News & Information       http://info.owt.com

Linux

08/13/2026   LinuxSecurity.com
A security update for python3.9 on Rocky Linux 9 addresses a critical vulnerability, allowing directory escape during tarfile extraction, rated with a CVSS score of 7.3.
08/13/2026   LinuxSecurity.com
A security update for the Automatic Bug Reporting Tool in Rocky Linux 8 addresses multiple vulnerabilities, including arbitrary file writes and content injection, enhancing system integrity.
08/13/2026   LinuxSecurity.com
A moderate security update for the kernel-rt on Rocky Linux 8 addresses vulnerabilities including a fix for partition descriptor bookkeeping and a double-free issue affecting network buffers.
08/13/2026   LinuxSecurity.com
A moderate kernel security update is available for Rocky Linux 8, addressing issues related to partition descriptor bookkeeping and a double-free bug, with associated CVE links provided.
08/13/2026   LinuxSecurity.com
A moderate security update for python-idna has been released for Rocky Linux 8, addressing a denial of service vulnerability identified as CVE-2026-45409.
08/12/2026   LinuxSecurity.com
A vulnerability in xdg-dbus-proxy allowed malicious Flatpak applications to monitor D-Bus signals; this has been fixed in version 0.1.6-1+deb13u2 for Debian's stable distribution.
08/12/2026   LinuxSecurity.com
Debian has issued an advisory regarding multiple vulnerabilities in the Xorg X server that could lead to privilege escalation and denial of service, urging updates for affected packages.
08/12/2026   LinuxSecurity.com
Debian's xorg-server package has several vulnerabilities that may allow privilege escalation and crashes if exploited; users are advised to upgrade to the latest fixed version.
08/12/2026   LinuxSecurity.com
Gentoo Linux has issued a security advisory about multiple vulnerabilities in FreeType, urging users to upgrade to version 2.14.3 to mitigate risks including an information leak.
08/12/2026   LinuxSecurity.com
Ubuntu issued a security notice for a vulnerability in node-follow-redirects affecting multiple LTS releases, allowing potential exposure of sensitive information due to improper handling of authentication headers.
08/12/2026   LinuxSecurity.com
Fedora has released an update for vaultwarden to version 1.37.1, addressing several CVEs and patched vulnerabilities, enhancing the security of this unofficial Bitwarden server.
08/12/2026   LinuxSecurity.com
Fedora 43 has updated cri-o to version 1.34.11, addressing CVE-2026-34986 and resolving specific bugs while providing upstream fixes for enhanced stability and security.
08/12/2026   LinuxSecurity.com
Fedora 44 has released apr-util version 1.6.5 with security fixes, enhancing its Apache Portable Runtime Utility library for better handling of XML, LDAP, and other functionalities.
08/12/2026   LinuxSecurity.com
The Fedora 44 update for libcupsfilters version 2.1.1 includes security fixes for CVE-2026-64611 and CVE-2026-64612, addressing potential vulnerabilities in printing filters.
08/12/2026   LinuxSecurity.com
The Fedora update addresses vulnerabilities CVE-2026-11822 and CVE-2026-11824 in SQLite 3.51.2, enhancing security against arbitrary code execution and buffer overflow risks.
08/12/2026   LinuxSecurity.com
Fedora 44's linux-firmware package has been updated with numerous firmware updates for various devices including amdgpu, WiFi, Bluetooth, and ethernet, along with AMD CPU microcode improvements.
08/12/2026   LinuxSecurity.com
Fedora has released an update for cri-o version 1.34.11, addressing a denial of service vulnerability and providing upstream fixes, with installation instructions available via dnf.
08/12/2026   LinuxSecurity.com
Fedora 44 has released an update for vaultwarden version 1.37.1, addressing multiple vulnerabilities, including a significant denial of service issue and other undisclosed security patches.
08/12/2026   LinuxSecurity.com
SUSE released a moderate security update for gzip to address CVE-2026-41992, involving a global buffer overflow vulnerability. Users are advised to apply the update promptly.
08/12/2026   LinuxSecurity.com
Ubuntu released security updates for libgit2 addressing multiple vulnerabilities that could allow remote code execution, denial of service, and credential leaks across various LTS versions.
08/11/2026   Linux Journal
Intel’s Linux Vulkan Driver Adds AV1 Video Encoding for Arc Alchemist GPUs

Intel’s open-source Linux graphics stack has taken another step forward with hardware-accelerated AV1 encoding through Vulkan Video. New code merged for Mesa’s ANV Vulkan driver enables the VK_KHR_video_encode_av1 extension on Intel’s DG2/Alchemist graphics hardware, including Arc A-Series GPUs.

