soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #fragnesia

[?]Jesus Michał von Gentoo 🏔 (he) » 🌐
@mgorny@social.treehouse.systems

We've also posted about our , , handling on the website:

gentoo.org/news/2026/05/19/cop

…and yes, another secfix round coming.

CC @wariat

    [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
    @mgorny@social.treehouse.systems

    I've finally finished pushing the latest update for Distribution Kernels, and requested their stabilization. This includes upstream releases 7.0.9, 6.18.32, 6.12.90 and 6.6.140; and Gentoo patch bumps 6.1.173_p1, 5.15.207_p1 and 5.10.256_p1.

    All of these contain the v5 patch. And yes, while the exploit is in the wild, upstream still hasn't merged a fix to the mainline kernel, let alone all the LTS branches. Of course, the patch keeps covering more holes, but it would really be preferable to do that as a followup instead of leaving people vulnerable and forcing us to keep rebasing it.

    They also include a few reverts in 6.18 and 6.6 for broken PowerPC backports that upstream didn't apparently test. 🤷

    We're doing our best, but I'd still recommend running the latest 7.0.x kernel, or LTS 6.18.x, because upstream is far from reliable with the backports.

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      Made Public As Latest Local Privilege Escalation Vulnerability

      phoronix.com/news/Linux-Fragne

        2 ★ 1 ↺
        Light boosted

        [?]OCTADE » 🌐
        @octade@soc.octade.net

        Linux could be changed to prevent a whole class of potential future page cache exploits.

        '/usr/bin/su' and '/bin/su would never be in the memory cache at all ... by default ... except in systems that run entirely in memory.

        Perhaps suid binaries should have special sandboxing for forcing them to be read from protected media into sandboxed memory addresses.

        Maybe that would be a tougher nut to crack?