Posts
484
Following
100
Followers
5027
@akendo Eventually, yes, but based on the patches being submitted upstream, not anytime soon...
0
0
0
@oldhomemovie These are all already in released kernels, so it's "just" a re-review that's happening for the backport to the older kernel release branches.
0
0
2
Edited yesterday

This might be a “record” for stable kernel -rc releases. Not really a record I want to ever beat…

     version  queued
	5.10:	 798
	5.15:	 935
	6.1:	1191
	6.6:	1424
	6.12:	1376
	6.18:	1518
	7.2:	1815
	total:	9057
3
3
22
repeated

The September 11 CRA reporting milestone is here.

Our new community guide explains manufacturers’ reporting obligations and how open source maintainers and stewards can prepare for collaboration when vulnerabilities affect downstream products.

https://openssf.org/blog/2026/09/11/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers/

0
1
0
repeated

Open Call for Nominations: European Open Source Awards 2027

Please consider taking a minute and tell us who we should recognize and honor this time around! We need to know about the heroes to be able to celebrate them.

https://awards.europeanopensource.academy/nomination-process

1
6
0

@jeroen

What are the 4 square transparent thingies below the big keychron smash button?

Framework laptop connectors (USB-C -> USB-C ones)

And I never remember what button does what just yet, need to come up with a color scheme…

0
0
0
@Aissen @fj For those of us in the "Find software vulnerabilities in this code" business, we've known and seen this happen for a very long time (and we keep telling everyone this every chance we get.)

Glad to see other people/groups/companies also realizing that anything you send to an external site, should be considered public at that point in time.
0
0
2
@libewa @bagder @janne For CVEs, no, the numbers do not show that at all, it's 5.15 that is the "highlight". But note we didn't really start tracking CVEs until 2024, so historical data is going to be hard to compare properly.
0
0
1
I can't resist keyboards in "odd" formats...
3
3
39
@tris @torvalds You do you, there's nothing wrong with getting a pre-built PC if you like that, but some of us want to make different things (or what we want just doesn't come "pre-built").
1
0
1
@bagder @janne Hey, "red" is bad, but in this case, it should be "good" in that we are fixing lots of old debt here. It's not like we are adding more buggy code, as the "where was the CVE introduced" numbers show.
But it's your graph, you pick whatever color you want :)
2
0
9
@bagder @janne I can give you raw numbers if you want as well, so you can use it in your own graphing tools, I'll email them to you...
2
0
3
For anyone "worried" that the CRA was going to cause some reporting requirements as of September 11, 2027, the EU has answered that question and updated their FAQ with in section 5.5 that says we only have to start reporting in December 2027:
https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-implementation-frequently-asked-questions
So while many of us were ready to start the reporting process, it is good that we have a bit more time for the tools and infrastructure to get solid before we have to start using it.
2
7
21
repeated

Thorsten Leemhuis (acct. 1/4)

7.1 is now unsupported upstream – @gregkh just announced that while releasing 7.1.13 and a bunch of other new stable and longterm releases:

""Note, the 7.1.y kernel series is now end-of-life. Please move to the 7.2.y kernel series at this point in time.""

https://lore.kernel.org/all/2026090223-botanical-purging-2933@gregkh/

0
2
1
repeated

v262~rc1 is out! If you don't help testing it out, YOUR favourite third party service will be next on the takeover list

https://github.com/systemd/systemd/releases#release-v262-rc1

1
5
0
repeated
@aho ctrl-a is not a valid keystroke in my mutt config....
1
0
0
@kasperd @icing It's a mix, some are fixing an issue that a user has with a specific hardware device, others fix for hardware that is coming soon, but the huge majority right now is static analysis tools that are finding really old minor things that can be triggered if you "hold it wrong". Those are vulnerabilities at our level.

We also had a rash of syzbot found things recently as they updated their tooling to go "one layer deeper" for many USB gadget and devices, so that's just "normal" fuzzers doing their good work that they have been doing for a long long time.

We don't care "if it's exploitable", that's impossible to determine, and kind of pointless for us to worry about most of the time. See my many talks on that very topic if you are curious (also my blog posts about CVE kernel stuff, which cover it as well.)
0
0
1
@ljs Good, then you can keep the maintainers endlessy busy :)
0
0
0
Show older