Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

Inkscape 1.4.2 Adds Initial Support for Importing Vectornator / Linearity Curve Files

Inkscape 1.4.2 is here to introduce a new splash screen, add initial support for importing Vectornator / Linearity Curve files, add a new extension to the Clean up Paths feature to remove duplicate nodes and nodes that are closer than a given threshold, and improve importing of Affinity Designer (.afdesign) files.

IPFire 2.29 Core Update 194 Brings Linux Kernel 6.12.23 LTS and Other Updates

Coming a month after IPFire 2.29 Core Update 193, which introduced post-quantum cryptography support for IPsec tunnels, the IPFire 2.29 Core Update 194 release is powered by a newer kernel from the long-term supported Linux 6.12 LTS series, namely Linux 6.12.23, which brings various security and stability fixes.

Shotcut 25.05 Open-Source Video Editor Released with Alpha Strobe Video Filter

Shotcut 25.05 is here almost two and a half months after the Shotcut 25.03 release to introduce a new Alpha Strobe video filter, adjustable track headers width to the timeline, an item count to the playlist, a new ‘Add Generator’ option to the Timeline toolbar, and a new File > Rereun Filter Analysis function.

9to5Linux Weekly Roundup: May 11th, 2025

I want to thank everyone who sent us donations; your generosity is appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

Flatpak 1.16.1 Linux App Sandboxing Framework Brings More Enhancements

Flatpak 1.16.1 brings various enhancements like the ability to allow a child account to update existing apps by default when using parental controls to ensure that security and bugfix updates can be installed. This change can be overridden by setting polkit policy rules for the org.freedesktop.Flatpak.override-parental-controls-update action.

LinuxGizmos.com

ALPHA-One Leverages RISC-V StarPro64 for Compact Local LLM Deployment

PINE64 has shared early details of the ALPHA-One, a compact generative AI agent powered by the RISC-V-based StarPro64 SBC. Priced at $329.99, the device is aimed at developers and testers, and comes preloaded with a 7 billion parameter LLM running in a Docker container.

Raspberry Pi OS Update Finalizes Bookworm-Based Release Ahead of Debian Trixie

A new version of Raspberry Pi OS is now available, marking what is likely the final release based on Debian Bookworm before the upcoming transition to Debian Trixie later this year. The update introduces usability enhancements, bug fixes, and performance optimizations across the system.

Armbian Updates Add OMV Support, Boot Improvements, and Rockchip Optimizations

OpenMediaVault is now available via the armbian-config interface, offering users an easy way to deploy a network-attached storage system on supported single-board computers. The integration simplifies what was previously a multi-step manual process into a guided installation within the Armbian ecosystem.

Coin-Sized RA4M1-Zero Board Features 32-Bit RA4M1 MCU

The RA4M1-Zero is a compact development board based on Renesas’ 32-bit RA4M1 MCU. Running at 48 MHz with a built-in FPU, it features firmware encryption, secure boot, and a castellated design for easy integration into custom hardware.

Internet Society

Bridging Tech and Policy: How Cat Easdon is Shaping the Future of Privacy and Security

Cat Easdon fell in love with computers as a child. She was captivated by how they worked, tinkering with both software and hardware until she confronted the foundational questions of trust, security, and privacy. These questions took on greater urgency after the 7/7 bombings in her hometown of London in 2005, which led to expanded surveillance in the name of security. Suddenly, the privacy risks she had been exploring felt very real. 

