Linux
2.15K subscribers
4.2K photos
20 videos
17.7K links
Новости Линукс Linux

По всем вопросам @evgenycarter
Download Telegram
📰 Jellyfin 12.0 Media Server Released with Faster Database, Modern UI

Jellyfin 12.0 is out with a faster database backend, Modern UI by default, FFmpeg 8.1, expanded books and comics features, and security fixes.

🔗 Source: /

#ffmpeg

👉@sysadminoff

https://linuxiac.com/jellyfin-12-0-media-server-released-with-faster-database-modern-ui
Chrome 153 starts Google’s new two-week release cycle

Chrome 153 is rolling out across desktop, Android, and iOS as Google begins delivering major Chrome updates every two weeks instead of every four. The faster cadence is intended to shorten the wait for security fixes, performance improvements, and web-platform changes as online threats evolve more quickly.
Source

👉@sysadminoff

https://4sysops.com/archives/chrome-153-starts-googles-new-two-week-release-cycle/
👍1
Samsung bets on on-premises Mistral AI to tune chip fabs

Samsung is bringing Mistral AI models, including Mistral Large, inside its semiconductor operations while taking a strategic equity stake in the French startup. The on-premises deployment will analyze fab data for defect detection, equipment tuning, chip design, and yield improvement without sending sensitive engineering information to external cloud services.
Source

👉@sysadminoff

https://4sysops.com/archives/samsung-bets-on-on-premises-mistral-ai-to-tune-chip-fabs/
📰 FEX 2609 Released With Speedier JIT Performance, JIT Disk Cache Option

FEX 2609 was released overnight as the newest monthly feature release for this open-source emulator that allows running Linux x86_64 binaries on AArch64, including the likes of Steam and Steam Play (Proton) for enabling Windows games to run rather well on ARM64 Linux systems...

🔗 Source: https://www.phoronix.com/news/FEX-2609-Released

#linux #opensource #proton #steam

👉@sysadminoff

https://phoronix.com/news/FEX-2609-Released
📰 FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.The.

🔗 Source: https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html

#linux

👉@sysadminoff
📰 LLVM Merges Support For AMD's RMPCHKD, RMPREAD & RMPOPT Instructions

With the Linux kernel still working toward landing support for AMD's RMPOPT optimization for helping to reduce overhead on SEV-SNP enabled servers, the LLVM/Clang compiler has in turn prepped for the milestone by landing support for the RMPOPT, RMPREAD, and RMPCHKD instructions for Zen 5 and newer...

🔗 Source: https://www.phoronix.com/news/LLVM-Zen5-Zen6-RMPOPT

#amd #kernel #linux

👉@sysadminoff

https://phoronix.com/news/LLVM-Zen5-Zen6-RMPOPT
18 уязвимостей в ядре Linux c эксплоитами для получения прав root в системе

Исследователи из компании Nebula Security раскрыли сведения о 18 уязвимостях в ядре Linux и подготовили для них эксплоиты, позволяющие непривилегированному локальному пользователю получить права root в системе. Уязвимости устранены в различных весенних и летних обновления ядра ядра. Выявленные проблемы.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66239
DeepSeek Harness flaw let AI agents disable their own sandbox

A critical DeepSeek Harness vulnerability let a coding agent switch itself into unrestricted mode with one shell command, bypassing both file-sandbox protections and approval prompts. CVE-2026-82533 affects versions through 0.1.1-rc.2, and administrators should install 0.1.2-alpha.2 or later because the first fixed version listed by the project was not published to npm.
Source

👉@sysadminoff

https://4sysops.com/archives/deepseek-harness-flaw-let-ai-agents-disable-their-own-sandbox/
Databricks makes AI agent search faster by teaching it when to stop

Databricks has expanded Adaptive Instructed-Retriever, a search model that dynamically decides how many retrieval rounds an AI agent needs instead of using the same search depth for every request. The company says the approach delivers comparable retrieval quality to leading models while responding about twice as fast, helping reduce latency and compute costs for multi-step enterprise searches.
Source

