ShredOS is a small live Linux distribution whose sole purpose is to securely erase the contents of disks. It can boot from a USB device, CD or DVD and it supports both BIOS and UEFI booting. The system boots directly into nwipe, a program that securely erases the contents of block devices; it can wipe a single drive or multiple disks in parallel. After booting the system, the user can select a disk to erase, together with one of the various erasure methods, such as "Fill With Zeros", "Fill With Ones", RCMP TSSIT OPS-II, DoD, Gutmann Wipe, PRNG Stream, Schneier Wipe, BMB21-2019 and others. The nwipe program automatically starts its ncurses-based interface in the first virtual terminal (ALT-F1), while other useful tools, such as hdparm, smartmontools and hexeditor can be run in the second virtual terminal (ALT-F2). ShredOS is available in "Standard" and "Lite" editions, with the latter able to run on computers with as little as 512 MB of RAM.
KLV-Airedale is an independently-developed, general-purpose and minimalist Linux distribution featuring a customised Xfce desktop. It is compatible with Void, as it uses Void's package management tools and repositories. The distribution is built using a custom build script called FirstRib, which deploys the OverlayFS filesystem to provide a frugal install, Squashfs capabilities, and an option to copy the system to RAM (copy2ram). Like Void, KLV-Airedale uses the runit init system.
Version:next-20260716 (linux-next)
Released:2026-07-16
The
extensible
scheduler class (sched_ext) allows the installation of custom CPU
schedulers as a set of BPF programs. While sched_ext, in its current form,
has already led to a lot of interesting scheduler-development work, the
subsystem itself is still undergoing rapid evolution. Among other work,
the ability to set up a hierarchy of
sub-schedulers is approaching completion, and
a longstanding incompatibility with
proxy
execution is coming to an end.
Security updates have been issued by AlmaLinux (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), Debian (chromium, dhcpcd5, and ntfs-3g), Fedora (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), Mageia (openssl, poppler, python-mistune, and tmux), Oracle (389-ds-base, cups, git-lfs, glibc, host-metering, kernel, libsolv, libxml2, nginx:1.24, PackageKit, python-pillow, and qemu-kvm), Red Hat (buildah, containernetworking-plugins, and skopeo), SUSE (buildah, cosign, curl, distribution, dnsmasq, glib-networking, glibc, gnutls, gstreamer-plugins-bad, ImageMagick, kernel, podman, python-cryptography, python313-django-debug-toolbar, rekor, sccache, sssd, and yelp), and Ubuntu (dotnet8, dotnet10, libslirp, luajit, python-idna, sympa, and tomcat8).
OPNsense is a FreeBSD-based specialist operating system (and a fork of pfSense) designed for firewalls and routers. It is developed by Deciso B.V. in the Netherlands. Some of the features of OPNsense include forward caching proxy, traffic shaping, intrusion detection, two-factor authentication and easy OpenVPN client setup. The project's focus on security brings a number of unique features, such as the option to use LibreSSL instead of OpenSSL (selectable in the GUI). OPNsense also includes an update mechanism that delivers important security updates in a timely fashion.
Kumander Linux is a Debian-based distribution featuring the Xfce desktop. The distribution's key feature is a Windows 7-like theme and desktop behaviour designed to make the migration from Windows to Linux easier.
Inside this week's LWN.net Weekly Edition:
- Front: Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE.
- Briefs: Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
It should come as no surprise that a gathering of filesystem developers
would discuss filesystem testing; it has been a mainstay of the
Linux Storage,
Filesystem, Memory Management, and BPF Summit over the years and the
2026 summit was no exception. Ted Ts'o led the discussion this time; he
had a few different topics to raise, including his perception of increasing
regressions for ext4 in the stable kernels and what can be done to help
reduce them. As
with other similar
sessions at the summit over the years,
there is a lot of interest in collaborating on test inputs and outputs, but
finding a way to centralize that information has so far eluded the
filesystem community.
The SUSE Security Team Blog has a post
with an analysis of seunshare,
which is used by SELinux to confine untrusted programs. During a
review of version
3.10 of the program, the team identified two local
Denial-of-Service (DoS) vectors.
Since seunshare is supposed to run on SELinux-enabled systems, it
is important to understand what kind of privilege escalation can be
achieved when vulnerabilities are exploited in a setuid-root binary
like this. Many SELinux-enabled systems, such as Fedora and openSUSE,
ship with the "targeted" SELinux policy by default. This policy is
focused on confining well-known system services, but assigns an
unconfined SELinux context to interactive users by default to achieve
a balance between security and usability.
There is currently no domain transition from the unconfined domain
to the more restricted seunshare_t defined in the SELinux policy for
seunshare. This means the execution of seunshare continues in the
unconfined domain. Thus in the context of attacks carried out by
interactive users, the impact of the vulnerabilities below will be a
root-like privilege escalation despite the system running in SELinux
enforced mode.