The development expands Intel’s Vulkan Video capabilities on Linux and gives applications another standardized way to access the dedicated video encoding hardware found in modern Intel GPUs.

AV1 Encoding Arrives in Intel ANV

The key change is support for the Vulkan extension VK_KHR_video_encode_av1 in Mesa’s open-source Intel ANV driver.

The extension was finalized by the Khronos Group in 2024 and provides a standardized Vulkan interface for hardware-accelerated AV1 encoding. It complements Vulkan Video’s existing AV1 decoding support and means Vulkan can provide both encoding and decoding interfaces for AV1, H.264, and H.265.

Intel had previously stated that its Arc graphics products would support Vulkan Video AV1 encoding through a future software update.

Initially Targeting Intel Arc Alchemist

The newly enabled Linux support specifically targets DG2, better known commercially as Intel’s Arc Alchemist GPU generation.

These GPUs already contain dedicated hardware capable of AV1 encoding, so the Mesa update does not add AV1 capability through software. Instead, it provides Vulkan applications with another way to access the GPU’s existing hardware video engine.

That distinction is important because hardware encoding can deliver much better performance and efficiency than encoding AV1 entirely on the CPU.

Why AV1 Matters

AV1 has become increasingly important for streaming, screen recording, video conferencing, and online video distribution.

The codec can provide high image quality at relatively low bitrates, making it attractive for applications where bandwidth and storage efficiency matter. It is also royalty-free, which has helped encourage adoption throughout the open-source ecosystem.

Hardware AV1 encoding can be particularly useful for:

  • Game streaming

  • Desktop recording

  • Live broadcasting

  • Video conferencing

  • Video transcoding

  • Content creation

For Linux users with supported Intel Arc hardware, Vulkan Video now has the potential to provide a common API for these workloads.

Building on H.264 and H.265 Support

The AV1 work follows recent improvements to Intel’s Vulkan Video encoding support for other codecs.

08/06/2026   Linux Journal
New AMD P-State Patch Delivers Major Linux Gaming Performance Boost

A newly proposed patch for the Linux kernel's AMD P-State CPU frequency scaling driver is showing impressive gaming performance improvements, potentially delivering a noticeable boost for Ryzen users without requiring new hardware. Early benchmarks indicate that the optimization can significantly improve frame rates in CPU-bound games by allowing processors to respond more quickly to changing workloads. (phoronix.com)

Although the patch has not yet been merged into the mainline Linux kernel, the initial results have generated considerable excitement among Linux gamers and kernel developers alike.

What Is AMD P-State?

AMD P-State is the modern CPU frequency scaling driver for AMD Ryzen processors on Linux. Rather than relying on the older ACPI CPUFreq driver, AMD P-State communicates directly with the processor to adjust clock speeds based on workload demands.

Its goals include:

  • Faster frequency scaling
  • Improved power efficiency
  • Better responsiveness
  • Higher performance during demanding workloads
  • Lower power consumption when the system is idle

Most modern Linux distributions already support AMD P-State on compatible Ryzen processors. (kernel.org)

A Focus on Gaming Performance

The new patch specifically targets how quickly AMD P-State responds when a game suddenly demands additional CPU performance.

Many games rapidly alternate between light and heavy CPU workloads. If the processor takes too long to increase its clock speed, short performance dips can occur.

The proposed optimization reduces that delay, allowing the CPU to boost more aggressively when needed and helping maintain smoother gameplay. (phoronix.com)

Promising Benchmark Results

According to early testing, the patch delivers meaningful improvements across several Linux gaming workloads.

Reported benefits include:

  • Higher average frame rates
  • Better 1% low FPS performance
  • Faster CPU frequency response
  • Improved responsiveness during gameplay
  • More consistent frame delivery

The biggest gains appear in CPU-limited games where processor performance has a greater impact than GPU performance. Systems that are already GPU-bound may see smaller improvements. (phoronix.com)

Designed for Modern Ryzen CPUs

The patch targets systems using the AMD P-State driver, which supports many recent Ryzen processors.

Compatible platforms generally include:

08/04/2026   Linux Journal
Linux Kernel Begins Phasing Out the crypto_rng Layer to Simplify Random Number Generation

Linux kernel developers are moving forward with plans to remove the crypto_rng API layer, a long-standing component of the kernel's cryptographic subsystem. The proposed change is part of a broader effort to simplify the kernel's internal architecture by eliminating redundant code paths and encouraging developers to rely on the kernel's modern random number generation interfaces instead. (phoronix.com)

Although the change happens entirely behind the scenes, it reflects the Linux kernel community's ongoing commitment to reducing technical debt, improving maintainability, and modernizing core infrastructure.