OpenSSH 9.1 released (UPDATED)

posted by Roy Schestowitz on Oct 04, 2022,
updated Oct 05, 2022

OpenSSH 9.1 has just been released. It will be available from the
mirrors listed at https://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol 2.0 implementation and includes sftp client and server support.
Once again, we would like to thank the OpenSSH community for their continued support of the project, especially those who contributed code or patches, reported bugs, tested snapshots or donated to the project. More information on donations may be found at: https://www.openssh.com/donations.html
Changes since OpenSSH 9.0 =========================
This release is focused on bug fixing.
Security ========
This release contains fixes for three minor memory safety problems. None are believed to be exploitable, but we report most memory safety problems as potential security vulnerabilities out of caution.
* ssh-keyscan(1): fix a one-byte overflow in SSH- banner processing. Reported by Qualys
* ssh-keygen(1): double free() in error path of file hashing step in signing/verify code; GHPR333
* ssh-keysign(8): double-free in error path introduced in openssh-8.9
Potentially-incompatible changes --------------------------------
* The portable OpenSSH project now signs commits and release tags using git's recent SSH signature support. The list of developer signing keys is included in the repository as .git_allowed_signers and is cross-signed using the PGP key that is still used to sign release artifacts: https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc
* ssh(1), sshd(8): SetEnv directives in ssh_config and sshd_config are now first-match-wins to match other directives. Previously if an environment variable was multiply specified the last set value would have been used. bz3438
* ssh-keygen(8): ssh-keygen -A (generate all default host key types) will no longer generate DSA keys, as these are insecure and have not been used by default for some years.
New features ------------
* ssh(1), sshd(8): add a RequiredRSASize directive to set a minimum RSA key length. Keys below this length will be ignored for user authentication and for host authentication in sshd(8).
ssh(1) will terminate a connection if the server offers an RSA key that falls below this limit, as the SSH protocol does not include the ability to retry a failed key exchange.
* sftp-server(8): add a "users-groups-by-id@openssh.com" extension request that allows the client to obtain user/group names that correspond to a set of uids/gids.
* sftp(1): use "users-groups-by-id@openssh.com" sftp-server extension (when available) to fill in user/group names for directory listings.
* sftp-server(8): support the "home-directory" extension request defined in draft-ietf-secsh-filexfer-extensions-00. This overlaps a bit with the existing "expand-path@openssh.com", but some other clients support it.
* ssh-keygen(1), sshd(8): allow certificate validity intervals, sshsig verification times and authorized_keys expiry-time options to accept dates in the UTC time zone in addition to the default of interpreting them in the system time zone. YYYYMMDD and YYMMDDHHMM[SS] dates/times will be interpreted as UTC if suffixed with a 'Z' character.
Also allow certificate validity intervals to be specified in raw seconds-since-epoch as hex value, e.g. -V 0x1234:0x4567890. This is intended for use by regress tests and other tools that call ssh-keygen as part of a CA workflow. bz3468
* sftp(1): allow arguments to the sftp -D option, e.g. sftp -D "/usr/libexec/sftp-server -el debug3"
* ssh-keygen(1): allow the existing -U (use agent) flag to work with "-Y sign" operations, where it will be interpreted to require that the private keys is hosted in an agent; bz3429
Bugfixes --------
* ssh-keygen(1): implement the "verify-required" certificate option. This was already documented when support for user-verified FIDO keys was added, but the ssh-keygen(1) code was missing.
* ssh-agent(1): hook up the restrict_websafe command-line flag; previously the flag was accepted but never actually used.
* sftp(1): improve filename tab completions: never try to complete names to non-existent commands, and better match the completion type (local or remote filename) against the argument position being completed.
* ssh-keygen(1), ssh(1), ssh-agent(1): several fixes to FIDO key handling, especially relating to keys that request user-verification. These should reduce the number of unnecessary PIN prompts for keys that support intrinsic user verification. GHPR302, GHPR329
* ssh-keygen(1): when enrolling a FIDO resident key, check if a credential with matching application and user ID strings already exists and, if so, prompt the user for confirmation before overwriting the credential. GHPR329
* sshd(8): improve logging of errors when opening authorized_keys files. bz2042
