freenode
4m agoHIGH-severity CVE in CPython tarfile allows symlink attacks via hard links to modify or disclose files outside extraction target. 10m agoLarge kbuild series parallelizes objtool, Rust crates, probes and gzip, claiming 36-90% build speedups; Linus and Kees discuss. 20m agollama.cpp M-RoPE path overreads batch positions past API docs 32m agoglibc tdelete stack overflow fixed as CVE-2026-19542 34m agov2 18-patch series adds BTF LOCSEC encoding for inline function sites to support kprobe tracing. 34m agoNixOS discourse PSA recommends switching nixpkgs flake inputs to official channels.nixos.org tarballs for smaller downloads and GitHub independence. 34m agoNew LuCI theme thread reveals stored unauthenticated SVG XSS via wallpaper upload served as image/svg+xml. 36m agoInitial public disclosure of unauthenticated quadratic DoS in graphql-go <=0.8.1 with no fix or private reporting channel. 40m agoGlibc flags buffer overflow in strfmon monetary formatting 43m agoUsers report on Julia 1.13 release improvements (TTFX, REPL) and note some regressions plus HN visibility. 46m agoWorking NSS offload for IPQ5018 NAT using upstream stmmac on 6.18, with public branches and reports on multiple boards. 2h agoIncomplete Emacs CVE-2024-53920 fix still allows code execution