The solo maintainer for libxml2 is no longer accepting embargoed vulnerability reports, citing the unsustainable burden as an unpaid volunteer. Security issues will be treated like any other bug report moving forward.
https://socket.dev/blog/libxml2-maintainer-ends-embargoed-vulnerability-reports #opensource #cybersecurity h/t @joshbressers
Reporting a „possible memory leak“ in a 7 year old curl version, because the RSS jumps from 6.2 to 7 MB once.
Could be.
But, dear reporter, we can only try our best to be a better curl *today*. There is no changing the past (hence the name).
We outstretch our hands to you! Come and live with us in the present! Let the ancestors rest and rejoyce among the living!
Ticket sales for Kernel Recipes 2025 are now open! The conference will take place from September 22 to 24, 2025, in Paris. The agenda is still in the works, but you can already check out the list of speakers and a few of the topics online.
https://kernel-recipes.org/en/2025/
If you're a student, we’re offering a 50% discount—just get in touch with us!
See you in september!
A bunch of new stable kernels is out. With them, the #Linux 6.14.y stable series is now end-of-life – shortly after the merge window of 6.16 closed.
This thus happened a bit earlier than we are used to, but will be the new normal. To quote @gregkh from https://lore.kernel.org/all/2025061030-latticed-capacity-dc94@gregkh/:
'"Note this is the LAST 6.14.y release. This kernel branch is now end-of-life. Please move to the 6.15.y kernel branch at this time.
If you notice, this has happened a bit more "early" than previous end-of-life announcements. Normally, after -rc1 is out there is a TON of stable patches happening due to the changes that come into the merge-window that were marked for stable backports but didn't get into Linus's release before -final. As some people have objected to this large influx being added to a stable kernel that is just about to go end-of-life, let's try marking this end-of-life a bit earlier to see how it goes.
It might also spur maintainers/developers to get fixes into -final a bit more as well :)"'
Q: "Why have you suddenly been reworking coredumping, Christian?"
A: "Because I'm a clown and also I had it with all the CVEs because we provide a **** API for userspace."
So now that @torvalds merged the pidfs and initial coredump work things are already better but I have more work there.
In other news, there's two new CVEs in userpace that should be gone completely by installing a pidfd into the umh or by using the coredump socket.
[1]: https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt
ER2025 is over, and thanks to all of our sponsors it was a big success!
https://embedded-recipes.org/2025/blog/wrap/
The slides & videos are now available on the Speakers page
of the website: https://embedded-recipes.org/2025/speakers/
Please don’t hesitate to send us your feedback, critiques,
suggestions and rants. We’d want to hear what you thought of the
location, the venue, the food, the talks, the workshops, the evening
event, or anything else you want to share with us.
Please write us at: embedded-recipes@baylibre.com
This is a great interview with @gregkh on corporate involvement in the #Linux kernel and #opensource. He goes in depth on justifying working upstream and how it made him a better engineer.
#LLMs are not a knowledge base!
Stop spreading misinformation!
They are statistical models that _simulate_ knowledge!
We, as a #society, really have to pay attention to the words and #language we're using.
But I guess, when talking about LLMs, details are not really important, are they!? Oh, such beautiful irony!
"If all these big companies are shouting from the rooftops that AI is up to production code the money relies on, then zero open source contributions of substance is a glaring absence."
(Original title: If AI is so good at coding … where are the open source contributions?)
@embeddedrecipes has just kicked off!
New organizers are running the show this year — big thanks to BayLibre for picking up the torch and keeping the spirit of Recipes alive: small-scale, sharing, and real exchange.
You can follow the conference live!
The 2025 edition of @embeddedrecipes starts with @gregkh
https://www.youtube.com/live/U5L8XHkP-lI?si=h5-X2I97Rnb1hey8
#er2025 #embeddedrecipes
Long but cheering+ practical from @bert_hubert
https://berthub.eu/articles/posts/a-coherent-non-us-cloud-strategy/
"Europe has ample compute capacity and skills.... the carrot won’t be enough to make Europe sovereign again. We must have our own technology under our own control, but we must also make sure that it gets used"
Psst, hey: HACKERS ARE NOT TECH BROS. The vast majority of hackers never become tech bros. The ethics of hacking runs completely counter to that of tech bros.
Hackers make hardware do things they weren’t intended to do. They circumvent barriers. They string together contraptions that repurpose old stuff to do new things. Hackers aren’t that interested in money; they’re more interested in showing off their skills. They love to learn and make demos and create and share free tech that other hackers then build upon. All they want is acknoweledgement and the respect of their peers.
Tech bros are parasites. They’re greedy bastards who love to erect barriers between people and tech. They extract, addict, monetize. They turn everything fun and useful into a transaction, a dopamine trap, a subscription, a surveillance tool, an advertising outlet, and a vector to extract money from labor and suppliers.
Please don’t get them mixed up.
This ordinary Tuesday? Two. Two AI slop security reports arrived to #curl. So far.