👉@sysadminoff

https://4sysops.com/archives/databricks-makes-ai-agent-search-faster-by-teaching-it-when-to-stop/
BleachBit 6.0.4 offers faster scanning, improves Linux cleaners

A new version of BleachBit, an open-source system cleaning tool, is out. BleachBit 6.0.4 brings everything I mentioned in my spot on the BleachBit 6.0.4 beta release, including macOS support for the first time – albeit in an early state, and including a Cleaner for Safari and a choice of the (neat) BleachBit CLI or an early GUI. Windows and Linux users all benefit from faster startup times and scanning speeds, and gain new cleaners for Android Studio, Gradle’s cache, fish and Zsh shells and Python CLI. Top-level log files are cleared by the Claude cleaner, and browser “super cookies” […]
You're reading BleachBit 6.0.4 offers faster scanning, improves Linux cleaners, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.

👉@sysadminoff

https://www.omgubuntu.co.uk/2026/09/bleachbit-6-0-4-update
Infostealers are draining Claude subscribers’ paid token allowances

Infostealer malware is being used to steal active Claude login sessions, letting attackers consume subscribers’ paid token allowances without their knowledge. Anthropic says the attacks begin on users’ devices rather than with a breach of Claude’s infrastructure, but the resulting session hijacking can still trigger exhausted quotas, unauthorized charges, and account suspensions.
Source

👉@sysadminoff

https://4sysops.com/archives/infostealers-are-draining-claude-subscribers-paid-token-allowances/
📰 KDE Plasma 6.7.5 Desktop Environment Is Out with Many Improvements and Fixes

KDE Plasma 6.7.5 is now available as the fifth maintenance update to the KDE Plasma 6.7 desktop environment series with more improvements and bug fixes.

🔗 Source: https://9to5linux.com/kde-plasma-6-7-5-desktop-environment-is-out-with-many-improvements-and-fixes

#kde #plasma

👉@sysadminoff
AxonOS - real-time ОС для нейрокомпьютерных интерфейсов

Представлен открытый проект AxonOS, развивающий программную инфраструктуру для систем с нейрокомпьютерным интерфейсом, предназначенную для построения детерминированного слоя выполнения между нейронным оборудованием и AI. Ядро AxonOS разрабатывается на языке Rust в режиме "no_std" с акцентом на предсказуемое real-time выполнение, формализованный ABI системных вызовов, capability-модель доступа, обходящийся без блокировок IPC и контроль времени выполнения. Исходный код открыт под лицензиями MIT или Apache 2.0.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66241
PostGREShell: в PostgreSQL обнаружили существовавшую 12 лет возможность запуска произвольного кода

1 сентября исследователи Cyera Research раскрыли подробности уязвимости PostGREShell — CVE-2026-6471, позволявшей пользователю PostgreSQL с привилегией REPLICATION загружать произвольные нативные библиотеки в процесс СУБД. Ошибка появилась вместе с механизмом логического декодирования ещё в PostgreSQL 9.4 и оставалась незамеченной около 12 лет. Само исправление было выпущено раньше — 13 августа в PostgreSQL 18.6, 17.11, 16.15, 15.19 и 14.24.
PostgreSQL оценил CVE-2026-6471 в 7,2 балла CVSS. Согласно официальному описанию, пользователь, не являющийся суперпользователем, но имеющий атрибут REPLICATION, мог через механизм логического декодирования заставить сервер выполнить dlopen() произвольного файла, доступного системной учётной записи PostgreSQL. В результате код из библиотеки выполнялся уже не с SQL-правами атакующего, а непосредственно внутри процесса сервера БД.
( читать дальше... )



 cve, postgresql, replication

👉@sysadminoff

https://www.linux.org.ru/news/security/18377200
📰 New Patches Provide HDMI 1.4 3D Mode Support For AMD Radeon Graphics On Linux

It turns out one of the feature limitations of the AMDGPU Linux graphics driver is HDMI 1.4 3D output support with frame packing, top-and-bottom, and side-by-side options for transmitting simultaneous video streams. I wasn't aware of this limitation for the lack of any 3D displays and many Linux enthusiasts/gamers as well, but if you happen to have a compatible HDMI 1.4 3D display, there are pending patches to finally make this a reality...

