[-] KarnaSubarna@lemmy.ml 2 points 2 hours ago

Make it publicly available to the world or just for you (and people you know)?

60
145
submitted 2 days ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml

GNOME Boxes lead developer Felipe Borges has been overhauling the application with a major rewrite and today announced the new beta release. GNOME Boxes has migrated to using the GTK4 toolkit and libadwaita. The new GNOME Boxes code can also handle installing Microsoft Windows 11 now without needing any manual workarounds for Secure Boot or TPM requirements.

The new GNOME Boxes code also introduces a VSOCK device for accessing VM contexts and other improvements. With the revamped GNOME Boxes, it's also shifting to a Flatpak-first and only model for distributing of new GNOME Boxes releases.

195
submitted 5 days ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
231
submitted 1 week ago by KarnaSubarna@lemmy.ml to c/world@lemmy.world
11
submitted 2 weeks ago by KarnaSubarna@lemmy.ml to c/ubuntu@lemmy.ml

Fixes are available for 3 vulnerabilities reported in snapd, each with assigned CVE IDs and CVSS scores.

  • CVE-2026-8933, discovered by Qualys, allows local attackers to escalate privileges. It impacts default installations of Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. The CVSS 3.1 score assigned to the vulnerability is 7.8 (high).
  • CVE-2026-15226, discovered by Zygmunt Krynicki, Canonical team member, allows local attackers to escape snap confinement from confined root to unconfined root. The CVSS 3.1 score assigned to the vulnerability is 8.4 (high).
  • CVE-2024-5300 discovered by James Henstridge, Canonical team member, allows a sandboxed application to access hashed user passwords. This vulnerability impacts installations of Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS Ubuntu, 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS where systemd-userdbd is available. The CVSS 3.1 score assigned to the vulnerability is 5.6 (medium).

Affected releases

The following table lists the affected snaps. Revisions with patches will be updated as they are released.

Snap name Channel Remediation status
snapd latest/stable pending (2.76.1) publication
snapd fips-updates/stable not planned
core latest/stable pending

The snapd package distributed via the Ubuntu archive is also affected in the following releases. Fixes have been released as security updates.

Release Package Name Fixed Version
Xenial (16.04) snapd 2.61.4ubuntu0.16.04.1+esm4
Bionic (18.04) snapd 2.61.4ubuntu0.18.04.1+esm4
Focal (20.04) snapd 2.67.1+20.04ubuntu1~esm3
Jammy (22.04) snapd 2.76+ubuntu22.04.1
Noble (24.04) snapd 2.76+ubuntu24.04.1
Resolute (26.04) snapd 2.76+ubuntu26.04.3
11
submitted 2 weeks ago by KarnaSubarna@lemmy.ml to c/science@lemmy.ml

While carbonaceous chondrites make up only a small portion of the meteorites sampled on Earth, CO chondrites make up a very tiny fraction of those meteorites. According to the study, these types of meteorites are among the most pristine materials in our Solar System.

According to the study, the Cretaceous-Paleogene impactor was about six to nine miles wide and created a massive crater in the Yucatán Peninsula in Mexico. It was eventually named the Chicxulub crater.

“Being impacted by such a rare, distant projectile really underscores how unlucky the dinosaurs were,” Claeys said.

138

24
submitted 1 month ago by KarnaSubarna@lemmy.ml to c/firefox@lemmy.ml

As an exciting development for GPU-accelerated video decoding within the Mozilla Firefox web browser, initial support for Vulkan Video has landed in the web browser!

Firefox on Linux has long been focused on the Video Acceleration API (VA-API) that isn't universally supported by Linux graphics drivers. This has left to efforts like NVIDIA-VAAPI-Driver to layer VA-API atop NVIDIA NVDEC interfaces to enjoy GPU-accelerated video playback in Firefox. Smaller Arm/embedded graphics drivers also have been largely left out of the game in the VA-API space. But with Vulkan Video we are beginning to see more adoption and in a cross-platform manner.

The Firefox 153 release due out in July will have Vulkan Video decoding support available. The Vulkan Video activity in Firefox Git culminated this week with the work of NVIDIA engineer Tymur Boiko and Red Hat's Martin Stransky.

37
submitted 4 months ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml

First up with Flatpak 1.16.4 is a fix for CVE-2026-34078, which is a security issue allowing a complete sandbox escape leading to host file access and code execution in the host context. Ouch. The issue is due to Flatpak portal accepting paths in the sandbox-expose options that can be app-controlled symlinks pointing at arbitrary paths. Due to this apps can access all host files and can be used as a primitive for gaining code execution in the host context. Disabling Flatpak Portal is another way to workaround this issue but can cause app problems.

