Tumbleweed Monthly Update - November 2024
This month, the rolling-release continues to shine as a well-oiled machine. November brings key updates for Mesa, gtk4, php8, postgresql17 and more. Alongside these key updates, important security fixes arrived for mozjs128, postgresql, Firefox, and OpenSC, which resolved several CVEs to help bolster your system’s resilience. The fresh design introduced last month, with its revamped logo and day/night-themed wallpapers, continues to enhance Tumbleweed’s aesthetic appeal while the updates this month improve functionality and security.
As always, remember to roll back using snapper if any issues arise.
Happy updating and tumble on!
For more details on the change logs for the month, visit the openSUSE Factory mailing list.
New Features and Enhancements
-
GTK4 4.16.6 and 4.16.7: The newest version reduces the size of error underlines in text rendering for better visual clarity. The 4.16.6 version provides fixes for a smoother user experience. Wayland color management is now opt-in, helping prevent compatibility issues with KWin. Users can experiment with this feature by setting
GDK_DEBUG=color-mgmt. Improvements include preventing emoji selection when inserted inGtkText, setting default window icons from the application ID inGtkApplicationand enhancingGtkFontChooserto make its dialog more adaptable.The release also includes updated translations. -
postgresql 17.2: The package received two updates this month and resolves an ABI break affecting extensions that interact with
ResultRelInfoand restores the functionality ofALTER {ROLE|DATABASE} SETrole. Logical replication slots now handlerestart_lsncorrectly to avoid backward movement. The update prevents deletion of required WAL files duringpg_rewindand fixes race conditions with shared statistics entries. Index statistics incontrib/bloomare now correctly counted. The update fixes an assertion failure in regular expression parsing caused by disconnected NFA sub-graphs. -
gnutls 3.8.8: Improvements in this package were made in post-quantum cryptography and Online Certificate Status Protocol handling. Experimental support for X25519MLKEM768 and SecP256r1MLKEM768 key exchange algorithms in TLS 1.3 were added that align with the final ML-KEM standard. This update requires liboqs 0.11.0 or newer. Additionally, the library now validates all records in OCSP responses, ensuring the server certificate is checked against all available records instead of only the first. Improvements in handling malformed
compress_certificateextensions bring stricter RFC 8879 compliance, replacing incorrect alerts withillegal_parameterand rejecting overlong extension data. -
KDE Plasma 6.2.3:
Bluedevil improves PIN entry behavior, while Breeze resolves a potential null pointer issue. Discover updates its backend for compatibility with fwupd 2.0.0 and corrects review visibility in the Application Page. KWin receives extensive updates, including fixes for crashes, colormap leaks, file descriptor handling, and HDR brightness management. Plasma Desktop fixes app tooltips, task manager icon alignment, emoji search, and optimizes activity management. Other components like KPipeWire, KSystemStats, and Powerdevil improve stream handling, sensor robustness, and brightness adjustments, respectively. Plasma Mobile simplifies and cleans up the Action Drawer and enhances app list navigation and search functionality. Plasma Audio Volume Control ensures accurate device name updates, while Plasma Workspace adjusts logout screen behavior, theme defaults, and mobile user interface fixes. - KDE Gear 24.08.3: Elisa fixes missing icons on certain platforms. K3b corrects file pattern parsing for ripped files and removes deprecated MusicBrainz code. KAccounts-Integration improves logging, fixes dangling references, and handles missing files gracefully. Kate addresses session group saving, export order for SQL and builds on openSUSE with updated dependencies. Kdenlive resolves multiple crashes and improves project handling, proxy generation, and timeline management. KIO-Extras adds WebP thumbnail support. Kitinerary expands ticket extraction support for multiple transport services and improves handling of Renfe and Agoda formats. Konsole fixes issues with OSC color commands.
- KDE Frameworks 6.8.0: Baloo now excludes model/obj and text/rust from indexing. Breeze Icons adds support for text/x-typst mimetype icons and unifies index themes for better consistency. Extra CMake Modules gain Python bindings and improved static Qt6 support. KIO sees improvements in http handling, resizing in KFilePlacesView, and overall UX enhancements. Kirigami resolves various issues with icons, themes, and overlays, improving usability. KTextEditor enhances session restore, template handling, and introduces comprehensive swap file tests. Solid restores media change handling for audio CDs and adopts libmount on Linux for better functionality. This release also includes numerous bug fixes, CI improvements for static builds, enhanced Qt 6 compatibility, and updated translations.
- gnome-control-center 47.2: GNOME users see accessibility improvements by removing excessive “screen” labels. The appearance settings fix accidental resets of accent colors. Lemory leak are addressed in the Apps section, while Color ensures profiles are connected before use. Printers fix an incorrect tooltip in the “Add Printer” button. Updated translations are included.
-
ruby3.3 3.3.6: This update includes the merging of JSON 2.7.2 and reline 0.5.10, along with an upgrade to REXML 3.3.9. The release resolves significant bugs, such as improper object freeing when using
Data_Make_Struct, brokenIO#closefunctionality under Fiber scheduling, and errors with multibyte path names on Windows. Additional fixes address issues withFloathandling ASCII-incompatible strings, memory management inIO::Bufferoperations, and discrepancies ininstance_methodbehavior across Ruby versions. This version also corrects corruptRUBY_DESCRIPTIONmetadata when specific flags are used and improves hash key retrieval afterProcess.warmup.
