Linux kernel vulnerability allows remote code execution
A kernel vulnerability allowed authenticated remote users to leak information and execute code.
Read the full post32 posts
Projects, Linux, networks, systems, finds and internet standards from 2022.
A kernel vulnerability allowed authenticated remote users to leak information and execute code.
Read the full postJohannes presents his winter selection of microcontrollers, displays, RFID, CAN, storage and interface modules. Among others, RP2040, ATmega328, ATtiny85 and ATmega32U4 are named. An MCP2515 module adds CAN bus support.
Read the full postThe article explains model cards as structured companions to weights and code. They are meant to make purpose, data, metrics, limits and responsible use discoverable. Model cards live as the README in the respective Hub repository.
Read the full postCNLohr recreates a simple RISC-V processor without an MMU and boots uClinux and Doom on it. The project is publicly available on GitHub. The emulated processor has no MMU.
Read the full postHackaday explains an ATtiny85 adapter that makes I²C sensors available via USB as a regular Linux I²C bus. The example names the BMP280 and Si1145. Debian Sid already contained a suitable BMP280 driver.
Read the full postKG examines the seemingly simple disposal of radioactive waste by rocket and shows why mass, cost and failed launches devalue the concept. Disposal proposals often fail because risk is concentrated during transport. A technically possible solution can be considerably worse than a boring local one.
Read the full postOptimum Intel exports transformers for OpenVINO and runs them optimised on Intel hardware. The article combines model conversion, quantisation and pipeline use. OpenVINO optimises neural networks for Intel processors and other Intel hardware.
Read the full postThe report follows the optimisation of a 176-billion-parameter model from memory planning to distributed execution. It shows that production inference is a systems problem of parallelisation, kernels and communication. BLOOM is too large for the memory of a single common GPU.
Read the full postAccelerate distributes model parts across GPU, CPU and disk instead of first building the whole model in memory. Empty initialisation and automatic device maps avoid unnecessary peaks. init_empty_weights first creates the model structure without parameter data.
Read the full postIn 2022 researchers from the Vietnamese telecommunications group Viettel found a buffer overflow in the web-based ping tool of the low-cost TP-Link TL-WR841N Wi-Fi router (CVE-2022-30024). Logged-in attackers could execute their own code via an overlong host address and, for example, install a backdoor. TP-Link delivered updates for revisions V10 to V12 and declared older devices end-of-life.
Read the full postThe bitsandbytes integration loads large models with 8-bit weights and handles sensitive outliers separately. This lowers memory requirements while important numerical parts keep higher precision. LLM.int8 combines 8-bit matrix multiplication with higher-precision handling of outliers.
Read the full postGlen Vivaris turns a used IKEA desk with a recessed drawer, printed greeblies and an aged paint finish into a movie-style workbench. The base desk came from the second-hand market. Many details were 3D printed.
Read the full postWith Chrome 104 in August 2022, Google closed 27 security holes, at least seven of them high-risk; one earned its discoverer a bounty of 15,000 US dollars. Microsoft followed with Edge 104 and additionally fixed three Edge-specific bugs, including a critical sandbox escape (CVE-2022-33649, CVSS 9.6). Also new were Media Queries Level 4 and Web Bundles for faster loading.
Read the full postIn 2022 Trellix found a critical hole (CVE-2022-32548, CVSS 10.0) in numerous DrayTek routers through which unauthenticated attackers could take over the devices. A logic error in the length check on the login page /cgi-bin/wlogin.cgi led to a buffer overflow, exploitable from the LAN or via the internet if management was reachable there. The researchers found more than 200,000 vulnerable devices on the net.
Read the full postBLOOM was created as an international community project for open access to a very large language model. The article describes the languages, computing effort and the joint organisation behind the training. BLOOM has 176 billion parameters.
Read the full postSecurity tips only help if they explain risks and do not create false trust in individual measures.
