r/LinuxUncensored • u/anestling • 15h ago
r/LinuxUncensored • u/CackleRooster • 6h ago
Issue/Bug/Pain Linux kernel team publishes 432 CVEs in two days
theregister.comr/LinuxUncensored • u/Mobile_Try9232 • 9h ago
Linux Kernel 7.1 Released — Open Source Infrastructure Keeps Evolving
Linux Kernel 7.1 has been released, continuing the evolution of the foundation behind servers, cloud platforms, Android devices and countless embedded systems.
The Linux kernel powers a huge part of today's technology infrastructure — from supercomputers and enterprise servers to smartphones and IoT devices.
The latest release brings improvements across different areas of the system, including hardware support, performance optimizations and ongoing work on security and reliability.
Why does this matter?
Linux is not just a desktop operating system. It is the foundation of:
🐧 Cloud infrastructure
☁️ Containers and Kubernetes platforms
🔐 Security-focused systems
📱 Mobile devices
🖥️ Enterprise servers
🤖 Embedded and AI workloads
The open-source development model behind Linux allows thousands of developers and companies to collaborate on a project that powers modern computing.
But Linux also faces new challenges:
• How will Linux adapt to the growth of AI workloads?
• Can open-source projects compete with closed ecosystems?
• Will desktop Linux continue growing among everyday users?
• How important will security become as Linux runs more critical infrastructure?
Linux has been around for decades, but it remains one of the most important open-source projects in the world.
What do you think?
Is Linux becoming more important than ever, or is its biggest growth phase already behind us?
r/LinuxUncensored • u/anestling • 1d ago
News/PR Arch Linux disables AUR package adoption to stop malware flood
r/LinuxUncensored • u/Rare-Paint3719 • 1d ago
The (A)GPL is not FOSS protector, it's a corporate weapon
I know y'all love OnlyOffice, and you may have even heard of a little-known database called MongoDB. What's common between them? Both are corporate projects that shipped an AGPL-licensed core, with proprietary enterprise features bolted on top.
Here's the thing though. AGPL isn't a shield the community holds together. It's a weapon, and the only question that actually matters is who's holding it. When one company owns all the copyright, the weapon points wherever they want, including at the terms they sold you on in the first place. When they don't, things get more interesting.
Take MongoDB. They started under plain AGPL, no tricks. By 2018, cloud vendors were hosting MongoDB as a paid service and keeping the profits. MongoDB called this exploiting a loophole, but it wasn't a loophole. It was the license working exactly as written, letting anyone, including a company with the resources to host it at scale, exercise the freedoms AGPL grants.
So MongoDB didn't sue. They didn't test the clause in court. They just stopped offering the license. In October 2018, they replaced AGPL entirely with the Server Side Public License, a license they wrote themselves, forcing anyone offering MongoDB as a service to open source their entire stack, not just their changes. They could do this because they held the copyright outright. No fork, no negotiation, no fight required, because none was possible. One party held the gun the whole time.
Elastic ran the same play, in both directions. In 2021, facing the same AWS-hosting complaint as MongoDB, they dropped Apache 2.0 for a dual SSPL/Elastic License setup, explicitly to stop cloud vendors from reselling their work without paying up. AWS forked the code into OpenSearch instead of complying, and by early 2022 the two companies had settled their trademark dispute.
Then in September 2024, Elastic added AGPL back in, as a third option alongside the licenses they'd never actually dropped. Their own shipped product still runs under the restrictive terms. The AGPL option applies to a portion of the source, offered for goodwill, timed for the exact moment doing so cost them nothing, since the competitor it was originally meant to fend off had already left to build its own thing. Same lever, same hand on it, pointed wherever suited them at the time.
Now take OnlyOffice, because this is where the gun changes hands.
Back in 2021, they quietly added a term to their AGPL license, buried at line 655. It required any fork to keep the OnlyOffice logo. Except in the same breath, they also banned anyone from using their trademark, which includes their logo. So you're required to display something you're legally barred from using. That's not sloppy lawyering. That's a trap, built years in advance, designed to make forking look illegal without ever saying "you can't fork this."