* ssh(1): avoid multiplexing operations that could cause SIGPIPE from causing the client to exit early. bz3454
* ssh_config(5), sshd_config(5): clarify that the RekeyLimit directive applies to both transmitted and received data. GHPR328
* ssh-keygen(1): avoid double fclose() in error path.
* sshd(8): log an error if pipe() fails while accepting a connection. bz3447
* ssh(1), ssh-keygen(1): fix possible NULL deref when built without FIDO support. bz3443
* ssh-keyscan(1): add missing *-sk types to ssh-keyscan manpage. GHPR294.
* sshd(8): ensure that authentication passwords are cleared from memory in error paths. GHPR286
* ssh(1), ssh-agent(1): avoid possibility of notifier code executing kill(-1). GHPR286
* ssh_config(5): note that the ProxyJump directive also accepts the same tokens as ProxyCommand. GHPR305.
* scp(1): do not not ftruncate(3) files early when in sftp mode. The previous behaviour of unconditionally truncating the destination file would cause "scp ~/foo localhost:foo" and the reverse "scp localhost:foo ~/foo" to delete all the contents of their destination. bz3431
* ssh-keygen(1): improve error message when 'ssh-keygen -Y sign' is unable to load a private key; bz3429
* sftp(1), scp(1): when performing operations that glob(3) a remote path, ensure that the implicit working directory used to construct that path escapes glob(3) characters. This prevents glob characters from being processed in places they shouldn't, e.g. "cd /tmp/a*/", "get *.txt" should have the get operation treat the path "/tmp/a*" literally and not attempt to expand it.
* ssh(1), sshd(8): be stricter in which characters will be accepted in specifying a mask length; allow only 0-9. GHPR278
* ssh-keygen(1): avoid printing hash algorithm twice when dumping a KRL
* ssh(1), sshd(8): continue running local I/O for open channels during SSH transport rekeying. This should make ~-escapes work in the client (e.g. to exit) if the connection happened to have stalled during a rekey event.
* ssh(1), sshd(8): avoid potential poll() spin during rekeying
* Further hardening for sshbuf internals: disallow "reparenting" a hierarchical sshbuf and zero the entire buffer if reallocation fails. GHPR287
Portability -----------
* ssh(1), ssh-keygen(1), sshd(8): automatically enable the built-in FIDO security key support if libfido2 is found and usable, unless --without-security-key-builtin was requested.
* ssh(1), ssh-keygen(1), sshd(8): many fixes to make the WinHello FIDO device usable on Cygwin. The windows://hello FIDO device will be automatically used by default on this platform unless requested otherwise, or when probing resident FIDO credentials (an operation not currently supported by WinHello).
* Portable OpenSSH: remove workarounds for obsolete and unsupported versions of OpenSSL libcrypto. In particular, this release removes fallback support for OpenSSL that lacks AES-CTR or AES-GCM.
Those AES cipher modes were added to OpenSSL prior to the minimum version currently supported by OpenSSH, so this is not expected to impact any currently supported configurations.
* sshd(8): fix SANDBOX_SECCOMP_FILTER_DEBUG on current Linux/glibc
* All: resync and clean up internal CSPRNG code.
* scp(1), sftp(1), sftp-server(8): avoid linking these programs with unnecessary libraries. They are no longer linked against libz and libcrypto. This may be of benefit to space constrained systems using any of those components in isolation.
* sshd(8): add AUDIT_ARCH_PPC to supported seccomp sandbox architectures.
* configure: remove special casing of crypt(). configure will no longer search for crypt() in libcrypto, as it was removed from there years ago. configure will now only search libc and libcrypt.
* configure: refuse to use OpenSSL 3.0.4 due to potential RCE in its RSA implementation (CVE-2022-2274) on x86_64.
* All: request 1.1x API compatibility for OpenSSL >=3.x; GHPR#322
* ssh(1), ssh-keygen(1), sshd(8): fix a number of missing includes required by the XMSS code on some platforms.
* sshd(8): cache timezone data in capsicum sandbox.
Checksums: ==========
- SHA1 (openssh-9.1.tar.gz) = 3ae2d6a3a695d92778c4c4567dcd6ad481092f6c - SHA256 (openssh-9.1.tar.gz) = QKfVArlcItV+e8V1Th85TL5//5d/AvOUhYOeHMDEGuE=
- SHA1 (openssh-9.1p1.tar.gz) = 15545440268967511d3194ebf20bcd0c7ff3fcc9 - SHA256 (openssh-9.1p1.tar.gz) = GfhQCcfj4jeH8CNvuxV4OSq01L+fjsX+a8HNfov90og=
Please note that the SHA256 signatures are base64 encoded and not hexadecimal (which is the default for most checksum tools). The PGP key used to sign the releases is available from the mirror sites: https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc
Reporting Bugs: ===============
- Please read https://www.openssh.com/report.html Security bugs should be reported directly to openssh@openssh.com