Key Package Updates
-
Mesa 24.3.0: The package introduces a new stable release with updates enhancing its graphical capabilities and addressing security and build issues. The update refreshes patches for various vulnerabilities, including CVE-2023-45913, CVE-2023-45919, and CVE-2023-45922, while incorporating fixes for Python 3.6 build compatibility and other adjustments. Deprecated options like
-Ddri3=enabledand-Ddri-search-pathhave been removed to streamline the build configuration. Vulkan 1.3 is now supported on Raspberry Pi 4 and 5 via v3dv, while the NVK driver adds support for important extensions likeVK_EXT_descriptor_buffer,VK_KHR_dynamic_rendering_local_read, andVK_KHR_pipeline_binary. RADV sees new features and Shader support is significantly enhanced. Full details can be accessed in the release notes. - kernel-source 6.11.8: Key updates for the Linux Kernel address issues like dangling pointers in virtual socket and hyper-v socket initialization, improved support for AMD audio on certain laptops, and fixes for display rendering and timeout handling in Intel and AMD graphics drivers. The update resolves several memory management, file system and USB-related bugs, which includes USB Type-C and serial device handling. Fixes were made to Thunderbolt connections, media device parsing, and the management of system clocks and platformance features for AMD processors. Updates to the Btrfs file system enhance subvolume flag management and quota handling.
-
GStreamer 1.24.9: Fixes include better timestamp handling in
flvmux,RTPManagerkeyframe management and enhancedSRTandV4L2support. Updates optimizeaggregator,playbin3, andqtdemux, with broader format and library compatibility. - gpgme 1.24.0: This package brings several significant enhancements and fixes, including extended decryption and verification commands that now support direct file output. Encryption and signing commands also allow input data to be read from files. Additional features include improved handling of designated revocation keys, new context flags for advanced operations like importing options and processing all signatures and the introduction of an easier method to change owner trust and enable or disable keys. The Qt library now supports simultaneous builds for Qt 5 and Qt 6, enabling file-based operations for encryption and signing while offering better integration for importing options and appending detached signatures.
- gtk4 4.16.3: This update enhances how default cursor themes are handled by searching within XDG directories to ensure better compatibility with Wayland environments. The default cursor size now matches the gsettings schema and provides a more consistent user experience. The fallback process for portal settings was refined as settings_portal is cleared when switching to fallback without portal settings. This release also includes updated translations.
-
php8 8.3.14: Fixes include addressing segmentation faults in DOM, GD, and FFI, memory leak in Reflection and OpenSSL, and use-after-free vulnerabilities in SPL and sockets. The update also resolves overflows in multiple modules, such as
mbstring,streamsandGMPfor more stable and secure handling of edge cases. Notable security improvements include patches for out-of-bounds writes in LDAP CVE-2024-8932, heap buffer over-reads in MySQLnd CVE-2024-8929, and CRLF injection vulnerabilities in streams CVE-2024-11234. -
ibus 1.5.31: This includes enhanced CI support for both generic setups and Wayland environments, as well as updates to compose keys based on the latest Xorg and GTK standards. The release transitions to using
localectlfor XKB configuration retrieval in Wayland, enhancing integration. Security improvements include a change to the IBus unique name, while updates to XKB engines and Unicode categories ensure broader compatibility. This version resolves various issues, including problems with X11 applications and games, Emoji handling, Flatpak integration, and preedit behavior in specific input methods likem17n:sa:itrans.
Bug Fixes and Security Updates
Several key security vulnerabilities were addressed this month:
- Firefox 132:
-
CVE-2024-10458: Permission leak via embed or object elements.
- CVE-2024-10459: Use-after-free in layout with accessibility, potentially leading to an exploitable crash.
- CVE-2024-10460: Confusing display of origin for external protocol handler prompt.
- CVE-2024-10461: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response.
- CVE-2024-10462: Origin of permission prompt could be spoofed by a long URL.
- CVE-2024-10463: Cross-origin video frame leak in some conditions.
- CVE-2024-10468: Race conditions in IndexedDB could cause memory corruption and a potentially exploitable crash.
- CVE-2024-10464: History interface could cause a Denial of Service condition.
- CVE-2024-10465: Clipboard “paste” button persisted across tabs, allowing a potential spoofing attack.
- CVE-2024-10466: DOM push subscription message could hang Firefox, causing it to become unresponsive.
- CVE-2024-10467: Memory safety bugs fixed, potentially exploitable to run arbitrary code.
-
php8 8.3.14:
- CVE-2024-8932: An out-of-bounds access in the LDAP extension’s ldap_escape function.
- CVE-2024-8929: A heap buffer over-read in MySQLnd that could leak partial heap content.
- CVE-2024-11233: An issue in the Streams component allowing potential CRLF injection via proxy configurations.
- CVE-2024-11234: A vulnerability in the Streams component related to CRLF injection.
- CVE-2024-11236: Integer overflows in PDO DBLIB and PDO Firebird quoters, leading to out-of-bounds writes.
-
opensc 0.26.0:
-
CVE-2024-45615: Uninitialized values in
libopenscandpkcs15initcould lead to undefined behavior. -
CVE-2024-45616: Incorrect checks or usage of APDU response values in
libopenscmay result in uninitialized values. -
CVE-2024-45617: Missing or incorrect return value checks in
libopensccan cause uninitialized values. -
CVE-2024-45618: Similar issues in
pkcs15initdue to improper return value handling. -
CVE-2024-45619**: Improper handling of buffer or file lengths in
libopensc. -
CVE-2024-45620**: Similar buffer or file length handling issues in
pkcs15init. - CVE-2024-8443**: A heap buffer overflow in the OpenPGP driver during key generation.
