11 hónap 4 hét óta
The
OpenBSD
7.6 release cycle is entering its final phases…
With the following
commit,
Theo de Raadt (deraadt@) moved -current to version 7.6:
CVSROOT: /cvs
Module name: src
Changes by: deraadt@cvs.openbsd.org 2024/09/17 07:39:17
Modified files:
sys/conf : newvers.sh
Log message:
head into release
For those unfamiliar with the process:
this is not the 7.6 release,
but is part of the standard build-up to the release.
Remember: It's time to start using
"-D snap" with
pkg_add(1)
(and
pkg_info(1)).
(Regular readers will know what comes next…)
This serves as an excellent reminder to upgrade snapshots frequently,
test both base and ports, and
report
problems [plus, of course,
donate!].
11 hónap 4 hét óta
Four researchers have published a formal proof that Linux's new deterministic random bit generator (DRBG) is secure in a particular sense — specifically, that the number of queries that would need to be made to it to uncover its internal state depends on the quality of the entropy it can collect from different sources. As long as it can gather enough entropy, it produces secure random numbers.
Since the significant structural changes in Linux 4 and Linux 5.17, there has
been no research on the provable security of Linux-DRBG. For the first time (to
the best of our knowledge), we formally model the Linux-DRBG in Linux 6.4.8
and prove its security in the seedless robustness model
Thanks to Jason Donenfeld for bringing the paper to our attention.
daroc
11 hónap 4 hét óta
Security updates have been issued by Debian (php-twig and pymongo), Fedora (linux-firmware, microcode_ctl, and python3.13), Mageia (clamav, microcode, postgresql13 and postgresql15, python3-webob, suricata, tcpreplay, tgt, and wireshark), Oracle (httpd, kernel, and linux-kernel), Red Hat (firefox, kernel, kernel-rt, pcs, and thunderbird), SUSE (389-ds, chromium, golang-github-prometheus-prometheus, htmldoc, kernel, SUSE Manager Client Tools, and wireshark), and Ubuntu (clamav, curl, dcmtk, dovecot, nginx, openssh, and python3.10, python3.12, python3.8).
daroc
11 hónap 4 hét óta
Version 8.0.0 of
the Valkey open-source in-memory data
store is now available. This is the first major release of Valkey
since the project forked from Redis in March of this year:
While this is a major version, Valkey takes command set compatibility
seriously: Valkey 8.0.0 makes no backwards incompatible changes to the
existing command syntax or their responses. Your existing tools and
custom software will be able to immediately take advantage of Valkey
8.0.0. Since Valkey 8.0.0 does make some small changes to previously
undefined behaviors, it's wise to
read
the release notes. Additionally, because this version makes changes in how the
software uses threading, you may want to re-evaluate your cluster's
infrastructure to achieve the highest performance.
jzb