buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
#Trauer um #Kernel-Entwickler #Dan_Williams
Die #Kernel-Community hat mit Dan Williams einen langjährigen Entwickler verloren. Williams verstarb jetzt unerwartet im Alter von 54 Jahren.
Wer sich schon einmal mit persistentem Speicher unter #Linux beschäftigt hat, ist zwangsläufig über Williams Arbeit gestolpert:
https://linuxnews.de/trauer-um-kernel-entwickler-dan-williams/
Trauer um Kernel-Entwickler Dan Williams
https://linuxnews.de/trauer-um-kernel-entwickler-dan-williams/ #kernel #linux #linuxnews
I think the most important question is: why does anyone comply with what one incurious, self-centered, and self-important man, Linus Torvalds, says?
Why is that most important? Because Linux does not belong to Linus Torvalds. It belongs to the world. Torvalds only gets to dictate if the people who are best-positioned to take that power from him fail to do so. From where I sit (as an outsider), he should have been removed from the project, or at least have his dictatorial power removed, long ago, and the primary problem is that there is no structure or will to actually do that.
Under these conditions Linux is a hierarchical, and therefore right-wing, project. The project allows a single man to dictate the future evolution of a global good. Let's drop the illusion that it is "free" or "open" till that changes.
Re: https://www.heise.de/thema/Passwort_Podcast @christopherkunz @syt
K.A was ihr meint, wenn ihr davon abratet, #Kernel Patches zu cherry-picken. Also ich cherry-picke meine eigenen (https://al2klimov.de/linux) #Linux Patches wie ich gerade lustig bin, es bootet und macht was es soll. /s
If #kernel hackers are now giving #Claude Code unfettered access to do as it pleases on their development computers, what exactly is stopping #Anthropic from performing a supply-chain attack on the entire #Linux ecosystem?
Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?
RE: https://mastodon.social/@rperezrosario/116925717178519995
"I realize that some people really dislike AI, but this is an area where I'm willing to absolutely put my foot down as the top-level maintainer.
Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it.
Or just walk away.
AI is a tool, just like other tools we use. And it's clearly a useful one.
It may not have been that "clearly" even just a year ago, but it's no longer in question today.
There are other questions around AI (like what the economy of it will actually look like in the end), but "is it useful" is no longer one of those questions. Anybody who doubts that clearly hasn't actually used it.
Yes, it can also be a somewhat painful tool, both for maintainer workloads and just from a "it keeps finding embarrassing bugs" standpoint.
But the solution is not to put your head in the sand and sing "La La La, I can't hear you" at the top of your voice like some people seem to do.
The solution is to make sure those LLM tools _help_ maintainers instead of just causing them pain. There's no question on that side.
We're not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.
And no, AI isn't perfect. But Christ, anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time.
Because it's not like natural intelligence is always all that great either.
The kernel project has been and will continue to be about the technology.
Sure, the social angle of working on open source is important and often a very motivating part of the project, but in the end that's a side benefit, not the _point_ of the project.
This is *NOT* some kind of "social warrior" project, never has been, and never will be.
In the kernel community we do open source because it results in better technology, not because of religious reasons.
And so we make decisions primarily based on technical merit. Not fear of new tools."
When I look in sources for real work I use the old school method
This is just a lazy exercise
DESCRIPTION
badblocks is used to search for bad blocks on a device (usually a disk partition). device is the special file corresponding to the device (e.g /dev/hdc1). last_block is the last block to be checked; if it is not specified, the last block on the device is used as a default. first_block is an optional parameter specifying the starting block number for the test, which allows the testing to start in the middle of the disk. If it is not specified the first block on the disk is used as a default.
sources:
man badblocks(8)
https://explorar.dev/linux-kernel/
#kernel #sources #programming #logic #terminal #linux #explorar #dev #bash #csh #kzh #zsh #sh
GhostLock: 15 Jahre alte Kernel-Lücke ermöglicht Root-Zugriff
https://linuxnews.de/ghostlock-15-jahre-alte-kernel-luecke-ermoeglicht-root-zugriff/ #security #linux #kernel #linuxnews
15-Year-Old Linux Kernel GhostLock Flaw Lets Local Users Gain Root
CVE-2026-43499, dubbed GhostLock by Nebula Security, exposes a long-standing Linux kernel futex bug that can lead to local root access.