What Is the crypto_rng Layer?

The crypto_rng framework is an API within the Linux kernel's Crypto API that provides random number generation services for kernel components.

Historically, it allowed different kernel subsystems and drivers to request random data through a generic cryptographic interface. Over time, however, the kernel's dedicated random number generator has matured considerably, making much of the crypto_rng abstraction unnecessary. (kernel.org)

Today, developers generally recommend using the kernel's built-in random number generation functions directly instead of routing requests through the older crypto layer.

Why Developers Want to Remove It

According to discussions on the Linux kernel mailing list, the crypto_rng layer has become largely redundant.

Modern kernel code already relies on well-established interfaces such as:

  • get_random_bytes()
  • get_random_u32()
  • get_random_u64()

These functions are maintained as part of the kernel's primary random number generation subsystem and are widely used throughout Linux. Maintaining an additional abstraction layer increases code complexity without providing significant practical benefits. (phoronix.com)

Removing unnecessary infrastructure also makes the kernel easier to maintain and audit over the long term.

Simplifying the Crypto API

The Linux Crypto API has evolved significantly over the years as new algorithms, hardware accelerators, and security features have been introduced.

Kernel maintainers have increasingly focused on:

07/30/2026   Linux Journal
GNU Binutils 2.47 Released with New RISC-V Features, Linker Improvements, and Reproducible Builds

The GNU Project has officially released GNU Binutils 2.47, the latest version of its essential collection of binary development tools for Linux and other Unix-like systems. The release delivers numerous bug fixes alongside new assembler, linker, and disassembler capabilities, expanded RISC-V support, reproducible source archives, and continued modernization of the GNU toolchain.

Used by developers worldwide, GNU Binutils forms a core part of the software development ecosystem, providing the low-level tools needed to assemble, link, inspect, and manipulate executable programs and object files.

What Is GNU Binutils?

GNU Binutils is a collection of command-line utilities that work closely with compilers such as GCC and Clang. While a compiler translates source code into object files, Binutils provides the tools needed to transform those object files into executable programs and libraries.

The package includes well-known utilities such as:

  • ld (GNU Linker)
  • as (GNU Assembler)
  • objdump
  • objcopy
  • readelf
  • nm
  • strip
  • ar
  • strings

Together, these tools are used daily by Linux distributions, embedded developers, operating system projects, and software engineers building applications in C, C++, Rust, Go, and many other languages.

Expanded Support for RISC-V

One of the biggest improvements in Binutils 2.47 is expanded support for the rapidly growing RISC-V architecture.

The release adds support for several additional standard RISC-V extensions, allowing developers targeting modern RISC-V processors to work with newer instruction sets and hardware capabilities. These additions continue the GNU toolchain's strong commitment to one of the fastest-growing open processor architectures.

As more Linux distributions, development boards, and enterprise hardware adopt RISC-V, keeping development tools current is becoming increasingly important.

New Assembler Options

GNU Assembler (gas) gains several useful enhancements in version 2.47.

Among the most notable is a new command-line option:

  • --reloc-section-sym=[all|internal|none]

This option gives developers finer control over how relocations referencing locally bound symbols are converted to section symbols, improving flexibility for certain assembly and linking workflows.

The release also introduces numerous assembler improvements across multiple CPU architectures.

Better Disassembly for AArch64

Developers working with Arm-based systems also benefit from new functionality.

07/28/2026   Linux Journal
GOG Officially Expands Linux Support with Native Galaxy Client in Development

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS—until now.

Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway.

A Long-Requested Feature Finally Becomes Reality

Native GOG Galaxy support has consistently ranked among the most requested features from Linux users. Until now, players who wanted to use Galaxy's library management, cloud saves, achievements, and automatic updates had to rely on compatibility layers or community-developed launchers.

In a statement to GamingOnLinux, GOG joint CEO Krzysztof Papliński said the company has hired a dedicated specialist and is actively exploring the best approach for bringing Galaxy to Linux. He described Linux as "one of the topics we hear the most about from our community," emphasizing that the project is now an active development priority.

Why GOG Galaxy Matters

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application.

The launcher currently offers features including:

  • Automatic game installation and updates
  • Cloud save synchronization
  • Achievement tracking
  • Playtime statistics
  • Game library organization
  • Integrated storefront browsing
  • Friends lists and social features
  • Cross-platform launcher integration

Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem.