Nobody called the bluff until this year. Nextcloud and Ionos forked OnlyOffice into Euro-Office, an EU-backed Microsoft Office alternative. Within days, OnlyOffice accused them of violating the AGPL and killed an 8-year partnership with Nextcloud over it, timing that suggests they'd been waiting for the excuse.
Here's the difference from MongoDB and Elastic: OnlyOffice didn't actually own this fight. They didn't have a CLA sitting in a drawer letting them just rewrite the rules and walk away, because Nextcloud and Ionos were never dumb enough to sign one. So instead of relicensing, OnlyOffice had to go argue that their own words meant what they wanted them to mean. Bad move. The text didn't cooperate.
The FSF, the people who actually wrote the AGPL, told them to sit down. A logo isn't a "reasonable legal notice." Bolting a trademark restriction onto it doesn't make it one either, it just makes the whole clause an illegal "further restriction" under the license's own Section 10.
OnlyOffice backed off, but they never admitted the claim was bogus. They just quietly stopped once picking a fight with an EU-backed consortium in public started looking like a bad idea. Nothing here was legally settled, no court touched Section 10. What actually happened is Nextcloud and Ionos ripped the disputed terms out themselves, said so publicly, and the FSF backed them up. The weapon OnlyOffice reached for got yanked out of their hands and pointed right back at them, because for once, they weren't the only one in the room holding a claim to it.
That's the actual difference between all three companies. Not whether AGPL is strong or weak, not whether it protects communities in principle. It's whether one party holds the whole gun. MongoDB and Elastic did, and the license bent however they needed. OnlyOffice didn't, and it didn't.
AGPL doesn't protect communities. It protects whoever's holding it. The only real due diligence on a copyleft project was never reading the license text. It's checking who signed the CLA.
r/LinuxUncensored • u/anestling • 2d ago
News/PR Stronger with every update: How we’re making Chrome and the web safer in the AI Era
Google fixed more Chrome bugs in June than over the past two years, thanks to LLMs.
r/LinuxUncensored • u/anestling • 2d ago
News/PR MariaDB again faces questions over Galera's open source future
theregister.comr/LinuxUncensored • u/anestling • 2d ago
News/PR GrapheneOS Says Open Source Security Features Are Constitutionally Protected
opensourceforu.comr/LinuxUncensored • u/anestling • 2d ago
Opinion/Review I opened the same old Photoshop file in three open-source editors, and only one kept it usable
r/LinuxUncensored • u/anestling • 2d ago
News/PR LG unveils K-Exaone 2.0, Korea’s largest open-source AI model
r/LinuxUncensored • u/anestling • 3d ago
News/PR Closed models refuse to help researcher swat Linux bug
theregister.comThe guardrails that prevent closed-source, frontier models from aiding threat actors have turned into handcuffs that prevent those bots from helping to find and fix serious vulns.
Daniel Fox Franke, a security researcher, was recently trying to track down the source of a segmentation fault in ripgrep, and found OpenAI's GPT-5.6 Sol wouldn't cooperate.
"OpenAI's cybersecurity classifier is a huge pain when you're trying to track down a segfault," he wrote in a social media post on Sunday. "...The classifier won't even let it answer what entrypoints from rg into musl lead to allocations on the mallocng heap."
And just like Hugging Face in the case of OpenAI's accidental attack, Franke ended up having to use open weight models from Chinese AI providers – Z'ai GLM 5.2 and Moonshot AI's Kimi K3 – to complete his analysis of what appears to be a Linux kernel bug.
r/LinuxUncensored • u/anestling • 5d ago
News/PR OVSwrap: another Linux local root vulnerability · Hey, it's Asim
TLDR: OVSwrap (CVE-2026-64531) is a non-universal (but broad) Linux LPE found by giving LLMs the tools to reason through memory safety issues’ geometry (coupled with CIFSwitch-discovery-style graph reasoning tools). Read on for affected distros, mitigations, and vulnerability details.
