Latest Linux and open source news from around the web

UNIX and Linux System Administration Handbook Sponsored · View on Amazon → Designing Data-Intensive Applications Sponsored · View on Amazon →
OMG! Ubuntu

You can run Ubuntu on your PS5 (and play Steam games)

Someone has hacked their PlayStation 5 to run Ubuntu 26.04 LTS and used it to play GTA V Enhanced on Steam at a smooth 60fps at 1440p โ€“ and now you can too. The feat was pulled off by security engineer Andy Nguyen, who announced a public release of his ps5-linux project this week to more people can turn their โ€œโ€ฆPS5 Phat console on 3.xx and 4.xx [Firmware] into a fully functional Linux PC gaming deviceโ€. Obviously, this is all unofficial. The project exploits a patched hypervisor vulnerability to give Linux direct access to the PS5โ€™s hardware โ€“ which with its [โ€ฆ]

LWN.net

[$] LWN.net Weekly Edition for April 30, 2026

Inside this week's LWN.net Weekly Edition: Front: Famfs; Python packaging council; Zig concurrency; pages and folios; Strawberry music manager; 7.1 merge window. Briefs: GnuPG 2.5.19; Copy Fail; Plasma security; Fedora 44; Ubuntu 26.04; Niri 26.04; pip 26.1; RIP Seth Nickell; RIP Tomรกลก Kalibera; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.

LWN.net

A security bug in AEAD sockets

Security analysis firm Xint has disclosed a security bug in the Linux kernel that allows for arbitrary 4-byte writes to the page cache, and which has been present since 2017. The vulnerability has been fixed in mainline kernels. A proof-of-concept script demonstrates how to use the flaw to corrupt a setuid binary, which works on multiple distributions, by requesting an AEAD-encrypted socket from user space and splicing a particular payload into it. A supplemental blog post gives more details about the discovery and remediation. A core primitive underlying this bug is splice(): it transfers data between file descriptors and pipes without copying, passing page cache pages by reference. When a user splices a file into a pipe and then into an AF_ALG socket, the socket's input scatterlist holds direct references to the kernel's cached pages of that file. The pages are not duplicated; the scatterlist entries point at the same physical pages that back every read(), mmap(), and execve() of tha

OMG! Ubuntu

Enabling Ubuntu Pro in Security Center is a Cinch

Canonical made it easier to opt-in to additional security coverage in Ubuntu 26.04 LTS, by adding Ubuntu Pro settings to its desktop Security Center application โ€“ and it works great. The range of options is the same as in Software & Updates > Ubuntu Pro tab โ€“ that app is no longer preinstalled in 26.04 โ€“ but the presentation and layout is less cramped. More room is available for concise explanations of the settings and switches. Click to enable Ubuntu Pro and use the โ€˜enable with Ubuntu One accountโ€™ option to authenticate via your web browser. If you have an [โ€ฆ]

Linux.org

Run Windows Apps on Linux with WinBoat

For anyone running Linux who wants, or needs, to run a Windows program, there are few ways to do it and sometimes it doesn't work. Some Windows apps will not run on WINE, or the like, and you are stuck not being able to use it. Some people will run a virtualized Windows system inside Linux and make it work that way. WinBoat is another such virtualized system that runs on Docker. This method has a few more alternatives and seems faster. In this article, I can help you get WinBoat set up... https://www.linux.org/threads/run-windows-apps-on-linux-with-winboat.60069/

LPI

DevOps Tools Introduction #15: Taking the Test

Congratulations, youโ€™ve made it to the final posting in our DevOps Tools Introduction series. Throughout the last few months, weโ€™ve explored new topics each and every week. Working through all the referenced resources was a significant investment of time. In ... Read more The post DevOps Tools Introduction #15: Taking the Test appeared first on Linux Professional Institute (LPI).

LWN.net

[$] Python packaging council approved

The Python packaging world now has a formal governance council, of the form described in PEP 772 ("Packaging Council governance process"), which was approved by the steering council on April 16. It has been over a year since the PEP was first proposed in February 2025 and it has undergone lengthy discussions in multiple postings to the Python discussion forum. The packaging council will have "broad authority over packaging standards, tools, and implementations"; it will consist of five members who will be elected in a vote that is likely to come in Juneโ€”after PyCon US 2026 is held mid-May.

LWN.net

Security review of Plasma Login Manager (SUSE Security Team Blog)

SUSE's Security Team has published a detailed blog post on their recent review of the Plasma Login Manager version 6.6.2, which was forked from the SDDM display manager. While most of the code remains the same, the new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from defense-in-depth security issues. [...] Based on the high severity of the defense-in-depth issues shown in this report, our assessment is that there is effectively no separation between root and the plasmalogin service user account. At this time there is no bugfix available by upstream, but a security fix is planned for the next Plasma release on May 12. We have not been involved in upstream's bugfix process so far and have no knowledge about the approach that will be taken to address the issues from this report.

Phoronix

The Intel Lunar Lake CPU Performance Gains On Linux Over The Past Year

Recently I ran benchmarks looking at the Xe2 graphics performance gains on Intel Lunar Lake over the past year with what's shipped by Ubuntu and comparing against our original tests of the Lenovo ThinkPad X1 Carbon Gen 13 Aura Edition. With those Lunar Lake iGPU benchmarks out of the way, here is a look at how the Lunar Lake CPU performance has evolved on Linux since April 2025.

LWN.net

Security updates for Wednesday

Security updates have been issued by AlmaLinux (firefox, gdk-pixbuf2, java-17-openjdk, libxml2, python3, python3.11, python3.12, sudo, and webkit2gtk3), Debian (dnsdist, node-tar, pdns, pdns-recursor, and policykit-1), Fedora (chromium, edk2, and vim), Oracle (firefox, gdk-pixbuf2, go-toolset:rhel8, libpng12, LibRaw, libxml2, python, python3, python3.11, python3.12, python3.12-wheel, vim, webkit2gtk3, xorg-x11-server, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), Red Hat (container-tools:rhel8, delve, git-lfs, go-rpm-macros, grafana, grafana-pcp, osbuild-composer, and rhc), SUSE (bouncycastle, clamav, container-suseconnect, dovecot22, erlang, firefox, fontforge, freerdp2, ghostscript, giflib, gnome-remote-desktop, go1.25, go1.26, google-guest-agent, haproxy, ignition, ImageMagick, kernel, libcap, libpng16, libraw, librsvg, mariadb, openexr, pocketbase, protobuf, python-Pillow, python-requests, qemu, rust1.94, sudo, tomcat, tomcat10, tomcat11, webkit2gtk3,