Reading view

Linux Developers Consider Retiring The x32 ABI

The Linux kernel mailing list has a new patch proposing the retirement of the x32 ABI, reports Phoronix: The Linux x32 ABI for x86_64 processors allow making use of the full 64-bit register file and wide data path but retaining 32-bit pointers to provide for a smaller memory footprint when not needing 64-bit pointers. Linux x32 came to the party late and didn't enjoy much adoption over the years and is now looking at possible removal from the Linux kernel. The x32 code was a nice concept for helping lower memory footprint requirements while otherwise making use of the x86_64 capabilities, but with its limited adoption and x86_64 simply being the de facto standard these days, Linux kernel developers are looking at phasing out the x32 ABI. The x32 ABI was added in Linux 3.4 back in 2012 plus also required updated compiler support too. The proposed patch argues "there is practically no real use for x32," noting that some Linux vendors (like Debian) already disable x32 by default to reduce attack surfaces. "Should nothing happen within the next half year, lets remove code bits around August after the summer break." Discussions about dropping x32 support first started in 2018...

Read more of this story at Slashdot.

  •  

Yearslong fight over users' right to tweak smart TV software heads to trial

For years, owners of Vizio smart TVs have had little control over the software running on their sets—software that can track viewing habits, push ads, and generally shape the experience of using the device.

The Software Freedom Conservancy (SFC), a US nonprofit that promotes and provides legal support for free and open source software projects, isn't happy about that—so much so that it has spent eight years trying to force the release of the complete source code for Vizio's Linux-based smart TV operating system.

Now, after numerous delays since the SFC filed suit in 2021, a California jury will decide in August whether Vizio must provide that code in executable form to SFC and any Vizio TV owner who wants it.

Read full article

Comments

© Aurich Lawson | Getty Images

  •  

Yearslong fight over users' right to tweak smart TV software heads to trial

For years, owners of Vizio smart TVs have had little control over the software running on their sets—software that can track viewing habits, push ads, and generally shape the experience of using the device.

The Software Freedom Conservancy (SFC), a US nonprofit that promotes and provides legal support for free and open source software projects, isn't happy about that—so much so that it has spent eight years trying to force the release of the complete source code for Vizio's Linux-based smart TV operating system.

Now, after numerous delays since the SFC filed suit in 2021, a California jury will decide in August whether Vizio must provide that code in executable form to SFC and any Vizio TV owner who wants it.

Read full article

Comments

© Aurich Lawson | Getty Images

  •  

Linux bitten by second severe vulnerability in as many weeks

Linux users have been bitten by yet another vulnerability that gives containers and untrusted users the ability to gain root access, marking the second time in as many weeks that a severe threat has caught defenders off guard.

The threat, known as Dirty Frag, allows low-privilege users, including those using virtual machines, to gain root control of servers. Attacks are particularly suitable in shared environments, where a server is used by multiple parties. Hackers can also gain root as long as they have access to a separate exploit that gives a toehold into a machine. Exploit code was leaked online three days ago and works reliably across virtually all Linux distributions. Microsoft has said it has spotted signs that hackers are experimenting with Dirty Frag in the wild.

Immediate and significant threat

The leaked exploit is deterministic, meaning it works precisely the same way each time it’s run and across different Linux distributions. It causes no crashes, making it stealthy to run. A vulnerability known as Copy Fail, disclosed last week with no patches available to end users, possesses the same characteristics.

Read full article

Comments

© Getty Images

  •  
❌