UPDATE

A couple of reference pages:

Other Recent Tux Machines' Posts

Broken Telephone or Real Mass Layoffs at Microsoft Today? (May 13 2025) [original]
This is good news for GNU/Linux
IPFire 2.29 Core Update 194 Brings Linux Kernel 6.12.23 LTS and Other Updates
IPFire developer Michael Tremer released IPFire 2.29 Core Update 194 today as a new stable update to this open-source hardened Linux firewall distribution that primarily performs as a router and a firewall.
Inkscape 1.4.2 Adds Initial Support for Importing Vectornator / Linearity Curve Files
Inkscape 1.4.2 has been released today as the second maintenance update to the Inkscape 1.4 series of this open-source, cross-platform, and free SVG (Scalable Vector Graphics) editor for Linux, macOS, and Windows.
Final Bookworm-Based Raspberry Pi OS Released Ahead of Debian Trixie
A new Raspberry Pi OS update is now available for download
Fedora and Red Hat People on RHEL, PHP, and Vim
3 new blog posts
today's howtos
a lot from ID Root
Linux 6.15-rc6
new RC is out
Summer Plans for Tux Machines [original]
How much hotter might it get by June?
Shotcut 25.05 Open-Source Video Editor Released with Alpha Strobe Video Filter
Shotcut 25.05 has been released today as the latest stable version of this open-source, cross-platform, and free video editing software for Linux, macOS, and Windows systems written in Qt and MLT.
KDE Plasma 6.3.5 Improves Support for Multi-Screen Setups, NVIDIA GPU Users
Today, the KDE Project released KDE Plasma 6.3.5 as the fifth and last maintenance update to the latest KDE Plasma 6.3 desktop environment series to address more bugs, crashes, and other issues.
 
