PodParley PodParley
665: Patch Me If You Can

EPISODE · May 4, 2026 · 1H 20M

665: Patch Me If You Can

from LINUX Unplugged · host Jupiter Broadcasting

We dig into the Copy Fail vulnerability and test a proof-of-concept against our own box. Plus, Jon Seager, VP of Engineering at Canonical joins us, and we kick off the BSD Challenge!Sponsored By:Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMCopy Fail — CVE-2026-31431 — "An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root." — TheoriCopy Fail: 732 Bytes to Root - Xint — "A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017." — XintLinux Kernel Bug Explained - Jorijn — "CopyFail is more portable. One script, every distro, no offsets. Dirty Pipe needed kernel ≥ 5.8; Copy Fail covers 2017–2026." — Jorijn"Kubernetes Pod Security Standards (Restricted) and default seccomp do NOT block the syscall used." — JorijnArs: Most Severe Linux Threat in Years — "The most severe Linux threat to surface in years catches the world flat-footed." — Ars TechnicaSysdig: CVE-2026-31431 Analysis — "The flaw was introduced in 2017 via commit 72548b093ee3, which switched AEAD operations to in-place processing." — SysdigCERT-EU AdvisoryUbuntu Security TrackerThe Register: Crypto FlawKernel Patch (reverts 2017 optimization) — "This mostly reverts commit 72548b093ee3 except for the copying of the associated data." — Kernel CommitBuggy Commit: 72548b093ee3 (2017)DeepWiki: AF_ALG Internalsoss-security DisclosurePSA + GRUB Mitigation - Jan WildeboerUbuntu 26.04 LTS (Resolute Raccoon) Released — "Ubuntu 26.04 LTS sets the example for providing best-in-class resilience while simultaneously embracing innovation and the advancement of open source." — Jon Seager, VP Ubuntu EngineeringThe Future of AI in Ubuntu - Jon Seager — "Throughout 2026 we'll be working on enabling access to frontier AI for Ubuntu users in a way that is deliberate, secure, and aligned with our open source values." — Jon SeagerUbuntu 26.04 Release NotesUbuntu AI Features Throughout 2026 - Phoronix — "Canonical's approach to AI is refreshingly thoughtful — Microsoft should take note." — ZDNetCanonical DDoS Attack Update — "Canonical's web infrastructure is under a sustained, cross-border attack and we are working to address it." — arcticp, CanonicalUbuntu Weekly Newsletter #942Canonical AI Approach - ZDNet9to5Linux: Opt-In LLM Toolsuutils/coreutils: Cross-platform Rust rewrite of the GNU coreutilsLINUX Unplugged 636: Engineering the FutureLiveCD fails to start X session on QEMU · Issue #354 · ghostbsd/issuesMonty's “rescue” drive NixOS configMagnolia Mayhem's BSD Challenge ReportPick: NASty — NASty is a NAS operating system built on NixOS and bcachefs. It turns commodity hardware into a storage appliance serving NFS, SMB, iSCSI, and NVMe-oF — managed from a single web UI, updated atomically, and rolled back when things go sideways.Pick: Defuse — Defuse is a GTK4 application for removing image backgrounds locally.Defuse on Flathub

NOW PLAYING

665: Patch Me If You Can

0:00 1:20:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Sunday Morning Linux Review - MP3 Feed Tony Bemus, Mary Tomich, Phil Porada, and Tom Lawrence Sunday Morning Linux Review www.smlr.us is a podcast with Tony Bemus, Mary Tee , Phil Porada, and Tom Lawrence. We talk about the Linux and Open Source News. Edited episodes and show notes are found at www.smlr.us , We will be Live on IRC #SMLR and Video: youtube.com/c/SmlrUs Linux Game Cast on Odysee Linux Game Cast Helping the Linux community with gaming, podcasting, live streaming, and audio & video production since 2010. [LinuxGameCast Webzone](https://linuxgamecast.com/) Ignition Zone Ignite to Rise Life Coaching Hey, I see you. You’re running a business, handling all the things, and somehow, you’re still answering emails at 10 PM.You tell yourself, ”Just one more thing,” but somehow, one more thing turns into one more hour.Sound familiar?Welcome to ”Ignition Zone,” the podcast for high-achieving women who are ready to set boundaries, unplug, and still keep their business thriving.I’m Crystal Cornacchia, The Unplugged Success Coach, and I help women like you reclaim your time without feeling guilty or losing momentum.Each week, I’ll give you quick, no-fluff episodes packed with simple strategies to:✔ Stop overworking and take back your time✔ Set boundaries that actually stick✔ Unplug without your business falling apart✔ Grow your business without being on call 24/7This is for you if you want to step back without stepping away and finally build a business that doesn’t need you every second of the day.New episodes drop every Tuesday on Spotify, Apple Podcasts, and igniteinnovation.net. La chronique techno – blogueLinux.ca Un blogue Québécois sur Linux
URL copied to clipboard!