🖥️ Distribuzioni Linux (ultime 48–72h)
- KaOS 2026.06 — ISO completamente Dinit-based Citazione: “a first stable ISO image that is fully Dinit-based… A move away from systemd as init system is completed.” Stack: Dinit + turnstile + seatd; Plasma non incluso nell’ISO.
- SteamOS 3.8.10 — aggiornamento Arch base, supporto Steam Machine Citazione: “SteamOS 3.8.10 has just been released… updated Arch system base; initial support for upcoming Steam Machine hardware…”
- PorteuX 2.7 — Plasma 6.7, GNOME 50.2, ntfs-plus Citazione: “ntfs3 kernel driver… updated to the new ntfs-plus driver… GCC 16.1.0, FFmpeg 8.1.1, KDE Plasma 6.7.0, GNOME 50.2…”
- Home Assistant OS 18.0 — kernel 6.18, Docker 29.5.3 Citazione: “kernel updated from 6.12 to 6.18… Docker upgraded to v29.5.3…”
🛡️ Patch CVE (ultime 48–72h)
- GhostLock CVE‑2026‑43499 — privilege escalation kernel Citazione: “AlmaLinux has released emergency patches to address the GhostLock privilege escalation bug (CVE‑2026‑43499)… Fedora pushing kernel 7.1.3 rebases…” Impatto: AlmaLinux 8/9/10, RHEL 7–10, Debian/Ubuntu tramite advisories coordinati.
- Januscape — memory corruption storica Citazione: “Januscape memory corruption flaw.”
- CVE‑2026‑23111 — bug “di un solo carattere” in nf_tables Citazione: “CVE‑2026‑23111… un singolo carattere, il simbolo !, cambia il comportamento atteso del codice e apre la strada a un use‑after‑free nel kernel.” Rilevanza: host container, VPS, CI/CD.
- Bad Epoll CVE‑2026‑46242 — accesso root su Linux/Android Citazione: “Bad Epoll… consente a un utente locale privo di privilegi di ottenere l’accesso root… race condition… proof‑of‑concept con tasso di successo ~99%.” Kernel vulnerabili: 6.4+ non ancora patchati upstream.
- Avviso BSI WID‑SEC‑2026‑2077 — multiple kernel flaws Citazione: “diverse vulnerabilità nel kernel Linux… rischio elevato CVSS 8.6… UAF, heap overflow, race conditions…” Raccomandazioni: aggiornare Ubuntu 22.04→24.04, Debian 11→12, RHEL 8→9, SLES 15 SP5→SP6.
🧬 Kernel mainline (stato al 20 luglio 2026)
- Linux 7.2‑rc2 — limite core RISC‑V 64→256, hardening BPF Citazione: “increase RISC‑V core limit… reinforced against BPF JIT spraying.”
- Wayland 1.26 — nuove primitive per puntatore e socket Citazione: “Wayland 1.26 aggiorna puntatore, rimozione dei global, gestione dei socket…”
- Rust nel kernel — riduzione vulnerabilità , driver futuri solo in Rust Citazione: “Rust… could have prevented almost 80% of vulnerabilities… driver subsystem will accept only Rust drivers.”
- IA nel processo di revisione patch Citazione: “Torvalds considera l’IA uno strumento… Sashiko segnala bug nelle patch attraverso commenti…”
🇮🇹 Eventi italiani software libero
Nessun evento italiano nelle ultime 48h nei documenti caricati (FSF, FSFE, Linux.it). Eventi europei rilevanti per la comunitĂ italiana:
- OpenSouthCode 2026 — Málaga, 26–27 giugno Citazione: “Join the FSFE at the OpenSouthCode 2026 in Málaga, Spain.”
- FSFE Berlin Local Group — 9 luglio Citazione: “FSFE local meeting in Berlin… 9 July 2026.”
Rubrica