-
CVE-2024-45615: Uninitialized values in
-
libsoup:
-
CVE-2024-52531: A buffer overflow in
soup_header_parse_param_list_strictcould occur during UTF-8 conversion in applications using libsoup versions prior to 3.6.1. This issue cannot be triggered by input received over the network. - CVE-2024-52532: An infinite loop and excessive memory consumption were possible when reading certain patterns of WebSocket data from clients in libsoup versions before 3.6.1.
-
CVE-2024-52531: A buffer overflow in
-
mozjs128 128.4.0:
-
CVE-2024-10458: Permission leak via
embedorobjectelements. - CVE-2024-10459: Use-after-free in layout with accessibility.
- CVE-2024-10460: Confusing display of origin for external protocol handler prompt.
- CVE-2024-10461: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response.
- CVE-2024-10462: Origin of permission prompt could be spoofed by long URL.
- CVE-2024-10463: Cross-origin video frame leak.
- CVE-2024-10464: History interface could cause a Denial of Service condition.
- CVE-2024-10465: Clipboard “paste” button persisted across tabs.
- CVE-2024-10466: DOM push subscription message could hang Firefox.
- CVE-2024-10467: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4
-
CVE-2024-10458: Permission leak via
-
postgresql17 17.1:
- CVE-2024-10976: Incomplete tracking of tables with row-level security could allow reused queries to access unintended rows.
- CVE-2024-10977: Error messages during SSL or GSS protocol negotiation could be spoofed by a man-in-the-middle.
- CVE-2024-10978: Incorrect privilege assignment could allow less-privileged users to view or modify unintended rows.
- CVE-2024-10979: In PL/Perl, unprivileged database users could alter sensitive process environment variables, potentially leading to arbitrary code execution.
-
libssh2_org 1.11.1:
- CVE-2023-48795: A vulnerability that could cause mishandled handshake and sequence numbers, allowing attackers to bypass integrity checks and downgrade security features in certain OpenSSH extensions.
-
Xen 4.19.0_06:
- CVE-2024-45818: Fixed a deadlock in x86 HVM standard VGA handling.
-
CVE-2024-45819: Only x86 systems running PVH guests are affected; HVM and PV guests are not vulnerable. The
libxltoolstack may leak data to PVH guests via ACPI tables.
-
python-tornado6 6.4.2:
- CVE-2024-52804: The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue
Conclusion
November 2024 was another stellar month for Tumbleweed as it showcased its commitment to delivering the newest software with an impressive array of updates. Notable updates to Mesa, GTK4, KDE Plasma, PostgreSQL and more provide rolling release users with the latest in open-source technology for a secure and robust system. Keep rolling forward, and don’t forget to check out the detailed changelogs and discussions on the openSUSE Factory mailing list. Here’s to another month of seamless updates—happy tumbling!
Slowroll Arrivals
Please note that these updates also apply to Slowroll and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users.
Contributing to openSUSE Tumbleweed
Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list. For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the openSUSE Factory mailing list . The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.
Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.
stalld: unpatched fixed temporary file use and other issues
Table of Contents
- 1) Introduction
-
2) Use of Fixed Temporary File Path
/tmp/rtthrottleinscripts/throttlectl.sh - 3) The
fill_process_comm()Function Might Read Unexpected Control Characters - 4) Experimental FIFO Boosting Feature might have a Danger of Locking up the System
- 5) Potential Race Conditions when Accessing
/proc/<pid>/{status,comm} - 6) Weird
umask()Setting used indaemonize() - 7) CVE Assignments
- 8) Timeline
- 9) References
1) Introduction
Stalld is a daemon that aims to prevent starvation of operating system threads on Linux. It has recently been added to openSUSE Tumbleweed and we performed a routine review of the contained systemd service. During the review we noticed a couple of security issues that should be addressed.
We reached out to upstream via their GitLab issue tracker and created a public and a private issue (still private), but never got any reaction. After nearly three months without a reply we decided to publish the available information now.
This report is based on stalld version v1.19.6.
2) Use of Fixed Temporary File Path /tmp/rtthrottle in scripts/throttlectl.sh
The throttlectl.sh script, which is called with root
privileges as a pre and post script in stalld’s systemd unit, is using the
fixed /tmp path /tmp/rtthrottle to cache the original values found in
/proc/sys/kernel/sched_rt_runtime_us and
/proc/sys/kernel/sched_rt_period_us. This allows for a symlink attack and
a file pre-creation attack.
2.a) Symlink Attack
A symlink attack can only work if the Linux kernel’s protected_symlinks
setting is not in effect. If that would be the case then an attacker could
place a symlink at the location causing throttlectl to overwrite arbitrary
files in the system, allowing for a local Denial-of-Service.
2.b) File Pre-Creation Attack
Pre-creating the path in /tmp/rtthrottle will always work, even if the
protected_regular setting in the kernel is active. This is the case because
the shell redirection in the script (like in the line echo $period >
$path/sched_rt_period_us) will fall back to opening the target file without
O_CREAT in the open() flags, if creating the file fails. Without O_CREAT
the protected_regular logic no longer triggers.
This means that if a local attacker pre-creates the file, the script will write
to a file owned by the attacker. By the time the script tries to restore the
values from this file, the local attacker can place arbitrary values in it,
which will in turn be written to the pseudo files in
/proc/sys/kernel/sched_rt_*. This is a kind of local Denial-of-Service or a
local integrity violation. It is not an information leak, because the content
of these pseudo files is world-accessible anyway.
2.c) Exploitability
When stalld starts at boot time, there is not much opportunity for unprivileged local users to exploit this issue. If the service is started at a later time, or restarted, then the attack vector is exploitable, though.