Linux Is No Longer an Afterthought

GOG's announcement reflects the growing importance of Linux gaming over the past several years.

The rapid adoption of Valve's Steam Deck, continuous improvements to Proton, and increasing hardware compatibility have significantly expanded Linux's role in PC gaming. As Linux's share of Steam users has grown, more developers and publishers have begun treating the platform as a viable target rather than a niche operating system.

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

07/23/2026   Linux Journal
Linux Kernel 7.1.4 Released with Bug Fixes, Security Updates, and Hardware Improvements

Greg Kroah-Hartman has announced the release of Linux Kernel 7.1.4, the latest stable maintenance update for the Linux 7.1 series. As with other stable kernel releases, version 7.1.4 focuses on fixing bugs, improving hardware compatibility, and addressing security and reliability issues without introducing new features. The update became available on July 18, 2026, and users of the Linux 7.1 branch are encouraged to upgrade as soon as possible.

Rather than changing the kernel's feature set, Linux 7.1.4 delivers dozens of targeted fixes collected from developers across multiple kernel subsystems, helping ensure a more stable experience for desktops, servers, embedded devices, and cloud deployments.

Another Important Stable Maintenance Release

The Linux stable branch exists to provide safe updates between major kernel versions. Every stable release undergoes review before being published and contains fixes that have already been tested in the mainline kernel.

Linux 7.1.4 continues this process by incorporating patches that resolve regressions, improve system stability, and fix issues reported by users since the release of Linux 7.1.3.

For most users, these maintenance updates are recommended because they improve reliability without altering existing functionality.

Bug Fixes Across Multiple Kernel Subsystems

Like previous stable releases, Linux 7.1.4 includes fixes spanning many areas of the kernel.

The update addresses issues affecting:

  • Memory management
  • File systems
  • Networking
  • Device drivers
  • Architecture-specific code
  • Core kernel infrastructure
  • USB and storage subsystems

These targeted patches help eliminate crashes, improve compatibility with newer hardware, and resolve edge cases that may only appear under specific workloads.

Improved Hardware Compatibility

One of the ongoing goals of Linux stable releases is expanding support for existing and newly released hardware.

Linux 7.1.4 includes updated drivers and compatibility fixes for various devices, helping improve support for:

  • Graphics hardware
  • Storage controllers
  • Networking devices
  • USB peripherals
  • Laptop components
  • ARM development boards

Although no major driver additions are expected in a maintenance release, incremental improvements like these often resolve hardware-specific bugs reported by users after earlier releases.

Security and Reliability Updates

Stable kernel releases also include security-related fixes that have been accepted into the maintenance branch.

07/21/2026   Linux Journal
Firefox 153 Released with HDR Video, Smarter PDF Tools, Better Privacy, and New Linux Improvements

Mozilla has officially released Firefox 153, bringing another round of improvements to its open-source web browser. The latest version introduces new multimedia capabilities, enhanced PDF editing tools, stronger privacy protections, better support for modern web technologies, and several features aimed at improving the browsing experience across Linux, Windows, and macOS. Firefox 153 became available on the stable release channel on July 21, 2026.

While this isn't a major redesign, Firefox 153 delivers a collection of practical updates that benefit both everyday users and web developers.

HDR Video Playback Comes to Windows

One of the headline features in Firefox 153 is support for High Dynamic Range (HDR) video playback on compatible Windows systems.

Users with HDR-capable displays and Windows HDR enabled can now enjoy richer colors, improved contrast, and brighter highlights when watching supported online video content. Mozilla notes that certain laptop displays offering only "HDR video streaming" are not currently supported, and some HDR videos recorded on mobile phones may still have limitations.

Although this feature is Windows-specific, it represents another step toward bringing Firefox in line with modern multimedia standards.

PDF Editing Becomes Even More Powerful

Mozilla continues expanding Firefox's built-in PDF editor, eliminating the need for third-party applications in many situations.

Firefox 153 introduces the ability to:

  • Merge multiple PDF documents
  • Insert images as new PDF pages
  • Continue using existing editing tools such as annotations, page organization, and text editing

These additions make Firefox an even more capable document viewer and editor, especially for users who frequently work with PDF files.

Stronger Privacy and Permission Controls

Privacy remains one of Firefox's biggest selling points, and version 153 introduces several enhancements designed to give users more visibility and control over website permissions.

New improvements include:

  • A visual indicator when a website is actively accessing your location
  • More restrictive default permissions for browser extensions accessing local files
  • Local Area Network (LAN) restrictions enabled by default for all users

These changes reduce unnecessary exposure of local resources while making it easier to understand what websites and extensions can access.

