Salta al contenuto principale

📰 Software Libero Today Rassegna quotidiana – 21 luglio 2026

Inviato da tuxsa il
news

🖥️ Distribuzioni Linux

  • KaOS 2026.06 — ISO completamente Dinit-based Citazione: “a first stable ISO image that is fully Dinit-based… A move away from systemd as init system is completed.” Stack: Dinit + turnstile + seatd; systemd ridotto a udev/tmpfiles.
  • SteamOS 3.8.10 — aggiornamento Arch-based Miglioramenti: supporto iniziale Steam Machine, wake-from-sleep via Steam Controller, update piĂą rapidi, fix per trackpad e dropdown menu nei giochi.
  • PorteuX 2.7 — grande aggiornamento multipiattaforma NovitĂ : ntfs-plus driver, GCC 16.1, FFmpeg 8.1.1, Plasma 6.7, GNOME 50.2, Qt 6.11.1, build pipeline migliorata.
  • Home Assistant OS 18.0 — major release Kernel 6.18, Docker 29.5.3, Buildroot 2025.02.14, swap size migliorato, firmware Raspberry Pi aggiornabile da HAOS.
 

🛡️ Patch CVE

  • Ondata straordinaria: 440 CVE pubblicate in 24 ore Il kernel ha emesso 431 advisory il 19 luglio e altri 9 il 20 luglio. Tutte giĂ  patchate nei rami stabili. Citazione: “the kernel project updated its security advisory pages with 431 new CVE identifiers… the next day… nine more, bringing the batch to 440.”
  • CVE critiche da monitorare
    • CVE‑2026‑53362 — variante “frag”, possibile privilege escalation/container escape.
    • CVE‑2026‑53383 — ksmbd, out‑of‑bounds read.
    • CVE‑2026‑63801 — TIPC use‑after‑free.
    • CVE‑2026‑63794 — overflow KVM/SEV.
  • GhostLock & Januscape (vulnerabilitĂ  storiche, 15–16 anni)
    • GhostLock (CVE‑2026‑43499) — futex PI, escalation privilegi.
    • Januscape (CVE‑2026‑53359) — KVM shadow MMU, fuga dalla VM verso l’host. Citazione: “CVE‑2026‑53359… un errore nella gestione della memoria… compromette il sistema host.”
 

🧬 Kernel mainline

  • Linux 7.2‑rc2
    • Limite core RISC‑V portato da 64 → 256.
    • Rafforzamento contro BPF JIT spraying.
    • Pulizia mod_devicetable.h per ridurre overhead di ricompilazione. Citazione: “the default RISC‑V core limit… increased from 64 to 256… reinforced against BPF JIT spraying.”
  • Contesto CVE 2026 Il kernel è il progetto con piĂą CVE segnalate nel semestre — segno di trasparenza, non di insicurezza. Citazione: “Il kernel Linux risulta in testa con 2.308 CVE… un segnale di trasparenza e maturitĂ .”
 

🔍 Extra: Notizie minori della settimana

  • DXVK 3.0.2 — fix per vari giochi, nuove opzioni debug.
  • Perl 5.44 — Unicode 17.0, nuove feature, fix CVE.
  • FSearch 0.3 — prima release dopo 3 anni, miglioramenti inotify/fanotify.