2.d) Suggested Fix
To fix this, we suggest to place the file into the /run/stalld directory,
which is owned by root. This directory is already created via stalld’s systemd
unit.
In the systemd unit some hardenings like PrivateTmp=yes could also be
applied to prevent any future temporary file issues of this type.
The throttlectl script should also set the errexit shell option to make it
exit upon any unexpected errors.
3) The fill_process_comm() Function Might Read Unexpected Control Characters
The fill_process_comm() function reads the content
of /proc/<pid>/comm from potentially untrusted processes in the system. The
data found in there is obtained from the name of the executable that the
kernel executed. Executable names can contain any data, except for the /
character. This also includes control characters like \r or even terminal
control sequences. This string is used by stalld to write information to
logs. By embedding a carriage return in an executable name, a local attacker
could achieve log spoofing.
To fix this, we suggest to transform any non-alphanumeric characters in the
string into some safe character like ?.
4) Experimental FIFO Boosting Feature might have a Danger of Locking up the System
Via the --force_fifo command line switch, stalld can be instructed to
“boost” stalled tasks by switching them to SCHED_FIFO scheduling. We are
wondering what happens if a “rogue task” is assigned to this scheduler. As far
as we know, if such a task never yields the CPU again, the whole system could
lock up. This might require stalld to run under SCHED_FIFO itself,
using a higher scheduling priority than the boosted task, to prevent any such
situation.
5) Potential Race Conditions when Accessing /proc/<pid>/{status,comm}
As usual, when iterating over the processes in the /proc file system, race
conditions can occur. Target processes could attempt to replace themselves by
other processes, confusing stalld. We don’t believe that the “stall” situation
can be provoked easily by a local attacker, though, thus the possibility to
exploit anything in this direction is likely small.
We just mention this as a hint to the reader, maybe we’re overlooking something more critical here.
6) Weird umask() Setting used in daemonize()
The daemonize() function applies a new umask to the daemon
process by calling umask(DAEMON_UMASK). The constant for this
has a weird value, though:
/*
* Daemon umask value.
*/
#define DAEMON_UMASK 0x133 /* 0644 */
We don’t know why an octal 0644 value isn’t used in the first place, instead
of writing this as a comment only. The constant 0x133 corresponds to an
octal value of 0463, though. It will mask out the owner-readable bit,
read-write bits for the group and write-execute bits for world. This is likely
not what was intended here.
Luckily no world-writable files will come into existence this way, but the misconfiguration could lead to strange effects in the future, e.g. because the owner of the file will not have read permissions for it.
We don’t believe this is a security issue, which is why we created a public issue in the upstream GitLab tracker for this.
7) CVE Assignments
Since upstream did not react and therefore also didn’t confirm any of these issues, we did not request any CVEs from Mitre until now. The fixed temporary file usage issue 2) likely is worthy of a CVE assignment, though.
8) Timeline
| 2024-09-09 | We reported the issues (1, 2) in the upstream GitLab project, offering coordinated disclosure for the sensitive issues. |
| 2024-11-13 | After getting no reaction for such a long time we commented in the issue, asking for a reply until 2024-11-22, otherwise we would publish the issue on our end. |
| 2024-11-28 | We published the information without upstream fixes being available. |
9) References
Juegos libres de calidad y en desarrollo noviembre 2024
Repito entrada recurrente. Os recuerdo que esta entrada mensual (que me salté el mes pasado) tiene como objetivo promocionar los juegos libres, pero no como una página que quede obsoleta o sea un cementerio de proyectos muertos, así que la voy a realizar poco a poco y con conocimiento de causa. Por ello, y conociendo mis limitaciones y mi estilo de trabajo, la voy a ir actualizando de forma mes a mes y su contenido se irá ampliando poco a poco a. De esta forma, bienvenidos a la entrada de juegos libres de calidad y en desarrollo de nobiembre 2024 en la que recopilo los juegos libres presentados en forma de entrada «tocha» en el blog ampliándola con OpenArena y con noticias breves algunos de los juegos presentados.
Juegos libres de calidad y en desarrollo septiembre 2024

Como decía al principio, esta entrada de la serie Juegos Libre de Calidad y en Desarrollo pretende ser una entrada viva y creciente, que tenga una parte fija pero dinámica en la que muestre no solo juegos libres sino también su estado de desarrollo, sus novedades principales y, si es posible, alguna noticia relevante de alguno de ellos: lanzamientos especiales, vídeos, premios, cambios notables, etc.
Para empezar utilizaré una tabla para mostrar la información y los juegos iniciales que aparecen son aquellos que he analizado a fondo en el blog dado que son los que tengo más claro su desarrollo, y cada més añadiré el siguiente que tengo en mente analizar.