#kernel #linux-&-open-source-news #software #vulnerability
https://linuxiac.com/15-year-old-linux-kernel-ghostlock-flaw-lets-local-users-gain-root/
KVM Januscape Bug: CVE-2026-53359 in Linux Kernel
🔗 https://cybersecurefox.com/en/kvm-cve-2026-53359-januscape-shadow-mmu-bug
#CVE-2026-53359 #KVM #Januscape #Linux #kernel #vulnerability #shadow #MMU
Dirty Clone – kolejny sposób na roota pod Linuksem https://sekurak.pl/dirty-clone-kolejny-sposob-na-roota-pod-linuksem/ #Aktualnoci #Eskalacja #Hacking #Kernel #Linux #Localroot #Lpe #Pagecache
Whereas DirtyClone exploits a kernel module (which can be tackled by unloading and blocking it), Bad Epoll does not.
CVE-2026-46331: Linux Kernel act_pedit Root Exploit
🔗 https://cybersecurefox.com/en/cve-2026-46331-linux-act-pedit-root
#CVE-2026-46331 #linux #kernel #act #pedit #local #privilege #escalation #page #cache #vulnerability
Linux 7.1 mit neuem NTFS-Treiber freigegeben
https://linuxnews.de/linux-7-1-mit-neuem-ntfs-treiber-freigegeben/ #kernel #linux #linuxnews
Nice, #Bumsrakete works on a #FreeBSD 15.0 system.
TL;DR page cache #vuln in the #kernel, exploitable within seconds, privesc from normal user to #root
17/10 can recommend ⭐🌟
New post: bcachefs on RHEL 10.2, or how I lost an evening to a filesystem.
Four hours of patching kernel headers by hand while the build kept inventing new ways to fail. Hit setenforce 0 out of pure reflex (it was Secure Boot, not SELinux). Gave up, switched to Fedora, worked in two minutes.
I tried REALLY hard. The kernel was right.
https://blog.hofstede.it/bcachefs-on-rhel-102-the-kernel-that-said-no/
#KDE #Linux: Abkehr von #Zen #Kernel und #AUR
#KDE_Linux konnte im Mai spürbare Schritte nach vorne machen und gewinnt an Struktur. Das Projekt stärkt seine Grundlagen und bringt mehr Kontrolle in Aufbau und Pflege des Systems.
Die Entwickler setzen nun auf den eigenen kde‑builder, um #KDE Software direkt zu kompilieren. Das frühere Erstellen von #Arch‑Paketen entfällt damit. Die #Distribution bleibt zwar technisch nah an #Arch, verfolgt aber einen klar eigenen Weg.
Neuer Blog-Artikel
Linux vs Windows - Ein kurzer technischer Vergleich: Windows vs. Linux. Von MS-DOS & OS/2 zum Hybrid-Kernel. Architektur, Sicherheit und Speicherverwaltung.
https://just-stuff.blog/linux-vs-windows-von-dos-bis-zum-hybrid-kernel/
With the date intentionally mis-set, after taking the network down then up, FreeBSD froze in response to:
pkg upgrade -Fqy
Then a kernel panic.
No response to keyboard input, so I could not type 'continue' at the prompt:
db>
I took a snapshot of the guest in the panic state.
root@maximal:~ # freebsd-version -kru ; uname -mvKU
16.0-CURRENT
16.0-CURRENT
16.0-CURRENT
FreeBSD 16.0-CURRENT main-n286271-ee41a882054c GENERIC-NODEBUG amd64 1600018 1600018
root@maximal:~ #
Erneut Schwachstelle im Kernel entdeckt
https://linuxnews.de/erneut-schwachstelle-im-kernel-entdeckt/ #kernel #cifswitch #security #linux #linuxnews
I always remap my sshd daemon to listen to a non-standard port, to reduce a lot of noise. Which has worked fine for years. But every now and then there are attempts. All the #Linux kernel flaws found lately has made remote login attempts more interesting for attackers. And they scan much more broadly now than just port 22.
And that's why my second line of defence is to disallow remote root login - and also make use of the AllowGroups feature in sshd_config. Users granted remote access must be member of a specific group. And root is also excluded from this group.
That pays off these days. And this is a nice filter match for #fail2ban and similar tools
I have 293 login attempts on "random users" since May 21. And 259 attempts as root.