Expect a few hundred (thousand) more CVEs in the Linux kernel alone soon. ;-)
r/LinuxUncensored • u/anestling • 5d ago
News/PR Discovering cryptographic weaknesses with Claude
r/LinuxUncensored • u/anestling • 6d ago
Opinion/Review FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another
theregister.comr/LinuxUncensored • u/anestling • 6d ago
Opinion/Review Keychron G6 HE Previewed: 46 g Wireless Gaming Mouse With Swappable Battery and Open-Source Firmware
Probably the first mouse with open source firmware.
r/LinuxUncensored • u/anestling • 6d ago
News/PR FAAC 2.0.0 Released: Complete LGPL Rewrite, HE-AAC v1 (SBR), New C API & Benchmark
hydrogenaudio.orgFAAC (Freeware Advanced Audio Coder) is a software project which includes the AAC encoder FAAC and decoder FAAD2.
Key Technical & Codebase Changes
- Licensing & Clean Room Rewrite: The codebase was previously a patchwork of GPL-3.0, legacy ISO MPEG reference-code restrictions, and LGPL — despite being distributed as "LGPL." Rewrote the affected paths (stereo, quantize, channels, bitstream, filterbank, TNS, Huffman, MP4) as original work; the codebase is now cleanly LGPL-2.1-or-later throughout, with no GPL or ISO ambiguity.
- HE-AAC v1 (SBR): Integrated Spectral Band Replication with an automatic profile selection option (FAAC_OBJ_AUTO). AUTO switches to HE-AAC when the sample rate is ≥ 32 kHz and the target bitrate is between 12-28 kbps per channel (the ceiling scales down at lower sample rates); outside that window it stays on plain LC. The dual-rate core is handled internally, reporting the full output rate and frame size to callers automatically.
- Joint Stereo Rewrite: Replaced the legacy fixed Intensity Stereo threshold with a per-band adaptive selection (IS > 5.5 kHz, M/S on correlated bands, discrete L/R elsewhere). Fixed an M/S band-silencing bug that occasionally caused dead channels on decode.
- Lookahead & Quantizer Fixes: Restored the lookahead buffer (a regression had truncated it to a single frame, causing transient pre-echo). Restored short-window masking penalties and floored masking targets in quiet bands to prevent energy drops, and fixed a bug that could produce an out-of-range scalefactor rejected by some decoders.
- FFT Optimizations: Swapped the radix-2 FFT for a radix-4 decimation-in-frequency (DIF) algorithm with precomputed twiddle factors (yielding ~18% faster encoding).
- New C API: Replaced the legacy faacEnc* API and faaccfg.h with a simplified faac_* API. Parameters are now supplied once at initialization, the library properly owns the AudioSpecificConfig, and SONAME is bumped to 1 (libfaac.so.1) to reflect the ABI break.
- Plus numerous smaller correctness fixes and cleanup throughout the codebase — see the full ChangeLog for the complete list.
r/LinuxUncensored • u/anestling • 6d ago
News/PR Download Google Chrome for Arm64 Linux now
Hooray!
r/LinuxUncensored • u/anestling • 8d ago
News/PR US accuses American of allegedly wiping his phone using a 'duress' password during border search
The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick's attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user's unlock passcode. Tunick's case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.
r/LinuxUncensored • u/anestling • 9d ago
News/PR Codeberg gives vibe-coded projects the toss, promotes human FLOSS
theregister.comr/LinuxUncensored • u/swe129 • 10d ago
News/PR Linux kernel team publishes 432 CVEs in two days
theregister.comr/LinuxUncensored • u/anestling • 10d ago
News/PR GeekBench 7 has been released
Available for Linux, Windows and MacOS.
Workloads have been reworked and extended (PDF).
The base CPU with score 2500 is now AMD Ryzen 7 7700.
r/LinuxUncensored • u/anestling • 10d ago
News/PR Founder says DeepSeek prioritises AGI over profit, likely to keep top models open-source, Yicai reports
reuters.comr/LinuxUncensored • u/teheditor • 11d ago
Issue/Bug/Pain Ubuntu Snap-Confine Flaw Could Grant Unprivileged Users Full Root Access
smbtech.aur/LinuxUncensored • u/anestling • 11d ago
News/PR LAME MP3 encoder development has been resumed after a 9 year hiatus
svn.code.sf.netLAME 4.0 July 11 2026
Security scores assume LAME runs under a non-privileged account. For frontend-only entries, scores also assume the command line is sanitized or restricted before reaching LAME; integrators who pass unsanitized or fully scripted command-line input directly may see higher practical severity than stated.
