Benvenuti su Slacky.eu - Italian Slackware Community

Community dedicata alla distribuzione Slackware Linux.

Slacky.eu è un progetto che offre un Forum in italiano per Slackware Linux, leggi la nostra storia.

Aggiornamenti dal mondo Slackware

News

3 Febbraio 2022 - Slackware 15.0

Oggi (2 febbraio alle 22:22 orario UTC) è stata finalmente rilasciata la Slackware 15.0. Vi aspettiamo nel forum per commentare. Happy fun :)

13 Gennaio 2022 - Slackware 15 RC3

Siamo arrivati alla terza, e a meno di sorprese, l'ultima Release Candidate di Slackware 15. Da ora in poi ci saranno modifiche solo in caso di problemi seri, ma tutto lascia supporre che il 17 gennaio, come anticipato da Pat su LinuxQuestions, esca la tanto sospirata versione 15. Ti aspettiamo nel forum per parlarne.

16 Agosto 2021 - Slackware 15 RC1

È uscita stanotte la prima Release Candidate di Slackware 15. Come ha scritto Pat si tratta di un "congelamento", a meno di bugfix. Questo significa che la 15.0 sarà rilasciata con i software nella versione presente in questa RC1, a meno appunto di bug trovati, o aggiornamenti di sicurezza.

15 Aprile 2021 - Slackware 15 beta

Qualche giorno fa Pat ha rilasciato un corposo aggiornamento definendolo beta. La data dell'uscita di Slackware 15 si fa sempre più vicina.


ChangeLog

Slackware Current

			
  • Mon, 28 Sep 2026 22:17:10 +0000
    Mon Sep 28 22:17:10 UTC 2026
    a/elogind-257.16-x86_64-5.txz: Rebuilt.
    Remove orphaned session cgroups.
    Thanks to gcosbug.
    a/eudev-3.2.15-x86_64-1.txz: Upgraded.
    a/mkinitrd-1.4.11-x86_64-81.txz: Rebuilt.
    /etc/default/geninitrd: make the initrd.gz symlink to prevent problems with
    LILO when upgrading from an earlier version of Slackware while retaining
    the existing lilo.conf.
    ap/groff-1.24.2-x86_64-1.txz: Upgraded.
    This release corrects command injection security vulnerabilities
    (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
    these is a preprocessor that is run when groff or troff is run with the
    `-T html` or `-T xhtml` options. The vulnerabilities are variously
    14-26 years old. Malicious input can escape groff's default "safer"
    mode, running commands embedded in that input at the user's privilege
    level. The groff development team recommends this release to any users
    who employ the named tools or GNU troff output formats with untrusted
    inputs.
    (* Security fix *)
    ap/lxc-7.0.0-x86_64-4.txz: Rebuilt.
    Use cgroup v2 (the host must be running this).
    Drop obsolete package aaa_elflibs.
    Update version in the generated slackpkg.conf.
    Thanks to roberto967.
    d/google-go-lang-1.27.1-x86_64-1.txz: Upgraded.
    kde/wcslib-8.10-x86_64-2.txz: Rebuilt.
    Fix some bogus directory permissions.
    Thanks to josiah.
    l/at-spi2-core-2.62.0.1-x86_64-2.txz: Rebuilt.
    [PATCH] at-spi-bus-launcher: Clean up dbus-daemon when terminating from
    signals other than SIGTERM.
    Thanks to gcosbug.
    l/dbus-python-1.5.0-x86_64-1.txz: Upgraded.
    l/hunspell-1.7.4-x86_64-1.txz: Upgraded.
    l/pcre2-10.49-x86_64-1.txz: Upgraded.
    This update fixes a security issue.
    An attacker-controlled regex pattern could lead to an out-of-bounds write
    with arbitrary data.
    For more information, see:
    https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m
    (* Security fix *)
    l/python-lxml-6.1.2-x86_64-2.txz: Rebuilt.
    Reverted. 6.1.3 breaks the elogind build.
    n/network-scripts-16.0-noarch-1.txz: Upgraded.
    rc.inet2: add comments about how to inhibit rc.rpc from starting.
    Thanks to guanx.
    n/rpcbind-1.3.1-x86_64-2.txz: Rebuilt.
    rc.rpc: if DISABLE_RPC_SERVICES=true in /etc/default/rpc, then don't start
    the RPC services.
    Thanks to guanx.
    x/egl-wayland-1.1.23-x86_64-1.txz: Upgraded.
    xap/freerdp-3.32.1-x86_64-1.txz: Upgraded.
  • Sun, 27 Sep 2026 21:16:56 +0000
    Sun Sep 27 21:16:56 UTC 2026
    a/lilo-24.2-x86_64-17.txz: Rebuilt.
    lilo-reinstall: also reinstall if image=/boot/vmlinuz.
    Thanks to Bravo_97.
    ap/qpdf-12.4.2-x86_64-1.txz: Upgraded.
    d/ccache-4.14.1-x86_64-1.txz: Upgraded.
    kde/ktextaddons-2.2.0-x86_64-1.txz: Upgraded.
    kde/wcslib-8.10-x86_64-1.txz: Upgraded.
    l/dbus-glib-0.116-x86_64-1.txz: Upgraded.
    l/frei0r-plugins-3.6.0-x86_64-1.txz: Upgraded.
    l/imagemagick-7.1.2_32-x86_64-1.txz: Upgraded.
    Added configure option --enable-year2038.
    Thanks to bigbadaboum.
    n/tftp-hpa-7.2-x86_64-1.txz: Upgraded.
  • Sat, 26 Sep 2026 22:13:00 +0000
    Sat Sep 26 22:13:00 UTC 2026
    a/libcgroup-3.2.0-x86_64-4.txz: Rebuilt.
    Fixed the BUILD number.

Slackware 15.0 (Stable)

			
  • Mon, 28 Sep 2026 22:17:10 +0000
    Mon Sep 28 22:17:10 UTC 2026
    patches/packages/groff-1.24.2-x86_64-1_slack15.0.txz: Upgraded.
    This release corrects command injection security vulnerabilities
    (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
    these is a preprocessor that is run when groff or troff is run with the
    `-T html` or `-T xhtml` options. The vulnerabilities are variously
    14-26 years old. Malicious input can escape groff's default "safer"
    mode, running commands embedded in that input at the user's privilege
    level. The groff development team recommends this release to any users
    who employ the named tools or GNU troff output formats with untrusted
    inputs.
    (* Security fix *)
    patches/packages/pcre2-10.49-x86_64-1.txz: Upgraded.
    This update fixes a security issue.
    An attacker-controlled regex pattern could lead to an out-of-bounds write
    with arbitrary data.
    For more information, see:
    https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m
    (* Security fix *)
  • Thu, 24 Sep 2026 23:11:03 +0000
    Thu Sep 24 23:11:03 UTC 2026
    extra/php82/php82-8.2.34-x86_64-1_slack15.0.txz: Upgraded.
    This update fixes security issues:
    FPM: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
    comparison.
    OpenSSL: TLS hostname verification falls back to CN after SAN mismatch.
    OpenSSL: Heap buffer overflow in php_openssl_matches_wildcard_name() on
    crafted server certificate wildcard CN.
    Phar: Integer overflow in phar_tar_number() allowing TAR archive entry
    injection.
    SOAP: Unbounded recursion in server-side cleanup_xml_node().
    SOAP: Integer overflow to buffer overflow in SOAP HTTP parsing.
    Standard: Out-of-bounds read in convert.* stream filters when
    line-break-chars contains NUL.
    Standard: Cross-origin credential leak in HTTP stream wrapper redirects.
    Standard: Out-of-bounds read in the HTTP stream wrapper when following a
    redirect with an empty Location header.
    For more information, see:
    https://www.php.net/ChangeLog-8.php#8.2.34
    https://www.cve.org/CVERecord?id=CVE-2026-91768
    https://www.cve.org/CVERecord?id=CVE-2025-1218
    https://www.cve.org/CVERecord?id=CVE-2026-91769
    https://www.cve.org/CVERecord?id=CVE-2026-91767
    https://www.cve.org/CVERecord?id=CVE-2026-6103
    https://www.cve.org/CVERecord?id=CVE-2026-91765
    https://www.cve.org/CVERecord?id=CVE-2025-14181
    https://www.cve.org/CVERecord?id=CVE-2026-92842
    https://www.cve.org/CVERecord?id=CVE-2026-91766
    https://www.cve.org/CVERecord?id=CVE-2026-93682
    https://www.cve.org/CVERecord?id=CVE-2026-17545
    (* Security fix *)
  • Mon, 21 Sep 2026 21:52:23 +0000
    Mon Sep 21 21:52:23 UTC 2026
    patches/packages/rsync-3.5.1-x86_64-1_slack15.0.txz: Upgraded.
    This is a bugfix release.
    For more information, see /usr/doc/rsync-3.5.1/NEWS.md.
    patches/packages/util-linux-2.42.4-x86_64-1_slack15.0.txz: Upgraded.
    This update fixes bugs and a security issue:
    nsenter: close cgroup.procs fd after join to prevent authority leak.
    For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2026-78408
    (* Security fix *)