| Género | Nombre | Presentado en el blog | Última actualización | Comentario | Otros juegos alternativos Libres o no. |
| Conducción | Speed-dreams | Si | Marzo 2024 Versión 2.3 |
Siempre activos en redes, sobre todo en X (ex-Twitter) | Need For Speed |
| Conducción | SuperTux Kart | Si | Septiembre 2023 1.4 Beta de 1.5, octubre 2024 |
Ya está aquí la beta de la versión 1.5. | SuperMario Kart |
| Estrategia por turnos | The Battle of Wesnoth | Si | 28 de octubre de 2024 Versión en desarrollo 1.19.5 9 de noviembre de 2024 versión estable 1.18.3 |
En la versión en desarrollo se está probando un menú principal rediseñado. | ?¿?League of Legends??¿ |
| Estrategia por turnos | Hedgewars | Si | Versión 1.0 el 9 de octubre de 2019 | Se está desarrollando un nuevo editor de temas. | Worms Warmux (proyecto libre sin desarrollo) |
| FPS | Alien Arena | Si | 7.71.7 (nueva) | ¡Alien Arena ha sido instalado más de 1500 veces desde Flathub! | Quake, Doom, Nexuiz, Unreal |
| FPS | Xonotic | Si |
20/06/2023 Versión 0.8.6 |
No necesita instalación | Quake, Doom, Nexuiz, Unreal |
| FPS | Si | Si | 0.8.8 2012 |
Para los amantes de la nostalgia hiperactiva. Se prepra en secreto su versión 3.0. | Quake, Doom, Nexuiz, Unreal |
| MMORPG | Ryzom | Si | 3 de julio de 2021 Versión 3.4.0 |
Es posible que esta no sea la última versión ya que se parchea muy seguido. | World of Warcraft Albion Online |
| MMORPG | Eternal Lands | Si | Diciembre de 2021 | A pesar de tener un cliente algo antiguo los foros están activos 100% | World of Warcraft Albion Online |
| Plataformas | Supertux | Si | 2021 Versón 0.6.3 |
Se estima que la 0.7.0 saldrá en agosto de 2024. | Super Mario |
| Plataformas | Frogatto & Friends | Si | 1.0 2010 |
Juego cerrado y completo | Wonder Boy |
| Simulación | Simutrans | Si | 3 de junio 2024 Simutrans 123 |
Disponible para Linux, Windows, Max, Steam y Android. | Transport Tycoon Deluxe |
| Simulación | OpenTTD | Si | 3 de mayo 2024 14.1 |
Disponible en Steam y Gog. | Transport Tycoon Deluxe |
Novedades de los juegos de la tabla
- Empezamos con Speed-dreams, el desarrolador Xavi92 ha grabado un video donde nos muestra las nuevas características en las que ha estado trabajando. Es posible generar competidores IA eligiendo coche y bot.
- El euipo de SuperTux Kart se complace en anunciar el lanzamiento de la primera beta de STK 1.5.
- Hilo especifico para escritores de The Battle of Wesnoth en su foro.
- Hilo específico de Xonotic para los traductores.
- [RYZOM] Trailer 25 – Free to play MMORPG for Windows, Mac and Linux
Y este mes no hay tiempo para más.
La entrada Juegos libres de calidad y en desarrollo noviembre 2024 se publicó primero en KDE Blog.
Project to have AMA with SUSE’s GM
The openSUSE community is invited to an online engagement with SUSE’s General Manager for Business Critical Linux on Dec. 3 at 16:00 UTC.
Rick Spencer, who leads the SUSE Linux Enterprise and SUSE Multi-Linux Manager teams, works closely with those contributing to openSUSE as part of his day-to-day roles. He is eager to strengthen the ties between SUSE and the openSUSE communities.
The Ask Me Anything session is an opportunity for open dialogue with members of the project and open-source contributors.
Participants can ask questions, share insights and learn about SUSE’s ongoing initiatives involving openSUSE and open-source development. Questions can also be submitted in advance to Rick Spencer or Gerald Pfeifer to guide the discussion.
Event Details:
-
Event: openSUSE Open Door Session with Rick Spencer
-
Date: Dec. 3, 2024
-
Time: 17:00–17:45 CET / 11:00–11:45 ET
-
Location: Online
How to Participate:
-
Submit Questions: Reach out to Rick Spencer or Gerald Pfeifer ahead of the session.
-
Join the Conversation: Online
Spencer provided the keynote at this year’s openSUSE Conference.
Syslog-ng Prometheus exporter added to RPM syslog-ng container image
Last week I introduced you to my latest project: a syslog-ng container based on Alma Linux. This week I added a syslog-ng Prometheus exporter to the container, so you can also monitor syslog-ng, if you enable it.

syslog-ng logo
Episodio 36 de KDE Express: Las distros KDE están on fire
Me congratula presentaros el episodio 35 de KDE Express, titulado «Las distros KDE están on fire» donde David Marzal sigue llevando en solitario estas más que interesantes píldoras. Un hurra por él.
Episodio 36 de KDE Express: Las distros KDE están on fire
Comenté hace ya bastante tiempo que había nacido KDE Express, un audio con noticias y la actualidad de la Comunidad KDE y del Software Libre con un formato breve (menos de 30 minutos) que complementan los que ya generaba la Comunidad de KDE España, aunque ahora estamos tomándonos un tiempo de respiro por diversos motivos, con sus ya veteranos Vídeo-Podcast que todavía podéis encontrar en Archive.org, Youtube, Ivoox, Spotify y Apple Podcast.
De esta forma, a lo largo de estos 36 episodios, promovidos principalmente por David Marzal, nos han contado un poco de todo: noticias, proyectos, eventos, etc., convirtiéndose (al menos para mi) uno de los podcast favoritos que me suelo encontrar en mi reproductor audio.
En palabras de David el nuevo episodio de KDE Express toca los siguientes temas:

Hacer copia de seguridad de todo, incluido de vuestros marcadores, listas y cuentas que seguis de Mastodon. Este episodio ha tardado más y tiene menos noticias por no hacer esas copias más regularmente. Y si os seguía y no teneis una petición, pegarme un toque a https://masto.es/@DavidMarzalC, que hice todo lo posible por buscar todas las cuentas que estaba siguiendo. Dicho lo cual, empezamos con las noticias KDE.
Artículo original con los enlaces en https://kdeexpress.gitlab.io/36/ Si no ves nada despues de esta linea en tu aplicación de podcast, es que no sabe leer bien el feed RSS, prueba otra 😉
- En Fedora 42 KDE se convertirá en una versión oficial y deja de ser un simple «spin». Español / English
- Y añade la opción de activar los repositorios de terceros en la pantalla de bienvenida
- Steam Deck actualiza a Plasma 5.27.10 (la última hasta la fecha en 5 es la 5.27.11 de marzo de 2024)
- Fedora lanza los spins Plasma Mobile y Kinote Mobile
- KDE Wave vuelve a estar en desarrollo más allá de mantenimiento básico
- Proyecto Banana, una distro atómica/inmutable en desarrollo por KDE. Basada en Arch y Brtfs.
- Plasma 6.3 (2025-02-11):
- Mejoras para tabletas
- Notificación cuando el sistema ha tenido que matar algún proceso por falta de memoria.
- Dolphin tiene una nueva interfaz para dispositivos moviles desde la 24.12
- El centro de información mostrará todas tus GPUs
- Discover te informará si la aplicación viene directamente de los desarrolladores o de voluntarios.
- El widget de impresora ahora muestra la información de la cola directamente
- El widget de indicador de teclado ahora muestra cuando las teclas modificadores están bloqueadas o «latched» por accesibilidad.
Y, como siempre, os dejo aquí el listado de los episodios. ¡Disfrutad!
Por cierto, también podéis encontrarlos en Telegram: https://t.me/KDEexpress
La entrada Episodio 36 de KDE Express: Las distros KDE están on fire se publicó primero en KDE Blog.
Cuarta actualización de Plasma 6.2
Me alegra compartir con todos vosotros la cuarta actualización de Plasma 6.2, iniciando así una serie de revisión de software que le dotará de más estabilidad, mejores traducción y resolución de errores. Estas actualizaciones son 100% recomendables y casi obligatorias para cualquier usuario ya que lo único que hacen es mejorar la versión sin comprometer sus funcionalidades.
Cuarta actualización de Plasma 6.2
No existe Software creado por la humanidad que no contenga errores. Es un hecho incontestable y cuya única solución son las actualizaciones. Es por ello que en el ciclo de desarrollo del software creado por la Comunidad KDE se incluye siempre las fechas de las mismas siguiendo una especie de serie de Fibonacci.
La Comunidad KDE ha publicado la primera actualización de Plasma 6.2, una versión que viene a subsanar los errores más graves del gran salto en cuanto a tecnología que fue Plasma 6 y Plasma 6.1.

Así que me congratula en presentar que hoy martes 26 de noviembre de 2024, un mes después de liberar el código de Plasma 6.2 la Comunidad KDE presenta la cuarta actualización de errores.
- libkscreen Doctor: aclarado el significado de brillo máximo cero.
- Espacio de trabajo Plasma: Icono de batería, añadido icono de auriculares.
- Control de volumen de audio Plasma: Arreglado el diseño de prueba de los altavoces para el perfil Pro-Audio
Más información: KDE
Las novedades generales de Plasma 6.2
Aprovecho para realizar un listado de las novedades generales de Plasma 6.2:
- Opción para reasignar los botones del lápiz de la tableta de dibujo a distintos tipos de clics del ratón.
- Capacidad de anular aplicaciones que bloquean la suspensión o el bloqueo de la pantalla.
- Discover es compatible ahora con PostmarketOS.
- Se ha renovado la interfaz gráfica del módulo Accesibilidad de las Preferencias del sistema para mayor… ¡accesibilidad!
- Nueva experiencia de usuario para el modo de edición de Plasma, para hacer que su modalidad sea más obvia y visualmente más elegante.
- Previsión meteorológica: Pronóstico nocturno del proveedor meteorológico NOAA.
- Opción para desactivar el desplazamiento suave en las aplicaciones de KDE.
- Se ha mejorado la organización de la vista de cuadrícula expandida de la bandeja del sistema.
- Ahora se reproduce un sonido al conectar o desconectar una pantalla.
- Herramienta de recorte integrada cuando se selecciona el avatar del usuario.
La entrada Cuarta actualización de Plasma 6.2 se publicó primero en KDE Blog.
With
With Microsoft ending support for Windows 10 in October 2025, millions of users are looking for alternatives that avoid costly hardware upgrades, additional upgrade costs to Windows 11 depending on the country a person is in or to mitigate security risks.
A compelling options for many are open-source operating systems. Linux distributions like openSUSE and others extend the life of hardware, enhance security and provide flexibility without additional expenses.
For those who reached this point, this Upgrade to Freedom guide will detail a beginner-friendly approach to transitioning from Windows to one of openSUSE’s distributions, which are known for being user-friendly, stable, and powerful.
Step 1: Prepare Your System
Before diving into the installation process, take the following steps to prepare:
-
Back Up Your Data
Save important files to an external drive, cloud storage or another secure location. Transitioning to Linux distributions typically involves reformatting your hard drive, which will erase existing data. -
Check Your Hardware Compatibility
Most modern hardware works well with Linux, but it’s good practice to confirm compatibility. Visit the openSUSE wiki for more information. -
Choose Your Version of openSUSE
openSUSE offers two versions:- Leap: A stable release designed for extended reliability and maintenance.
- Tumbleweed: A rolling release with the latest updates.
Beginners often prefer Leap for its stability. Tumbleweed will have constant, almost daily updates. Tumbleweed is favored by enthusiasts and developers who prioritize access to the newest features, technologies, and software update
Step 2: Download openSUSE
- Visit get.opensuse.org.
- Select the version you prefer (Leap or Tumbleweed).
- Download the ISO file to your computer.
Step 3: Create a Bootable USB
You’ll need a USB drive (at least 8GB) to install openSUSE.