See the post for the full write-up of the team's discoveries and timeline. The
vulnerabilities have been fixed in version 3.11.
Version:next-20260715 (linux-next)
Released:2026-07-15
Oracle Linux is an enterprise-class Linux distribution supported by Oracle and built from source packages for Red Hat Enterprise Linux (RHEL). Some of the special features of Oracle Linux include a custom-build and rigorously-tested Linux kernel called "Oracle Unbreakable Kernel", tight integration with Oracle's hardware and software products including most database applications, and "zero downtime patching" - a feature that enables administrators to update the kernel without a reboot.
Processes that use
io_uring
tend to keep a lot of balls in the air; being able to have many operations
underway at any given time is part of the point of that API in the first
place. The io_uring subsystem must, as a result, keep track of a lot of
tasks that have to be performed at the right time. In current kernels,
io_uring uses a standard kernel linked-list primitive to track those work
items. As of the 7.2 kernel release, though, io_uring will, instead, use a
new lockless, multi-producer, single-consumer (MPSC) queue, resulting in
some notable performance gains. Lockless algorithms tend to be tricky, but
the one used here is relatively approachable and shows how these algorithms
can work.
Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, openssl, perl-DBI, podman, vim, xorg-x11-server, and xorg-x11-server-Xwayland), Red Hat (python3.12), SUSE (afterburn, buildah, busybox, enc, freetype2-devel, go1.25, go1.25-openssl, go1.26-openssl, gosec, grafana, helm, krb5, kubernetes-old, libopenbabel8, libxml2, libxml2-16, nasm, openssl-3, patch, python-Authlib, python-mistune, python-soupsieve, python-sqlparse, python3-dulwich, python313-Pillow, rootlesskit, sbootutil-1, tomcat, and tomcat11), and Ubuntu (alsa-lib, dnsmasq, gnutls28, libheif, linux-aws, linux-fips, linux-lts-xenial, linux-gcp-5.15, linux-intel-iotg-5.15, linux-hwe-6.17, linux-raspi, mariadb, openvpn, python-httplib2, vim, and wget).
Whonix is an operating system focused on anonymity, privacy and security. It is based on the Tor anonymity network, Debian GNU/Linux and security by isolation. Whonix consists of two parts: One solely runs Tor and acts as a gateway, which is called Whonix-Gateway. The other, which is called Whonix-Workstation, is on a completely isolated network. Only connections through Tor are possible. With Whonix, you can use applications and run servers anonymously over the Internet. DNS leaks are impossible, and even malware with root privileges cannot find out the user's real IP.
The CMU CERT Coordination Center has put out
an advisory that many
exploitable versions of the shim binary, used to boot Linux on systems with
UEFI secure boot enabled, were never added to the revocation list.
An attacker with administrative privileges or the ability to modify
the boot process could use one of the vulnerable shim bootloaders
to bypass Secure Boot protections and execute arbitrary code before
the operating system loads. Code executed during this early boot
phase may achieve persistent compromise of the platform, including
the ability to load unsigned or malicious kernel components that
can survive system reboots and, in some cases, operating system
reinstallation.
The advisory contains a list of vulnerable shims.
Trace Labs OSINT VM is a Debian-based Linux distribution with specialist open-source intelligence (OSINT) tools to help find missing persons and reunite them with their families. It is provided as a set of pre-built images for VMware and Virtual Box virtual machines. The OSINT tools, which need to be downloaded separately via a helper script, include Email Search (to perform email searches via social media, breach info, and other sources), Multi Search (to perform searches over multiple sources, such as social media, domains, IPs, phone numbers), Username Search (to check username availability across multiple platforms), Social Media (to gather OSINT from popular social media platforms). Also included are Phone Numbers, Images & Video Analysis, Documentation & Capture; Geolocation & Mapping, among various other useful tools.
stillOS is an immutable Linux distribution based on AlmaLinux and featuring a customised GNOME desktop. It includes atomic updates and support for Flatpak packages. It also comes with a number of custom applications, such as stillControl (a tool for configuring desktop layouts), stillCenter (a software center with a curated store), stillTerminal (a custom terminal emulator that integrates with DistroBox containers and remote SSH instances), and Quick Setup (a first-boot tool to allow selection and installation of preferred applications). The project's goal is to provide a consumer-ready desktop Linux distribution that is user-friendly, stable, consistent and predictable.
butrelinux is an immutable Linux distribution derived from the CentOS-based edition of Bluefin. It features the KDE Plasma desktop. The distribution uses the Anaconda system installer for hard disk installation, includes drivers for NVIDIA graphics cards, and provides out-of-the-box support for Distrobox containers and Flatpak packages.
Pages