A new implementation within Linux containers removes several powerful capabilities, including audit controls, suspend prevention, and file system access, by modifying capability sets in a concise codebase. These changes aim to restrict container privileges and enhance security.
blog.lizzie.io
· 2026-10-05
FTL is an operating system design in which each container runs a userspace library implementing core OS functions like Linux process management, a virtual file system, and TCP/IP. A minimal FTL kernel provides the underlying interface for these userspace components to implement Linux system calls, similar to how a hypervisor operates.
ftl-os.org
· 2026-10-03
GrapheneOS says Android 17 QPR1, released for Pixels on September 15, contains a regression in the Pixel kernel driver tree that causes stuttering, lag and freezes under memory pressure, severe enough to trigger process kills. GrapheneOS inherited the bug through its firmware/driver updates but says it has shipped a fix in today's release, linking the kernel commit on GitLab.
discuss.grapheneos.org
· 2026-10-02
Debian's security team published advisory DSA-6528-1, addressing nearly 90 CVEs discovered in the Linux kernel. The advisory, issued by Salvatore Bonaccorso, lists vulnerabilities spanning multiple kernel subsystems and recommends users update their systems to the patched packages.
lwn.net
· 2026-10-01
Developer Matt Keeter has published Halfspace, an experimental IDE for solid modeling using distance fields, along with a browser-based WebGPU demo. The app serves as a showcase for his Fidget kernel, which handles rasterization and meshing, letting users view real-time renders and export models as images or triangle meshes.
mattkeeter.com
· 2026-09-30
A developer known as ntfargo has published a new PS5 jailbreak called Relapse, covering firmware versions 7.00 through 13.60. The exploit uses a browser-based WebKit stage combined with a kernel-level flaw to gain read/write access, and is delivered either via a local Python server or a hosted webpage. The release credits a large group of contributors and includes a disclaimer limiting its stated use to educational and security research purposes.
github.com
· 2026-09-29
Security researchers at VUsec and Scuola Superiore Sant'Anna developed a new Spectre v2 attack called Branch Target Reuse (BTR), which exploits stale branch predictor data left behind when JIT engines reuse memory addresses for new code. Tested against Firefox's SpiderMonkey, GraalVM, and the Linux kernel's cBPF, the attack can extract a system's root password hash within minutes on Intel processors. The flaws were assigned CVE-2026-64507 and CVE-2026-64508, and fixes have already been merged into the Linux kernel.
bleepingcomputer.com
· 2026-09-29
Phoronix's Michael Larabel reports that a clean x86-64 defconfig Linux kernel build now takes about 15 seconds on his dual AMD EPYC 9575F workstation, down from over 22 seconds before recent Kbuild patches. The speedup stems from work by Linux memory-management developer Lorenzo Stoakes, who used AI/LLM assistance to remove compilation bottlenecks, alongside continued hardware gains.
tomshardware.com
· 2026-09-27
Canonical says it is switching to a unified two-week release cycle for security updates, citing a surge in CVE reports driven partly by AI-assisted vulnerability discovery and the Linux kernel team's decision to become its own CVE Numbering Authority. The company says it will offer interim workarounds or hardening guidance within 24 to 48 hours of disclosure while full patches are prepared.
news.slashdot.org
· 2026-09-26
Criminals in Portugal, France and Germany have been mailing counterfeit credit cards and letters warning recipients that their card is expiring, urging them to scan a QR code to "activate" a replacement. The code leads to a fraudulent banking site that harvests login credentials, giving attackers access to victims' real accounts. Some fake cards even bear the recipient's actual name to increase credibility, according to digital banking advisor Georg Hauer.
wired.com
· 2026-09-26
Researchers identified a double-fetch flaw in Avast's kernel driver that can lead to a pool overflow, potentially allowing code execution outside the antivirus sandbox. The flaw involves multiple reads of the same user-supplied data, which can be manipulated between fetches. Recent Windows updates mitigate this issue by enforcing user-mode access checks, reducing the exploit's viability.
safateam.com
· 2026-09-25
AMD has submitted patches to its open-source Linux kernel driver adding GDDR7 memory identification along with new IP blocks including IH 8.0 and NBIF 7.10, according to Phoronix. Current Radeon RX 9000-series cards use GDDR6, making this the clearest driver-level sign yet of preparation for a next-generation GPU architecture, widely expected to be RDNA 5.
tomshardware.com
· 2026-09-23