Experimental JPEG XL Support

Firefox 153 also adds experimental support for the JPEG XL image format, which many developers consider a promising successor to older image standards.

JPEG XL offers several advantages, including:

07/16/2026   Linux Journal
NanoKVM-Go Brings AI-Powered Hardware Control to Linux with a Compact USB-C KVM

Sipeed has introduced NanoKVM-Go, a compact USB-C KVM-over-IP device that combines remote hardware management with AI integration. Designed for Linux, Windows, macOS, and other USB-C devices, NanoKVM-Go allows users to remotely view and control a system through a web browser while exposing its keyboard, mouse, and display functions to AI agents via the Model Context Protocol (MCP).

Unlike traditional KVM-over-IP solutions that require multiple cables and dedicated networking hardware, NanoKVM-Go simplifies the setup into a single USB-C connection, making remote administration and AI-assisted automation more accessible for developers, system administrators, and homelab enthusiasts.

A Portable USB-C KVM

NanoKVM-Go is roughly the size of a smartwatch, measuring about 45 × 40 × 15 mm, yet it combines several functions into a single device.

Key hardware features include:

  • USB-C connection for video, audio, keyboard, mouse, and power
  • Wi-Fi 6 connectivity
  • Browser-based remote management
  • Support for virtual USB storage
  • Built-in Tailscale integration for secure remote access
  • Fanless aluminum enclosure with low power consumption

Because it connects over USB-C using DisplayPort Alt Mode, the device can manage a wide variety of hardware without requiring software installation on the target system.

Designed for Linux and Beyond

NanoKVM-Go supports numerous USB-C devices, including:

  • Linux desktops and laptops
  • Windows PCs
  • macOS systems
  • Mini PCs
  • Steam Deck
  • Android devices with DisplayPort Alt Mode
  • iPhone 15 and newer models
  • Tablets supporting USB-C video output

For Linux users, this provides an easy way to perform BIOS configuration, operating system installation, kernel debugging, or remote troubleshooting—even when the operating system is unavailable.

AI Integration Through MCP

One of NanoKVM-Go's defining features is its AI-native design.

Rather than simply streaming a desktop remotely, the device exposes its KVM functions as an MCP (Model Context Protocol) server, allowing compatible AI agents to interact with the connected computer using hardware-level keyboard and mouse input.

This enables AI systems to:

  • View the screen
  • Move the mouse
  • Type on the keyboard
  • Launch applications
  • Navigate user interfaces
  • Complete repetitive desktop workflows

Because control happens at the hardware level, AI agents can interact with systems regardless of the operating system installed.

07/14/2026   Linux Journal
AI Uncovers a 15-Year-Old Linux Kernel Root Vulnerability Hidden Since 2011

Artificial intelligence has helped uncover one of the most significant Linux kernel security flaws in recent years. Security researchers at Nebula Security announced the discovery of GhostLock (CVE-2026-43499), a critical local privilege escalation vulnerability that remained hidden in the Linux kernel for approximately 15 years before being identified by the company's AI-powered vulnerability research platform, VEGA.

The vulnerability affects Linux kernels dating back to version 2.6.39 (2011) and allows an unprivileged local user to obtain full root privileges on vulnerable systems. Its discovery not only highlights the importance of timely kernel updates but also demonstrates how AI is beginning to transform vulnerability research.

What Is GhostLock?

GhostLock is a use-after-free (UAF) vulnerability located in the Linux kernel's futex (fast userspace mutex) implementation.

Futexes are synchronization primitives that allow user-space applications to efficiently coordinate access to shared resources while minimizing expensive kernel interactions. Because they are widely used throughout Linux, any flaw within this subsystem can have broad security implications.

According to Nebula Security, incorrect handling of the remove_waiter() function can leave behind a dangling kernel pointer that an attacker can manipulate to execute arbitrary code with kernel privileges.

A Reliable Path to Root Access

One of the reasons GhostLock has attracted so much attention is the reported reliability of the exploit.

Researchers demonstrated that an attacker with nothing more than a standard local user account can escalate privileges to root in roughly five seconds, with a reported success rate of 97% on vulnerable systems.

Unlike many kernel exploits that are unstable or require highly specific system configurations, GhostLock appears to be both practical and repeatable, making it particularly concerning for administrators.

Container Escapes Are Also Possible

The implications extend beyond traditional Linux desktops and servers.

Researchers report that GhostLock can also be used to escape containers and compromise the underlying host operating system. Because containers share the host kernel, a successful privilege escalation inside a container can potentially grant root access to the host itself.

This makes the vulnerability especially important for environments running: