frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Security vulnerability found in Rust Linux kernel code

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=3e0ae02ba831da2b707905f4e602e43f8507b8cc
34•lelanthran•10h ago

Comments

pityJuke•9h ago
Within the Android drivers, right?
uhfraid•9h ago
yes
jeroenhd•9h ago
Technically, binder is still part of Linux, even if it's not enabled by default in many cases.

This "security vulnerability" is just a local DoS though. Annoying and problematic as it effectively bypasses controls over power on/off behaviour, but as far as I can tell from this report, no memory is leaked and no code execution can be achieved.

yourdetect•8h ago
It's UB, it is not memory safe, so in theory, and often also in practice with this specific kind of bug, absolutely anything could happen, including code execution.

Greg Kroah-Hartman's comment is both wrong and perplexing.

dizhn•9h ago
The URL this points to does not say anything about security. There's an example of a race condition causing memory corruption and a crash.
LukeShu•9h ago
While it doesn't add much more info: https://lore.kernel.org/linux-cve-announce/2025121614-CVE-20...
aw1621107•9h ago
Effectively a dupe of this thread from ~14 hours ago: https://news.ycombinator.com/item?id=46302621 (130 comments as of this comment)
thesz•8h ago
The mistake there is a classical example of why (software) transactional memory is valuable. Double linked lists are trivial in single core execution, need PhD level understanding of everything in multicore execution and become trivial again in multicore execution with (S)TM.

Rust has troubles with STM because it lacks anything resembling effect system. Most probably, this will not be fixed.

dlahoda•36m ago
may you share links to read or vote to understand better and push for?
arowthway•7h ago
I hate this bot-detection anime girl popping up on my monitor while I pretend to be working. Same goes for the funny pictures at the beginning of some Github readmes. Sorry for complaining about a tangential annoyance, but I haven't seen this particular sentiment expressed yet.
udjdndndjdjr•7h ago
I had an idea!

Instead of using this to do some proof of work, why not just get the bot detector to mine bitcoin or something...

I mean it is just as useless... And at least the website gets some money back from the raw extraction of data now happening...

Edit: speeeeeling

udjdndndjdjr•7h ago
Also this is a joke
dlahoda•33m ago
this was the plan, this was the plan. just wait little bit it get spread more.
sebtron•7h ago
Normally I don't mind, but on this page it took at least 15 seconds for me.
megnu•7h ago
I use a uBlock Origin filter to block the anime girl from loading:

  ! Title: Hide Anubis Image
  */.within.website/x/cmd/anubis/static/img/*.webp$image
jraph•6h ago
It is expressed very often.
jsiepkes•5h ago
I don't get why this is noteworthy? It's literally a piece of code in a Rust "unsafe" block. If you put something in an "unsafe" block the compiler isn't going to help you, you are on your own. That's why it's called "unsafe".

Now what is kinda interesting is that instead of getting rid of the "unsafe" block the developers put in some extra check. I guess you can take the developer out of C but you can't take the C out of the developer?

U.S. Military members to get $1,776 'warrior dividend'

https://wpde.com/news/nation-world/president-donald-trump-announces-1776-warrior-dividend-checks-...
1•geox•1m ago•0 comments

Show HN: Free PDF tools that run in the browser

https://pdf.makr.io/
1•iowadev•2m ago•0 comments

Ask HN: How do I bridge the gap between PhD and SWE experiences?