I have talked before about explorar dev. It's a *fancy way *to expolore code in a browser.
I use the tried and tested manner ofvim drivers/acpi/acpica/acapps.hgcc source.c
orgg++
then read and analyze the code in my favourite Wyze amber terminal 80x25 at 38400bps.
Others can't / won't do that. For those who love to burn energy and ram in a massive browser tab, this gem is great to play with.
It is a gem understand me well, just not the feel of a real serial terminal, even one on my IPS LED panels feels more familiar.
Which ever you prefer have fun doing so
Sources:
man gcc(1)
https://explorar.dev/torvalds/linux
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/rawdiff/?id=v7.1-rc4&id2=v7.0
#programming #Linux #kernel #module #Anubis #protection #gcc #OpenSource #POSIX
I typed in alsamixer -c2because one of my audio interfaces suddenly had only output on one of the two channels.
As a rule, in Linux and any other Open Source OS, you don't reboot like a moronic end user, to fix a problem:
rmmod mod_nameinsmod mod_nameI executed the above steps (stepping over the kernel mod slush) and came in the alsamixer to see that there finally is a massive update to the alsamixer for this interface
What I needed to do is pull one fader up in the mixer and get the audio balance again. As a bonus I can now balance the output of the device in alsamixer, instead of on the rack-mount instrument mixer in my effects rack.
sources:
man alsamixer
man rmmod
man insmod
This is how the Linux kernel mailing list looks like from a browser.
From a mobile browser it looks less polished.
It's a *mailing list* you should read it from a email client, not a memory hungry browser, but if you are in the links browser it will look fine. Links is light ;)
The message is important; if you keep up with kernel development on the Linux side section audio drivers, you may find it interesting
https://lkml.org/lkml/2026/5/18/133
#Programming #Linux #kernel #module #Audio #ALSA #c #C_Lang #development #coding
Linus Torvalds: Linux Kernel Team kämpft mit KI erzeugten Sicherheitsmeldungen https://fosstopia.de/kernel-team-ki-sicherheitsmeldungen/ #ITSecurity #Kernel #LinusTorvalds #Linux #LinuxKernel
ModuleJail Blocks Unused Linux Kernel Modules to Limit Attack Surface
ModuleJail is a new project that blacklists unused Linux kernel modules, helping reduce the attack surface exposed by recent local privilege escalation flaws.
#kernel #linux-&-open-source-news #security #software #vulnerability
https://linuxiac.com/modulejail-blocks-unused-linux-kernel-modules-to-limit-attack-surface/
Kernel-Sicherheitsliste mit Bug-Meldungen überschwemmt
https://linuxnews.de/kernel-sicherheitsliste-mit-bug-meldungen-ueberschwemmt/ #kernel #ki #ai #linux #linuxnews
(log in)
WARNING: a linux kernel update is available
$ uptime
15:23:05 up 19:53, 1 user, load average: 0.49, 0.46, 0.60
$ ll -rat /var/log/apt/history.log
-rw-r--r-- 1 root root 18,530 May 16 19:25 /var/log/apt/history.log
$
*sigh*
2026 is 2026ing WAY too hard right now.
Thanks a million, slop-"researchers"
«„Fragnesia“ — Nächste Rechteausweitungslücke im Linux-Kernel:
Microsoft warnt vor einer weiteren Variante der CopyFail-Lücke namens „Fragnesia“ im Linux-Kernel. Sie verschafft root-Rechte.»
Mist, die nächste Linux-Lücke heute und dies noch von Microsoft entdeckt. Moment mal, könnte es sein dass es…, oder doch nicht…, ach komm…, ne es ist…?!??
#linux #fragnesia #microsoft #itsicherheit #lucke #copyfail #root #kernel #itsec #it #linuxkernel #opensource #0day #zeroday
Fragnesia Is Yet Another Dirty Frag Style Linux Kernel Exploit
Fragnesia exposes another Linux kernel page-cache attack path, allowing local root escalation through ESP handling.