Ubuntu 25.04 Upgrades Set to Go Live Again Soon
If you’ve been patiently waiting to do an in-place upgrade to Ubuntu 25.04 from 24.10
marcador is a minimal bookmark manager
This project is heavily inspired by buku
GNOME: An accessibility update
Is Fedora accessible now
Today in Techrights
Some of the latest articles
I Wish I'd Found This Hidden KDE Plasma Feature Sooner
Are you running Kubuntu Linux or another distro that uses the KDE Plasma desktop environment
I tried Linux Mint as a Windows fanboy and here's how it went
I say "properly" use Linux because I gave it a try around 2010
Kagi’s Orion Browser Linux Port Uses GTK4/libadwaita
I reported a few months back Kagi, the company behind the paid
Free and Open Source Software, howtos and Installations
This is free and open source software
Vine Linux is a Linux distribution with an integrated Japanese environment
Vine Linux is a compact and lightweight Japanese Linux distribution developed by Project Vine and many contributors
IBM Announces Powerhouse Linux Server
IBM has unleashed a seriously powerful Linux server with the LinuxONE Emperor 5
KIO Goodies
KIO (KDE Input/Output) is what allows KDE applications to transparently and asynchronously access files
Kdenlive 25.04.1 released
Kdenlive 25.04.1 is now available, containing several fixes and improvements
Armbian Updates Add OMV Support, Boot Improvements, and Rockchip Optimizations
The Armbian development team has rolled out a series of notable updates this week
'End of 10' offers hope and help to Windows 10 users who can't upgrade
Windows 10 support is ending
I found an independent Linux distro that's easy to install - and comes with everything I need
In a world filled with Linux distributions based on one of the big three
GNU/Linux, BSD, and Free Software Leftovers
today's leftovers
Open Hardware/Modding/Hacking/Revers-Engineering Leftovers
ESP32 and more
Programming Leftovers
Development picks
GNOME: Hidden Options, SafeEyes, and Outreachy
3 bits of news/views
I started dual-booting NixOS alongside Windows, and I’m so glad I did
NixOS is a Linux distro that runs on the Nix package manager
EasyOS Daedalus-series version 6.6.8 released
The previous release is 6.6.5, on March 30
Render a Guitar Pro Score in Real Time
Tuxguitar is a quite powerful application written in a mixture of Java / C
Android Leftovers
These 10 Hidden Android Features Make Everyday Life Easier
book is a simple bookmark manager
book is a simple bookmark manager
Review: Bluefin 41
At the end of April I shared an opinion that one thing missing from the Linux ecosystem is automation
today's leftovers
only two for now, MagicaVoxel and more
Recent Videos About GNU/Linux and Related Topics
From Invidious
Plamo Linux 8.2
new release
Today in Techrights
Some of the latest articles
9to5Linux Weekly Roundup: May 11th, 2025
The 239th installment of the 9to5Linux Weekly Roundup is here for the week ending on May 11th, 2025.
5 Things I Do on Linux to Make It More Secure
Do you install a lot of different apps on your Linux computer
Kitty 0.42 Launches With Quick-Access Terminal
Kitty 0.42, a GPU-accelerated terminal emulator, brings a Quake-style quick-access terminal
Why I Prefer GNOME for My Linux Desktop
While other desktop environments like XFCE and Cinnamon exist
Flatpak 1.16.1 Linux App Sandboxing Framework Brings More Enhancements
Flatpak 1.16.1 was released today as the latest stable version of this popular Linux application sandboxing and distribution framework and the first maintenance update to the Flatpak 1.16 series.
Raspberry Pi Connect Exits Beta with Version 2.5 Release
Raspberry Pi has officially ended the beta phase of Raspberry Pi Connect
Free and Open Source Software
This is free and open source software
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Programming/Development Leftovers
coding-related bits
Mozilla: Microsoft and Slop Problems
Mozilla leftovers
Barry Kauler's Updates on EasyOS Development (and More)
Barry Kauler posts
Retro/Open Hardware/Modding: Raspberry Pi, Sinclair C5, and More
Hardware leftovers
This Week in GNOME, GNOME Foundation Report, and Gtk Changes
GNOME updates
today's howtos
7 howtos for today
GNU Taler 1.0 released
Big GNU Taler news
5 Windows Features I Hope Linux Never Copies
You've probably heard that Linux distros lack a lot of Windows functionality
I Tried Installing Linux on a Surface Laptop, Here's How It Went
My Surface laptop finally started showing its age, and try as I might, there wasn’t much I could do to improve its performance
This Arch Linux Variant Takes a Unique Approach to Processes
Chances are, your Linux distro manages processes with systemd
Android Leftovers
Google just gave Chrome and Android a secret weapon against online scams
These Are My Top 6 Linux Distros for Running a Server
If you're new to servers—or Linux in general—don't worry
These 5 Distros Show How Customizable Linux Really Is
You might've heard that Linux can look like practically anything you want
Best Free and Open Source Software
This is free and open source software
Volumio is a music player operating system
Volumio is designed to be your Music Player OS
I found a minimal Linux distro that's fast and efficient for all experience levels
Xubuntu is built for speed and simplicity
Can't upgrade to Windows 11? This is the Linux distro alternative I recommend to most people
SDesk is a lightweight Linux distribution designed with a familiar interface
Clonezilla Live 3.2.1-28 Is Out Based on Ubuntu 25.04 and Linux Kernel 6.14
Clonezilla Live maintainer Steven Shiau released today Clonezilla Live 3.2.1-28 as the latest stable version of this partition and disk imaging/cloning tool based on Debian/Ubuntu.
Today in Techrights
Some of the latest articles