Vue lecture

Les internautes accusent TF1 de plagier la série The White Lotus pour la promotion de Demain nous appartient

Vouloir singer le prestige de HBO quand on produit un feuilleton quotidien est un calcul hautement risqué. TF1 en fait aujourd'hui la douloureuse expérience : en voulant donner des airs de The White Lotus à la nouvelle intrigue estivale de Demain nous appartient, la chaîne s'est pris les pieds dans le tapis rouge.

  •  

[$] Topics in filesystem testing

✇LWN
Par : jake
It should come as no surprise that a gathering of filesystem developers would discuss filesystem testing; it has been a mainstay of the Linux Storage, Filesystem, Memory Management, and BPF Summit over the years and the 2026 summit was no exception. Ted Ts'o led the discussion this time; he had a few different topics to raise, including his perception of increasing regressions for ext4 in the stable kernels and what can be done to help reduce them. As with other similar sessions at the summit over the years, there is a lot of interest in collaborating on test inputs and outputs, but finding a way to centralize that information has so far eluded the filesystem community.
  •  

Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog)

✇LWN
Par : jzb

The SUSE Security Team Blog has a post with an analysis of seunshare, which is used by SELinux to confine untrusted programs. During a review of version 3.10 of the program, the team identified two local Denial-of-Service (DoS) vectors.

Since seunshare is supposed to run on SELinux-enabled systems, it is important to understand what kind of privilege escalation can be achieved when vulnerabilities are exploited in a setuid-root binary like this. Many SELinux-enabled systems, such as Fedora and openSUSE, ship with the "targeted" SELinux policy by default. This policy is focused on confining well-known system services, but assigns an unconfined SELinux context to interactive users by default to achieve a balance between security and usability.

There is currently no domain transition from the unconfined domain to the more restricted seunshare_t defined in the SELinux policy for seunshare. This means the execution of seunshare continues in the unconfined domain. Thus in the context of attacks carried out by interactive users, the impact of the vulnerabilities below will be a root-like privilege escalation despite the system running in SELinux enforced mode.

See the post for the full write-up of the team's discoveries and timeline. The vulnerabilities have been fixed in version 3.11.

  •  

The Batman Part 2 est encore repoussé et ça va faire grincer des dents

L'attente autour du Chevalier Noir commence sérieusement à ressembler à un chemin de croix. Prévu pour être l'un des piliers des années à venir, The Batman Part 2 vient de subir un énième report d'envergure. Pour tenter d'éteindre l'incendie auprès de fans fatigués d'attendre, le réalisateur Matt Reeves a lâché un premier teaser.

  •  

Le nouveau film Vaiana est une catastrophe industrielle et fait pire que Blanche-Neige

Malgré une première place symbolique, le démarrage au box-office américain de l’adaptation en prise de vues réelles de Vaiana (Moana) tourne au fiasco industriel. Avec des recettes bien en deçà des prévisions pour son premier week-end d'exploitation, le blockbuster interroge sérieusement la stratégie de Disney autour de ses remakes en live-action, produits à la chaîne.

  •  

[$] Lockless MPSC FIFO queues for io_uring

✇LWN
Par : corbet
Processes that use io_uring tend to keep a lot of balls in the air; being able to have many operations underway at any given time is part of the point of that API in the first place. The io_uring subsystem must, as a result, keep track of a lot of tasks that have to be performed at the right time. In current kernels, io_uring uses a standard kernel linked-list primitive to track those work items. As of the 7.2 kernel release, though, io_uring will, instead, use a new lockless, multi-producer, single-consumer (MPSC) queue, resulting in some notable performance gains. Lockless algorithms tend to be tricky, but the one used here is relatively approachable and shows how these algorithms can work.
  •  

Security updates for Wednesday

✇LWN
Par : jzb
Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, openssl, perl-DBI, podman, vim, xorg-x11-server, and xorg-x11-server-Xwayland), Red Hat (python3.12), SUSE (afterburn, buildah, busybox, enc, freetype2-devel, go1.25, go1.25-openssl, go1.26-openssl, gosec, grafana, helm, krb5, kubernetes-old, libopenbabel8, libxml2, libxml2-16, nasm, openssl-3, patch, python-Authlib, python-mistune, python-soupsieve, python-sqlparse, python3-dulwich, python313-Pillow, rootlesskit, sbootutil-1, tomcat, and tomcat11), and Ubuntu (alsa-lib, dnsmasq, gnutls28, libheif, linux-aws, linux-fips, linux-lts-xenial, linux-gcp-5.15, linux-intel-iotg-5.15, linux-hwe-6.17, linux-raspi, mariadb, openvpn, python-httplib2, vim, and wget).
  •  

Many old shim versions are still accepted by secure boot

✇LWN
Par : corbet
The CMU CERT Coordination Center has put out an advisory that many exploitable versions of the shim binary, used to boot Linux on systems with UEFI secure boot enabled, were never added to the revocation list.

An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Code executed during this early boot phase may achieve persistent compromise of the platform, including the ability to load unsigned or malicious kernel components that can survive system reboots and, in some cases, operating system reinstallation.

The advisory contains a list of vulnerable shims.

  •  

Lunettes d’éclipse : attention à ces contrefaçons dangereuses vendues en France pour l’éclipse solaire du 12 août 2026

Le grand événement astronomique de l'été 2026 en France métropolitaine approche. L'éclipse solaire du 12 août est imminente, et il est encore temps de s'équiper en lunettes pour l'observer. Mais l'Association Française d'Astronomie a lancé l'alerte : des lunettes qui ne respectent pas les normes de sécurité sont disponibles à la vente. Ce qui représente un réel risque pour la sécurité du grand public.

  •  

Le bracelet Google Fitbit Air n’était pas très utile, mais l’application Bevel change tout

À 99 euros, le Google Fitbit Air est un des produits les mieux positionnés pour suivre sa santé… mais son application n'exploite pas assez bien les données collectées. La version 3.1 de Bevel change la donne : l'app peut désormais se connecter directement à Google Health et transforme le bracelet en alternative crédible à Whoop.

  •  

La mort lente des CAPTCHA se poursuit: avec Precursor, Cloudflare va observer votre comportement à la lettre

Cloudflare généralise Precursor, un système qui analyse en continu la façon dont un visiteur bouge sa souris ou tape au clavier pour distinguer un humain d'un bot. De quoi mesurer l'urgence avec laquelle l'industrie cherche des parades, trois semaines à peine après l'annonce du protocole PACT.

  •  

Un développeur transforme sa femme en monstre cauchemardesque pour son jeu

Mais d'où viennent les inspirations des développeuses et développeurs lorsqu'il s'agit de créer des designs de monstres tous plus spectaculaires les uns que les autres ? Chez certains, elles viennent de mauvais rêves, tandis que d'autres puisent leurs idées directement dans la nature. D'autres encore regardent leur femme dormir ou des restes de poulet.

  •  
❌