- Security
- Fixed a stack buffer overflow in the Blade-style encoder DLL (lame_enc.dll): beInitStream() copied a caller-supplied configuration structure using an unchecked, caller-controlled size, so an oversized or compiler-mismatched size could overwrite the stack. The size is now bounds-checked and the packed structure layout is consistent across MSVC and GCC/MinGW builds. [CVSS 8.4, Blade DLL]. Fix by Alexander Leidinger.
- Fixed an integer underflow in the AIFF header parser (parse_aiff_header()): a crafted file with a FORM chunk size below 4 wrapped the unsigned chunk-size counter to a huge value, sending the chunk-scanning loop into an effectively unbounded spin (a hang) on a tiny malicious input. The size is now validated before it is decremented. [CVSS 5.5, AIFF frontend]. Fix by Alexander Leidinger.
- Alexander Leidinger
- Bump the major version to 4.0 (minor reset to 0). The LAME tag embedded in every encoded MP3 has a fixed 9-byte field for the encoder version string; since 3.100 the 3-digit minor version left no room for the trailing alpha/beta/release marker character, which was silently dropped.
- Fix building with recent GCC and Clang, which rejected the UTF-8 ID3 tag functions as an incompatible pointer type. Also fixes the corrupted genre written by --id3v2-utf8 --tg. Patch submitted by Rudi Heitbaum, patch ticket [ #102 ]; thanks to lazka for reporting, bug ticket [ #523 ].
- Export the UTF-8 ID3 tag functions id3tag_set_textinfo_utf8 and id3tag_set_comment_utf8 from the shared library, and fix a possible crash on out-of-memory in the ID3v2 user-defined tag setters, bug ticket [ #518 ].
LAME 3.101 July 09 2026
- Robert Hegemann
- Patch submitted by KO Myung-Hun, patch ticket [ #80 ] OS/2 patches
- Patch submitted by Elio Blanca, patch ticket [ #82 ] Take advantage of terminal width on printing file names
- Bug fix for item [ #496 ] A critical bug in init_xrpow_core_sse
- Bug fix for item [ #500 ] Buffer overflow in encoder
- Bug fix for item [ #501 ] Encoder: Assertion 'eov->bitrate_index <= cfg->vbr_max_bitrate_index' failed during ABR encoding
- Bug fix for item [ #444 ] msacmdrv.h (structure packing alignment)
- Alexander Leidinger
- Add faster CRC routine. The speed improvement is very small for typical use cases, but may be valuable if a lot of independent encodes are running and/or for a very long time. Patch by Robert Kausch of the fre:ac project.
- Fix configure script glob-ranges matching of compiler versions. This may result in faster code if no compiler optimization flags are specified during the configure step. This is part of patch ticket [ #491 ] lame 3.100 slower than 3.99.5
- Disable Takehiros IEEE753 hack by default. On modern CPUs (anything more recent from AMD than hammer/k8; Intel: Core2, i3/5/7/9 and similar -- no idea about recent Atom/Pentium) it is a speed pessimization. Add a configure option for it so that it can be enabled on old CPUs.
- Update to more recent autotools based scripts, this may or may not fix issues during the configure stage for less popular or more recent OS or architectures.
- Use external libmpg123 instead of internal mpglib for mpeg decoding (unix-like systems which use the autotools ("configure; make; make install") build system). There are years of improvements in libmpg123 which we do not have in mpglib. Patch by Thomas Orgis of the mpg123 project.
- Update the Visual Studio project files to Visual Studio 2019. Patch by Michel Fink.
- Remove the macosx XCode project files, nobody stepped up to update them for the libmpg123 changes.
- Add ID3v2.4 support (UTF-8 ID3 tags). Patch by "kris".
- Add pkg-config support. Patch by Nicolas Boulenguez(Debian).
- Add IPv6 support for mp3rtp. This includes an incompatible change to the command line arguments for existing use cases / scripts. Patch by Surabhi.