Archive: ia: https://s.faithcollapsing.com/i58kw
#kernel #linux-&-open-source-news #software #vulnerability
https://linuxiac.com/fragnesia-is-yet-another-dirty-frag-style-linux-kernel-exploit/
Passwort - der Podcast von heise security: KI Fail, Copy Fail, S/MIME Fail
( XXL Folge 2,4 Stunden, leider ohne Kapitelmarker und Folgennummer, aber interessant wie immer. :-* O:-) )
#CopyFail zieht weite Kreise und geht auch am #Podcast nicht vorüber:
Die #Sicherheitslücke in #Linux ist technisch interessant, was Christopher und Sylvester allerdings an die Grenze ihres Wissens um #Kernel-Innereien bringt. Darüber hinaus wirft Copy Fail diverse grundsätzliche Fragen zur #Sicherheit von Linux und zur Handhabung von @Sicherheitslücken auf, die die Hosts diskutieren.
Außerdem geht in dieser Episode um eine löschwütige KI und natürlich um PKI, zumindest ein bisschen. #DNS #Mail
Webseite der Episode: https://passwort.podigee.io/57-ki-fail-copy-fail-s-mime-fail
Mediendatei: https://audio.podigee-cdn.net/2485319-m-32db6ba0613c9c3319703a63e31139a4.mp3?source=feed
That may be a safer bet going from a 5.4.* kernel version than a jump all the way up to a 7.1.* kernel. For context, this would be a manual kernel upgrade on an Ubuntu 20.04 virtual machine.
https://kernel.ubuntu.com/mainline/v5.10.255/
what do you think?
I manually upgraded a cloud virtual machine (test) running on Ubuntu 20.04 with a 5.4** kernel version to the latest 7.1 kernel available today:
https://kernel.ubuntu.com/mainline/daily/2026-05-13/
I rebooted and it seemed to work fine. Apache web server is running. Doesn't seem to have any problems, but no load is on it.
Do you think it would be fine to run such an old 20.04 Ubuntu version with such a recent kernel? Or should I find a more recently released 5.** series kernel and try that instead?
I am testing getting kernels patched for the recent Linux vulnerabilities, but need to run older Ubuntu 20.04 for a while yet until web applications are manually ported to run on newer versions.
#Fragnesia #Linux #Kernel
"All versions affected by dirtyfrag are affected."
"Any versions without this patch: https://lists.openwall.net/netdev/2026/05/13/79 , so any Linux kernel before May 13 2026."
Nouveaux kernels stables : 7.0.5 / 6.18.28 / 6.12.87 / 6.6.138
Ils embarquent un fix partiel pour #DirtyFrag (CVE-2026-43284) et Copy Fail 2.
Partiel, car Greg Kroah-Hartman a confirmé qu'un second patch est encore en développement et n'a pas encore été mergé.
La mitigation par blacklist des modules reste donc recommandée en attendant.
👇
https://lwn.net/Articles/1071775/
Entwickler diskutieren über Killswitch im Kernel
https://linuxnews.de/entwickler-diskutieren-ueber-killswitch-im-kernel/ #kernel #linux #linuxnews
Schwere Zeiten für den Linux-Kernel: Sicherheitslücke DirtyFrag - ungepatcht
Mehr: https://maniabel.work/archiv/1560
#Linux #Kernel #DirtyFrag #PageCache #Root #RxRPC #xfrm-ESP #up2date #BeDiS
This kernel vulnerability looks interesting to look at.
crypto: caam - fix overflow on long hmac keys
VLAI Severity -> High (confidence: 0.9638)
After years of promises, real-time Linux is actually shipping. The mainstream take is that this is about lower latency, but the real story is deterministic scheduling for control systems that can't tolerate jitter. PREEMPT_RT removes the final excuse for proprietary RTOS holdouts, and that's a bigger deal than most realize. #kernel #realtime #embedded
Two more copy.fail style exploits have been dropped. I hope everybody enjoys patching and rebooting.
Dirty frag: https://github.com/V4bel/dirtyfrag
Copy fail 2: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo
Kritische #Kernel #Lücke bedroht zahlreiche #Linux Systeme - #fosstopia
#IT #Security #Forscher haben eine schwere #Schwachstelle im #Linux_Kernel offengelegt (CVE-2026-31431). Die Lücke trägt den Namen Copy Fail und erlaubt lokalen Nutzern den Zugriff auf höchste Systemrechte (root). Angreifer können gezielt vier Bytes in den Seitencache beliebiger Dateien schreiben und so die Kontrolle über ein System übernehmen...
