NEWS
NEWS
In the news: Hundreds of Consumer and Enterprise Devices Vulnerable to LogoFAIL; Linux Mint 21.3 Beta Available with Latest Version of Cinnamon; Arch Linux 2023.12.01 Released with a Much-Improved Installer; Zorin OS 17 Beta Available for Testing; Red Hat Migrates RHEL from Xorg to Wayland; PipeWire 1.0 Officially Released; Rocky Linux 9.3 Available for Download; Ubuntu Budgie Shifts How to Tackle Wayland; and TUXEDO's New Ultraportable Linux Workstation Released.
Hundreds of Consumer and Enterprise Devices Vulnerable to LogoFAIL
At Black Hat Europe 2023, Fabio Pagani shared a presentation (https://www.blackhat.com/eu-23/briefings/schedule/index.html#logofail-security-implications-of-image-parsing-during-system-boot-35042) about a newly discovered collection of vulnerabilities being used against Linux and Windows systems that involves, believe it or not, logos.
LogoFAIL is a group of vulnerabilities that targets UEFI code from various firmware/BIOS vendors through high-impact flaws in the image parsing libraries within the firmware.
According to Binarly (https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html), "One of the most important discoveries is that LogoFAIL is not silicon-specific and can impact x86 and ARM-based devices. LogoFAIL is UEFI and IBV-specific because of the specifics of vulnerable image parsers that have been used. That shows a much broader impact from the perspective of the discoveries that will be presented on Dec 6th."
The vulnerability was originally discovered on Lenovo devices with Insyde, AMI, and Phoenix reference code and was reported under the advisory BRLY-2023-006.
After the research group was able to demonstrate a number of attack surfaces from image-parsing firmware components, it became a "massive industry-wide disclosure."
LogoFAIL allows attackers to store malicious images on either the EFI system partition or inside unsigned sections of firmware updates. When the images are parsed at boot, the vulnerability is triggered and the payload can then be executed to hijack the process and bypass security features.
Hundreds of consumer and enterprise devices (from numerous vendors) are vulnerable. As of now, there's no indication of when this vulnerability will be patched.
Linux Mint 21.3 Beta Available with Latest Version of Cinnamon
Christmas came early for Linux Mint fans because version 21.3 (aka "Virginia") is now available for download and testing.
The big ticket item for 21.3 is Cinnamon 6, which offers a Wayland session (for those interested in testing). The Wayland session for Cinnamon 6 includes support for fractional scaling (with HiDPI screens) and plenty of other improvements/new features, such as an updated Sound applet (with support for the Telegram Desktop), support for AVIF images as desktop wallpapers, better handling of YouTube in Hypnotix IPTV player, window resizing from with the menu editor, window resizing and keybinding updates from within the Menu Editor, and plenty of bug fixes.
All of the in-house apps have received plenty of attention and the "Romeo" unstable software repository will be available to use to install bleeding-edge releases of apps.
Linux Mint 21.3 is based on Ubuntu 22.04, is powered by the 5.15 LTS kernel, and will receive updates until 2027.
You can download an ISO of the beta version (https://mirrors.edge.kernel.org/linuxmint/testing/linuxmint-21.3-cinnamon-64bit-beta.iso) and test it yourself. To learn more about the latest release from Linux Mint, check out the official release notes (https://www.linuxmint.com/rel_virginia.php).
Arch Linux 2023.12.01 Released with a Much-Improved Installer
Arch Linux is well known for not only being one of the most stable operating systems on the market but also for being a bit complicated to install. With the December release (available now), that all changes.
Although Arch Linux still doesn't use a GUI installer, the archinstall
command makes installing the open source OS much simpler than previous iterations. With a text-based menu installer, you'll find getting Arch Linux up and running a far less "painful" process.
As first reported by 9to5Linux (https://9to5linux.com/arch-linuxs-december-2023-iso-release-brings-linux-6-6-lts-updated-installer), the latest version of archinstall
(version 2.7) also adds a few important features: support for unified kernel image (UKI), the ability to check for a new version of archinstall
during the installation process, support for the nvidia-dkms package (when installing the NVIDIA proprietary graphics driver); and plenty of bug fixes.
The latest version of Arch Linux also includes kernel 6.6 LTS.
Anyone looking to install the latest version of Arch Linux can head to the official download page (https://archlinux.org/download/), select the mirror nearest to your location, and download the ISO image for installation.
Unlike many Linux distributions, Arch Linux doesn't publish official release notes. Instead, you'll find information shared by the team with the public for the latest release at https://archlinux.org/releng/releases/2023.12.01/.
Of course, you can always join the Arch-announce mailing list (https://lists.archlinux.org/postorius/lists/arch-announce.lists.archlinux.org/) to keep abreast of what's going on with the distribution.
Buy this article as PDF
(incl. VAT)
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Wine 10 Includes Plenty to Excite Users
With its latest release, Wine has the usual crop of bug fixes and improvements, along with some exciting new features.
-
Linux Kernel 6.13 Offers Improvements for AMD/Apple Users
The latest Linux kernel is now available, and it includes plenty of improvements, especially for those who use AMD or Apple-based systems.
-
Gnome 48 Debuts New Audio Player
To date, the audio player found within the Gnome desktop has been meh at best, but with the upcoming release that all changes.
-
Plasma 6.3 Ready for Public Beta Testing
Plasma 6.3 will ship with KDE Gear 24.12.1 and KDE Frameworks 6.10, along with some new and exciting features.
-
Budgie 10.10 Scheduled for Q1 2025 with a Surprising Desktop Update
If Budgie is your desktop environment of choice, 2025 is going to be a great year for you.
-
Firefox 134 Offers Improvements for Linux Version
Fans of Linux and Firefox rejoice, as there's a new version available that includes some handy updates.
-
Serpent OS Arrives with a New Alpha Release
After months of silence, Ikey Doherty has released a new alpha for his Serpent OS.
-
HashiCorp Cofounder Unveils Ghostty, a Linux Terminal App
Ghostty is a new Linux terminal app that's fast, feature-rich, and offers a platform-native GUI while remaining cross-platform.
-
Fedora Asahi Remix 41 Available for Apple Silicon
If you have an Apple Silicon Mac and you're hoping to install Fedora, you're in luck because the latest release supports the M1 and M2 chips.
-
Systemd Fixes Bug While Facing New Challenger in GNU Shepherd
The systemd developers have fixed a really nasty bug amid the release of the new GNU Shepherd init system.