CVE-2026-34079 is also fixed and is for preventing arbitrary file deletion on the host file-system. CVE-2026-34079 stems from caching for ld.so removing outdated cache files without checking that the app controlled path to the outdated cache is in the cache directory.

[-] KarnaSubarna@lemmy.ml 37 points 4 months ago
  • Trump will again chicken out.
  • He thought (or made to believe) Regime change in Iran will a walk in the park.
  • Given the situation he is currently in, he just wants to save his face by any mean.
  • Dropping Nuke is biggest threat he can think of.
  • He don’t have the guts to follow it through.
  • He will just extend the deadline, or declare himself a winner and left Middle East to its fate.
300
submitted 4 months ago by KarnaSubarna@lemmy.ml to c/world@lemmy.world
22
submitted 4 months ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml

How to check if you are impacted

To get the version of the sudo package installed, run the following command:

dpkg -l 'sudo*' | grep ^ii

The following table lists the fixed versions of the sudo package in all supported Ubuntu releases:

Release Package Fixed version
Questing Quokka (25.10) sudo 1.9.17p2-1ubuntu1.1
sudo-ldap 1.9.17p2-1ubuntu1.1
sudo-rs Not affected
Noble Numbat (24.04 LTS) sudo 1.9.15p5-3ubuntu5.24.04.2
sudo-ldap 1.9.15p5-3ubuntu5.24.04.2
Jammy Jellyfish (22.04 LTS) sudo 1.9.9-1ubuntu2.6
sudo-ldap 1.9.9-1ubuntu2.6
Focal Fossa (20.04 LTS) sudo Not affected
sudo-ldap Not affected
Bionic Beaver (18.04 LTS) sudo Not affected
sudo-ldap Not affected
Xenial Xerus (16.05 LTS) sudo Not affected
sudo-ldap Not affected
Trusty Tahr (14.04 LTS) sudo Not affected
sudo-ldap Not affected

Affected sudo versions

How to address

We recommend you upgrade all packages:

sudo apt update && sudo apt upgrade

If this is not possible, the sudo userspace mitigations can be installed directly and does not require a reboot to apply:

sudo apt update
sudo apt install sudo

The unattended-upgrades feature is enabled by default for Ubuntu Xenial Xerus (16.04 LTS) onwards. This service:  

  • Applies new security updates every 24 hours automatically.
  • If you have this enabled, the patches above will be automatically applied within 24 hours of being available.
24

[-] KarnaSubarna@lemmy.ml 41 points 6 months ago

Linux offers near-endless customisation and Kernel is also open sourced for any kind of (performance) tweaks.

Moreover, Linux is, by design, better suited to be a server OS than desktop OS.

These are the same reasons why most of the web servers across world runs on Linux based distros.

[-] KarnaSubarna@lemmy.ml 45 points 2 years ago* (last edited 2 years ago)

In India, the share of Linux desktop became double just within one year (from 8% to 16%). I only hope this data is right.

https://gs.statcounter.com/os-market-share/desktop/india/#monthly-202301-202407

[-] KarnaSubarna@lemmy.ml 39 points 2 years ago

I moved to Mozilla Thunderbird long ago https://www.thunderbird.net/en-US/

[-] KarnaSubarna@lemmy.ml 43 points 2 years ago

UX is a very subjective matter.

[-] KarnaSubarna@lemmy.ml 53 points 2 years ago

Bad news is that it is not clear at this point whether Mozilla is going to go forward with the implementation. A post on Reddit by one of the project members suggests that the build is a "rough proof-of-concept". Some features tested in the build "did not survive". It is unclear which did not, as they are not mentioned. Mozilla is, however, implementing those that survived the cut into Firefox. Again, the poster does not mention which those are. It is also not verified that the poster is actually a member of the project team, so take this with a grain of salt as well.

[-] KarnaSubarna@lemmy.ml 122 points 2 years ago
  • Careful choice of program to infect the whole Linux ecosystem
  • Time it took to gain trust
  • Level of sophistication in introducing backdoor in open source product

All of these are signs of persistent threat actors aka State sponsor hacker. Though the real motive we would never know as it's now a failed project.

[-] KarnaSubarna@lemmy.ml 48 points 2 years ago* (last edited 2 years ago)

There is a work-in-progress version of Firefox for iOS with Gecko engine.

But, there is also a challenge that Mozilla is facing as Apple is still trying to make life of developers of other browsers as difficult as possible.

So, not sure how the whole thing will turn out.

view more: next ›

KarnaSubarna

0 post score
0 comment score
joined 2 years ago