Copy Fail (CVE-2026-31431) is a Linux kernel vulnerability that allows local unprivileged users to gain root access on affected systems.
https://linuxiac.com/copy-fail-linux-kernel-flaw-allows-local-users-to-gain-root/
🐘 How Linux 7.0 Broke PostgreSQL: The Preemption Regression Explained
IMHO #linux bisa seperti saat ini bukan karena diawali ingin menjadi sesuatu yang ideal tetapi justru karena pragmatisme.
Pd saat itu desain #microkernel #minix yg tdk monolithic dianggap sebagai mimpi indah idealisme sebuah #kernel. Tetapi Torvalds dan yang lain melihat banyak hal sangat ribet untuk diimpelmentasikan menggunakan desain microkernel, sehingga mereka memilih pragmatis.
Hingga lahir dan terus berkembanglah linux yang tidak ideal tapi bisa berevolusi menjadi seperti sekarang.
I always ask similar questions like the following,
There are a lot of folk who are pissed off at Linus Torvalds, for allowing some of his maintainers to use large language models to assist in finding bugs.
The Head Programmer of the fantastic and Beautiful curl also uses a large language model in some form, to hunt for bugs, because both he and Greg from the Linux kernel, saw that the LLM used on GitHub is now suddenly much better at finding those pesky bugs.
Mind you, the only LLM I like is the one that runs locally on my low powered Android phone. That's a micro LLM
Thanks in advance for your response
https://github.com/stevelaskaridis/awesome-mobile-llm
#LLM #AI #slop #miscreant #hallucinated #kernel #curl #Linux #BSD #investation #StopSlop #noAI #keepass #FediVerse #copilot #GitHub #Bull #kaka
New #Linux #kernel #policy: when writing code, humans can be "assisted" by "#AI", but they have to disclose it, and take full responsibility, as contributors.
While this gets celebrated as a "pragmatic stance", it simply delegates responsibilities to individual contributors that no one in good conscience can reasonably take.
Would you be willing to guarantee, legally binding, with all consequences, that your "AI" "assistant" didn't copy-paste code that's under an incompatible license? Or even proprietary, stolen one?
This is a cop out, not a responsible policy. Basically the dirty #subcontractor pattern: Everybody knows that nobody can actually guarantee what they're promising, but hey, wink wink here's their signature, they "promised" it wink wink
New blog post: #FreeBSD 16 System Calls Table
https://alfonsosiciliano.gitlab.io/posts/2026-04-09-freebsd-16-system-calls.html
I wrote this mainly as personal notes to explore and kick off a new project, but it might be useful for others too.
#happycoding #UNIX #openSource #kernel #coding #syscalls #SystemCall
A macOS kernel bug can cause OpenClaw to stop working after 49.7 days
https://photon.codes/blog/we-found-a-ticking-time-bomb-in-macos-tcp-networking
#HackerNews #macOS #kernel #bug #OpenClaw #networking #issues #timebomb
RE: https://mastodon.bsd.cafe/@grahamperrin/116344993053121523
@Dendrobatus_Azureus if you're willing to risk ire in The FreeBSD Forums, you might add a couple of links in <https://forums.freebsd.org/threads/102251/>:
1. <https://www.reddit.com/r/freebsd/comments/1sapr8a/claude_gained_a_root_shell_in_8_hours_by_creating/>
2. <https://www.reddit.com/r/freebsd/comments/1sbzf3q/freebsds_position_on_the_use_of_aigenerated_code/>
Respectively:
1. Claude Gained a Root Shell in 8 Hours by Creating an Exploit for the FreeBSD Kernel
2. FreeBSD's position on the use of AI-generated code?
The first of the two has a pinned comment with links out to the Fediverse, and back to The FreeBSD Forums.
If not links to Reddit, you might find at least one non-Reddit link that readers should find of interest. My personal favourite is the Nicholas Carlini presentation below.
#FreeBSD #Forums #security #infosec #cybersecurity #AI #Claude #research #kernel #vulnerability
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
<https://www.youtube.com/watch?v=1sd26pWhfmg> (3rd March)
― essential viewing for anyone with an interest in cybersecurity or infosec.
@dch thanks for the encouragement.
A few more links in the comment that's pinned under <https://redd.it/1sapr8a>, but Carlini's half-hour presentation is a must.