-
Insert a USB Drive
Plug the USB drive into your computer. -
Create the Bootable USB
Use software like:- Rufus (Windows)
- Etcher (cross-platform)
Select the downloaded openSUSE ISO file and follow the tool’s instructions to write the ISO to the USB drive.
Step 4: Boot Into the Installer
-
Restart Your Computer
During the boot process, press the key to enter your BIOS or boot menu (typically F2, F10, F12, or Delete). -
Select the USB Drive
From the boot menu, choose your USB drive as the boot device. Then save and exit. -
Start the Installation
When the openSUSE installer loads, select “Install.”
Step 5: Install openSUSE
The openSUSE installer will guide you through the setup process.
-
Select Your Language and Region
Choose your preferred language and time zone. -
Partition Your Drive
- Select automatic partitioning if you’re unsure.
- For advanced users, manual partitioning allows custom setups.
-
Create a User Account
Set up a username, password, and root (administrator) password. -
Review and Confirm
The installer will show a summary of your settings. Confirm to begin the installation.
There are options to select Desktop Environments (DE) during instalations. GNOME, KDE Plasma, Xfce and more. It’s a good idea to research these DEs beforehand to find one that matches your preferences. Many new users find GNOME reminiscent of macOS, while KDE Plasma and Xfce are often compared by new users to the traditional Windows desktop.
Step 6: Configure Your System
Once the installation is complete, restart your computer and remove the USB drive. openSUSE will boot up, and you can begin configuring your system.
-
Set Up Updates
Run the following command in the terminal to update your system: Leapsudo zypper updateTumbleweed
sudo zypper dupCongratulations on your Upgrade to Freedom!!!
Moving to Linux offers significant environmental benefits, as highlighted by Joanna Murzyn at the 2024 KDE Akademy conference, where she warned about the growing e-waste crisis and emphasized the importance of extending the lifespan of perfectly usable computers in her presentation, Only Hackers Will Survive.
This is part of a series on Upgrade to Freedom where we offer reasons to transition from Windows to Linux.
Transition from Windows to Linux: A Step-by-Step Guide
With Microsoft ending support for Windows 10 in October 2025, millions of users are looking for alternatives that avoid costly hardware upgrades, additional upgrade costs to Windows 11 depending on the country a person is in or to mitigate security risks.
A compelling options for many are open-source operating systems. Linux distributions like openSUSE and others extend the life of hardware, enhance security and provide flexibility without additional expenses.
For those who reached this point, this Upgrade to Freedom guide will detail a beginner-friendly approach to transitioning from Windows to one of openSUSE’s distributions, which are known for being user-friendly, stable, and powerful.
Step 1: Prepare Your System
Before diving into the installation process, take the following steps to prepare:
-
Back Up Your Data
Save important files to an external drive, cloud storage or another secure location. Transitioning to Linux distributions typically involves reformatting your hard drive, which will erase existing data. -
Check Your Hardware Compatibility
Most modern hardware works well with Linux, but it’s good practice to confirm compatibility. Visit the openSUSE wiki for more information. -
Choose Your Version of openSUSE
openSUSE offers two versions:- Leap: A stable release designed for extended reliability and maintenance.
- Tumbleweed: A rolling release with the latest updates.
Beginners often prefer Leap for its stability. Tumbleweed will have constant, almost daily updates. Tumbleweed is favored by enthusiasts and developers who prioritize access to the newest features, technologies, and software update
Step 2: Download openSUSE
- Visit get.opensuse.org.
- Select the version you prefer (Leap or Tumbleweed).
- Download the ISO file to your computer.
Step 3: Create a Bootable USB
You’ll need a USB drive (at least 8GB) to install openSUSE.
-
Insert a USB Drive
Plug the USB drive into your computer. -
Create the Bootable USB
Use software like:- Rufus (Windows)
- Etcher (cross-platform)
Select the downloaded openSUSE ISO file and follow the tool’s instructions to write the ISO to the USB drive.
Step 4: Boot Into the Installer
-
Restart Your Computer
During the boot process, press the key to enter your BIOS or boot menu (typically F2, F10, F12, or Delete). -
Select the USB Drive
From the boot menu, choose your USB drive as the boot device. Then save and exit. -
Start the Installation
When the openSUSE installer loads, select “Install.”
Step 5: Install openSUSE
The openSUSE installer will guide you through the setup process.
-
Select Your Language and Region
Choose your preferred language and time zone. -
Partition Your Drive
- Select automatic partitioning if you’re unsure.
- For advanced users, manual partitioning allows custom setups.
-
Create a User Account
Set up a username, password, and root (administrator) password. -
Review and Confirm
The installer will show a summary of your settings. Confirm to begin the installation.
There are options to select Desktop Environments (DE) during instalations. GNOME, KDE Plasma, Xfce and more. It’s a good idea to research these DEs beforehand to find one that matches your preferences. Many new users find GNOME reminiscent of macOS, while KDE Plasma and Xfce are often compared by new users to the traditional Windows desktop.
Step 6: Configure Your System
Once the installation is complete, restart your computer and remove the USB drive. openSUSE will boot up, and you can begin configuring your system.
-
Set Up Updates
Run the following command in the terminal to update your system: Leapsudo zypper updateTumbleweed
sudo zypper dupCongratulations on your Upgrade to Freedom!!!
Moving to Linux offers significant environmental benefits, as highlighted by Joanna Murzyn at the 2024 KDE Akademy conference, where she warned about the growing e-waste crisis and emphasized the importance of extending the lifespan of perfectly usable computers in her presentation, Only Hackers Will Survive.
