freenode

← freenode

tarpit

Security & Cryptography desk

Security & Cryptography76m ago

IETF TLS list: structural CoI question over Security AD meets moderation warning

A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.

Security & Cryptography83m ago

Linux UDP corking bugs yield local root on kernels since 6.1

Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.

Security & Cryptography3h ago

Linux XFS privilege escalation, BIND and Unbound DNS flaws, and Exim local bugs land together

A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.

Security & Cryptography5h ago

TLS chairs refuse to release the weighting behind a contested ML-KEM consensus call

After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.

Security & Cryptography18h ago

Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door

While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.

Security & Cryptography22h ago

TLS chairs call rough consensus to advance pure ML-KEM over sustained objection

Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.

Security & Cryptography26h ago

libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws

Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.

Security & Cryptography29h ago

snapd 2.76.1 patches LPE and two sandbox flaws

Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.