🔗 Source: https://www.phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode

#amd #linux

👉@sysadminoff

https://phoronix.com/news/AMDGPU-HDMI-1.4-3D-Mode
📰 CHUWI UniBook With Intel Wildcat Lake For A $449 Linux-Friendly Laptop

CHUWI recently launched the UniBook laptop powered by the Intel Core 3 304 "Wildcat Lake" SOC and priced at just $449 USD. Especially with today's high component pricing, a brand new sub-$500 laptop is extremely rare. Rather than using some dated SoC, it uses Wildcat Lake as Intel's new value option alternative to the Core 3 Series Ultra "Panther Lake" SoCs.

🔗 Source: https://www.phoronix.com/review/chuwi-unibook-wildcat-lake

#intel #linux

👉@sysadminoff

https://phoronix.com/review/chuwi-unibook-wildcat-lake
Выпуск альтернативного X-сервера yserver 1.5

Состоялся выпуск X11-сервера yserver 1.5.0, написанного с нуля на языке Rust и поддерживающего актуальные расширения протокола X11. Проект не ставит перед собой цель повторить все возможности Xorg Server и ограничивается только функциональностью, необходимой для запуска современных сред рабочего стола, оконных менеджеров, приложений и графических библиотек (GTK, Qt, SDL, GLFW). Из протестированных окружений отмечены MATE, Xfce, Cinnamon, Sonic и Enlightenment, а также оконные менеджеры, такие как icewm, FVWM3, openbox, i3 и wmaker. Код проекта распространяется под лицензией MIT.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66242
📰 Open CAD Studio Is a New Rust-Based Open-Source CAD App for Linux

Open CAD Studio is a new GPL-licensed CAD app for Linux with native DWG/DXF editing, 2D drafting, 3D modeling, and a browser-based version.

🔗 Source: /

#linux #opensource #rust

👉@sysadminoff

https://linuxiac.com/open-cad-studio-is-a-new-rust-based-open-source-cad-app-for-linux
📰 DaVinci Resolve 21.1 Released - Now With AI Assistant Integration

For those using the Linux-friendly DaVinci Resolve video editing and color correction/grading and visual effects software, DaVinci Resolve 21.1 is out today as a major update to this cross-platform solution...

🔗 Source: https://www.phoronix.com/news/DaVinci-Resolve-21.1

#linux

👉@sysadminoff

https://phoronix.com/news/DaVinci-Resolve-21.1
В ядре Linux 7.4 намечена значительная чистка устаревших ARM-систем

Арнд Бергман (Arnd Bergmann), отвечающий за пакеты с ядром в SUSE, подготовил патчи, удаляющие из ядра около 55 тысяч строк кода, связанного с поддержкой устаревших платформ ARM, которые почти не используются и мешают сопровождению актуальных подсистем. К удалению намечены платформы sa1100, omap24xx, i.MX31, samv7, lpc18xx, riscpc, axxia, footbridge, старые платы pxa, orion, dove и mv78xx0, чипы без блока управления памятью (MMU) и микроконтроллеры stm32f4/f7/h7. Указанные платформы намечены для удаления в ядре 7.5, ожидаемом в первом квартале 2027 года, чтобы не проводить удаление в LTS-ядре и дать время пользователям заявить о продолжении использования каких-то систем для предотвращения их удаления.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66243
Zuckerberg pitches Muse as a privacy-first AI agent

Mark Zuckerberg says Meta’s Muse is designed to move beyond chatbots by giving each user a persistent AI agent that can operate a virtual machine, pursue long-running goals, and interact with services on the user’s behalf. Its proposed security model includes confidential computing, least-privilege access, approval gates, and monitoring agents intended to detect prompt injection and unsafe data movement.
Source

👉@sysadminoff

https://4sysops.com/archives/zuckerberg-pitches-muse-as-a-privacy-first-ai-agent/