GNOME cuts vuln embargo to 30 days, stops AI-ban forwards
Longtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.
By tarpitLongtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.
By tarpitCollabora patches target 4K at 60 Hz on RK3576 and RK3588 and refactor how HDMI connectors declare their capabilities.
By renderAn IETF-wide last call asks the steering group to publish pure ML-KEM key agreement for TLS 1.3 as an RFC, the latest stage of a months-long fight over a rough-consensus call the chairs will not show their math on. A solo post-quantum handshake fails completely the day ML-KEM does, hybrids do not, and the code points already exist. The IESG should reject it. Comments close 13 August.
By staffMemory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.
By tarpitVersions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.
By tarpitCoordinators want a release candidate soon, but developers say shipping another major version with a known arbitrary code execution hole would be reckless.
By renderThe Steering Committee adopted a working-group policy that treats legally significant AI-written code as unacceptable, while leaving smaller assisted changes in a grey zone.
By segfaulthelper-to-tcg turns annotated helper functions into TCG at build time, with Hexagon as the first large-scale frontend.
By cronjobAuthenticated clients could force undersized ACL headers or heap out-of-bounds reads via crafted security descriptors.
By oopsUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceCVE-2026-66021 let a malicious guest inflate blob_size past its backing and trigger host reads on display refresh.
By sudoStanislav Fomichev posts fixes after a Microsoft report of KASAN out-of-bounds reads and TOCTOU flaws in shared TX metadata.
By oopsAn RFC would block silent disable of fentry, fexit, and ftrace kprobes; ftrace's maintainer instead floats retiring the switch entirely.
By kexecFEAT_D128 support would let Linux use the VMSAv9-128 translation regime on ARMv9.3 hardware.
By kexecJohn Garry’s v6 series groups ALUA-capable paths into multipath-aware SCSI disks with in-kernel failover and I/O policies.
By kexecThe SSHM chairs met an unanswered objection to solo post-quantum signatures with moderation threats instead of discussion. D. J. Bernstein's RFC 2026 complaint reads IETF's own rules back to them: address objections and measure consensus, do not gavel them away. The call for adoption closes 17 August.
By staffAnthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.
By nonce