Read the full postFrom an ISP’s perspective, Lutz Donnerhacke describes how sanctions lists lead to network blocks, overblocking and unclear responsibility between authorities and operators. The list at the time sometimes contained complete URLs instead of only domains. At least one operator who was contacted removed the linked content in question.
Read the full postManuel Schmitt describes the gradual switch of an entire hosting platform to separate PHP-FPM pools for each web hosting package. The switch was rolled out gradually over about a week and a half. Each web hosting package received its own FPM pool.
Read the full postThe guide shows how to export and validate Transformers models in ONNX format. This decouples the trained model from PyTorch and opens the way to specialised runtimes. Optimum provides command-line and Python routes for ONNX export.
Read the full postA new case with external water cooling shrinks the PlayStation 5 drastically and reveals its thermal limits. The original video has the ID he6xyl_MHXY. Compactness often comes from moving things elsewhere rather than from components disappearing.
Read the full postRFC 9114 maps HTTP semantics onto QUIC and avoids TCP-induced blocking between independent streams. HTTP/3 ties application and transport development more closely together than earlier versions. UDP reachability becomes an important operational factor again.
Read the full postRFC 9110 defines the shared semantics of HTTP independently of the concrete transport versions. Separate semantics allow HTTP/1.1, HTTP/2 and HTTP/3 to share a common basis. Clear terms reduce contradictory implementations.
Read the full postHilko Bengen shows how Linux auditd delivers fine-grained host events and how the unwieldy format can be made usable for attack detection with reasonable effort. Network monitoring only detects many attacks together with context from the affected host. More telemetry only helps if events are reliably correlated and prioritised.
Read the full postOptimum integrates optimised runtimes into familiar Transformers pipelines. This allows models to be accelerated with ONNX Runtime without rewriting the whole application. Optimum offers ORTModel classes for ONNX Runtime.
Read the full postThe article explains a design philosophy that puts readable, model-specific code above maximum abstraction. Deliberate repetition is meant to make changes, troubleshooting and research easier. Many model implementations remain readable as standalone Python files.
Read the full postDecision Transformers formulate reinforcement learning as predicting actions from states and a desired return. This allows well-known transformer training methods to be applied to offline trajectories. The model processes return-to-go, states and actions as a sequence.
Read the full postYour own Linux router gives you control over interfaces, firewall, updates and local network services.
Read the full postThe article splits long audio files into overlapping windows and then puts the recognition back together. This allows a model with a limited input window to process continuous recordings. With long input, Wav2Vec2 works with limited excerpts.
Read the full postIn 2022 Arduino co-founder Gianluca Martino wanted to fund the Jolly module via Kickstarter; it replaces the Arduino Uno’s microcontroller with a variant with Wi-Fi. It combines an ATmega328PB with an ESP8285 including 2 MByte of flash, an integrated antenna and Wi-Fi 4. Because the chip is compatible with the ATmega328P, form factor, GPIO pins and existing Arduino software are meant to keep working.
Read the full postThe case study optimises transformer inference on CPUs with ONNX Runtime, quantisation and dynamic batching. It shows when existing server hardware can be a practical alternative to GPUs. The platform runs optimised transformer models on modern CPUs.
Read the full postGolem’s short news of 5 January 2022 reported that the Chinese manufacturer Zhaoxin was planning new x86 processors for desktop and server for 2022, without giving details. The current state was, for example, the KX-U6780A with eight cores and 16 nm manufacturing. Further topics were a VA-API backend for Nvidia’s NVDEC under Linux and an AR chip from Qualcomm for Microsoft.
Read the full postIn January 2022 Ingo Molnar presented the “Fast Kernel Headers” project, a comprehensive overhaul of the Linux kernel’s roughly 10,000 header files. With more than 2,200 patches changing more than half of all source files, the “dependency hell” was to be untangled. According to initial benchmarks, build time was reduced by 78 percent, and in some cases considerably more for incremental builds.
Read the full post