1•ecophyseis•3m ago•0 comments

Show HN: ZAI Shell – Self-healing CLI agent that fixes command errors

https://github.com/TaklaXBR/zai-shell
1•taklaxbr•3m ago•0 comments

Mystery Drones, Or Maybe UFOs, Over Sweetwater County Are 'The New Normal'

https://cowboystatedaily.com/2025/12/15/mystery-drones-or-maybe-ufos-over-sweetwater-county-are-t...
1•sipofwater•5m ago•1 comments

Conductor: Context-driven development for Gemini CLI

https://developers.googleblog.com/conductor-introducing-context-driven-development-for-gemini-cli/
1•keithba•6m ago•0 comments

Chatbots inform young voters but don't change their vote choices

https://www.pnas.org/doi/10.1073/pnas.2515516122
1•zerolatitude•6m ago•0 comments

Making agentic government work: 7 principles for safer, smarter AI adoption

https://www.nextgov.com/ideas/2025/12/making-agentic-government-work-7-principles-safer-smarter-a...
1•WaitWaitWha•8m ago•0 comments

Toys with the highest play-time and lowest clean-up-time

https://joannabregan.substack.com/p/toys-with-the-highest-play-time-and
1•surprisetalk•8m ago•0 comments

There's no such thing as a fake feather [video]

https://www.youtube.com/watch?v=N5yV1Q9O6r4
1•surprisetalk•8m ago•0 comments

Remove Black Color with Shaders

https://yuanchuan.dev/remove-black-color-with-shaders
1•surprisetalk•9m ago•0 comments

I figured out how to stop making engines and start making games [video]

https://www.youtube.com/watch?v=3kzNiMMnT4U
2•surprisetalk•9m ago•0 comments

Asahi Linux Progress Linux 6.18

https://asahilinux.org/2025/12/progress-report-6-18/
1•birdculture•9m ago•0 comments

The Year in Physics

https://www.quantamagazine.org/the-year-in-physics-20251217/
1•ibobev•9m ago•0 comments

The Open Evaluation Standard: Benchmarking Nvidia Nemotron 3 Nano

https://huggingface.co/blog/nvidia/nemotron-3-nano-evaluation-recipe
1•ibobev•9m ago•0 comments

Military Standard on Software Control Levels

https://entropicthoughts.com/mil-std-882e-software-control
5•ibobev•10m ago•0 comments

Don't Worry About College Majors

https://thinkhuman.com/dont-worry-about-college-majors/
1•jamesgill•11m ago•0 comments

"Mother of All Demos" (1968)

https://www.youtube.com/watch?v=B6rKUf9DWRI
1•nothrowaways•11m ago•0 comments

Show HN: Turn your startup logo into a holiday Google doodle

https://doodle.logic.inc/
1•sgk284•12m ago•0 comments

Yann LeCun raising €500M at €3B valuation for new AI startup

https://sifted.eu/articles/yann-lecun-ami-labs-3bn-valuation
2•harscoat•13m ago•0 comments

Sadly, Fortnite will not return to iOS in Japan in 2025 as promised

https://twitter.com/TimSweeneyEpic/status/2001494517996732598
1•ChrisArchitect•14m ago•1 comments

Ask HN: How to fight back against Lovable, Replit, etc. in enterprise products

2•bears123•14m ago•0 comments

You can now verify Google AI-generated videos in the Gemini app

https://blog.google/technology/ai/verify-google-ai-videos-gemini-app/
1•meetpateltech•16m ago•1 comments

GitHub Actions Degraded

2•1qaboutecs•16m ago•0 comments

Agent Skills is now an open standard

https://claude.com/blog/organization-skills-and-directory
2•adocomplete•19m ago•0 comments

Good if make prior after data instead of before

https://dynomight.substack.com/p/prior
1•crescit_eundo•20m ago•0 comments

The View from Inside the AI Bubble

https://www.theatlantic.com/technology/2025/12/neurips-ai-bubble-agi/685250/
1•CharlesW•20m ago•0 comments

Ruby Weekly #780: What's New in Ruby 4.0

https://rubyweekly.com/issues/780
2•brandrick•21m ago•0 comments

Show HN: A better interface for base model LLMs

https://github.com/transkatgirl/Tapestry-Loom
2•transkatgirl•23m ago•1 comments

Show HN: Peachka – Protecting Videos from Stealing

https://peachka.net/
1•superdario•24m ago•0 comments