ublock-origin-and-other-mv2-extensions/
OpenAI pauses Astra work as critical cyber risk remains unresolved

OpenAI says it is pausing internal Astra activities that do not meet strengthened security requirements after evaluations showed the upcoming model may possess “Critical” cyber capabilities. The company has expanded testing and introduced tighter controls while it continues assessing whether Astra can autonomously develop zero-day exploits or execute novel attacks against hardened real-world systems.
Source

👉@sysadminoff

https://4sysops.com/archives/openai-pauses-astra-work-as-critical-cyber-risk-remains-unresolved/