This is part of a series on Upgrade to Freedom where we offer reasons to transition from Windows to Linux.Those who would like to order a laptop with Linux, can visit slimbook.com or other providers of Linux machines.
tuned: local root exploit in D-Bus method instance_create and other issues in tuned >= 2.23 (CVE-2024-52336, CVE-2024-52337)
Table of Contents
- 1) Introduction
-
2) Problems in the
instance_createD-Bus Method - 3) Problems in the PowerProfiles Interface
- 4) Bugfixes
- 5) Timeline
- 6) References
1) Introduction
Tuned is a privileged daemon for Linux that supports automatic tuning of various hardware and kernel settings during runtime. The daemon offers a comprehensive D-Bus interface protected by Polkit authentication. We regularly perform reviews of newly introduced D-Bus system services and changes to them. Tuned sees frequent additions to its D-Bus interface and this is already the tenth review of it that we carried out since 2019. Usually the reviews are straightforward and we have no complaints, but this time was the exception.
During the review we checked the D-Bus methods matching the following Polkit actions:
com.redhat.tuned.instance_create (auth_admin:auth_admin:yes)
com.redhat.tuned.instance_destroy (auth_admin:auth_admin:yes)
net.hadess.PowerProfiles.HoldProfile (no:no:yes)
net.hadess.PowerProfiles.ReleaseProfile (no:no:yes)
This report is based on tuned release v2.24.0.
2) Problems in the instance_create D-Bus Method
Calling the instance_create() D-Bus method is allowed without
authentication for locally logged-in users (yes Polkit setting). The method
call accepts various parameters, including an options dictionary, that are
fully under attacker control.
2a) Script Options Allow Local Root Exploit (CVE-2024-52336)
The script_pre and script_post options allow to pass arbitrary scripts
that will be executed by root. The parameters are extracted in
daemon/controller.py:459, stored unmodified in a new
Instance object and the only verification of the script path is performed in
plugins/base.py:222:
if not script.startswith("/"):
log.error("Relative paths cannot be used in script_pre or script_post. " \
+ "Use ${i:PROFILE_DIR}.")
return False
So the only requirement is that an absolute path is passed. Thus, scripts under control of an unprivileged user can be passed here. This allows for a local root exploit.
Reproducer
As a locally logged-in non-privileged user execute the following D-Bus call:
$ gdbus call -y -d com.redhat.tuned -o /Tuned \
-m com.redhat.tuned.control.instance_create cpu myinstance \
'{"script_pre": "/path/to/myscript.sh", "devices": "*"}'
The path /path/to/myscript.sh needs to be replaced by a path to a user controlled executable script or program. It will be executed by tuned with root privileges.
2b) Instance Name can Contain Arbitrary Data (CVE-2024-52337)
The instance_name parameter of the instance_create() method is not
sanitized. This string is later on used in logging and in the output of
utilities like tuned-adm get_instances, or other third party programs that
utilize tuned’s D-Bus interface to obtain instance names.
A local attacker can include arbitrary data in the instance name and can achieve log spoofing this way. By placing newline characters into the name, seemingly independent, legitimate-looking entries can be added to the tuned log. By adding terminal control sequences the terminal emulators of administrators or other users can be influenced. The following is a Proof-of-Concept for this:
$ EVIL=`echo -e "this is\nevil\033[?1047h"`
$ gdbus call -y -d com.redhat.tuned -o /Tuned -m com.redhat.tuned.control.instance_create cpu "$EVIL" '{"devices": "*"}'
When another user now calls tuned-adm get_instances then the terminal emulator
will switch to the alternate screen upon output of the crafted instance name.
Affectedness
The instance_create() D-Bus method has been added via upstream commit
cddcd233 and was first part of version tag
v2.23.0. The initial version already contained support for the script option
parameters and the instance_name parameter.
3) Problems in the PowerProfiles Interface
3a) Cookie in PowerProfiles API is Predictable
The new D-Bus methods HoldProfile() and ReleaseProfile() use a cookie to
identify a profile hold. The cookie is simply a continuously increasing
integer starting at zero. This means other users in the system can easily
release the profile holds of other users.
3b) User Supplied Strings can Contain Arbitrary Data
The HoldProfile() call accepts reason and app_id strings which are used
in logging and may also be returned as a dictionary via
ProfileHold.as_dict(). These strings can again contain crafted data that
could have side effects similar to the ones shown in section 2b).
Suggested Fix
A local DoS scenario using the cookie would only be an issue on multi-user
systems, or if the Polkit settings are relaxed so that also non-local sessions
can use these D-Bus methods. One way to make this more robust could be to hand
out random cookie IDs instead, to make the attack less trivial.
4) Bugfixes
Upstream published release v2.24.1 that addresses the issues described in this report. Commit 90c24eea037 contains the cumulative fixes as follows:
- plugins are now only loaded from trusted locations (
_safe_script_path()function). - various user supplied strings are rejected if they contain disallowed
characters (
is_valid_name()function). - upstream also tightened the tuned Polkit policy for
instance_createand a number of other actions, that they also found to be problematic when accessed by local unprivileged users.
For issue 3a) no upstream fix is available at the moment. This is more of a hardening suggestion, though.
5) Timeline
| 2024-11-07 | We reported the issues to the Red Hat security team. |
| 2024-11-08 | Red Hat security confirmed the issues and communicated the CVE assignments to us, and the publication date of 2024-11-26 was suggested. |
| 2024-11-11 | Red Hat shared the suggested patch and we reviewed it. |
| 2024-11-26 | The publication date has been reached and publication happened as planned. |