<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Fri, 29 May 2026 18:15:41 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>LINUX Unplugged - Episodes Tagged with “Nas Os”</title>
    <link>https://linuxunplugged.com/tags/nas%20os</link>
    <pubDate>Sun, 24 May 2026 19:30:00 -0700</pubDate>
    <description>An open show powered by community LINUX Unplugged takes the best attributes of open collaboration and turns it into a weekly show about Linux.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Weekly Linux talk show with no script, no limits, surprise guests and tons of opinion.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>An open show powered by community LINUX Unplugged takes the best attributes of open collaboration and turns it into a weekly show about Linux.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>668: --yolo</title>
  <link>https://linuxunplugged.com/668</link>
  <guid isPermaLink="false">7f96d0bb-26dd-4d42-bc26-d18d4334d149</guid>
  <pubDate>Sun, 24 May 2026 19:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/f31a453c-fa15-491f-8618-3f71f1d565e5/7f96d0bb-26dd-4d42-bc26-d18d4334d149.mp3" length="73424792" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Brent’s been hacking smart speakers, Wes has a surprise, and Chris gives up on OpenClaw.</itunes:subtitle>
  <itunes:duration>1:16:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
  <description>&lt;p&gt;Brent’s been hacking smart speakers, Wes has a surprise, and Chris gives up on OpenClaw. &lt;/p&gt;
</description>
  <itunes:keywords>Jupiter Broadcasting, Linux Podcast, Linux Unplugged, open source, self-hosted, AfterTouch, NASty, Hermes Agent, OpenClaw, GNOME Commander, halo, OpenCode Go, Nomad, Vaultwarden, NixOS, smart speakers, Bose hacking, NAS, bcachefs, declarative configuration, AI agents, Rust, federated architecture, source of truth, file manager, password manager, Bose, code hosting, NAS OS, embedded Linux, mesh VPN, Greg KH, Greg Kroah-Hartman, Bose SoundTouch 30, OpenClaw to Hermes migration, Rust for Linux, Hermes</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Brent’s been hacking smart speakers, Wes has a surprise, and Chris gives up on OpenClaw.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://defined.net/unplugged">Nebula</a>: <a rel="nofollow" href="https://defined.net/unplugged">Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.
</a></li><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Jupiter Signal Network Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Put your support on automatic with our annual plan, and get one month of membership for free!
</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="ConnecTen Internet" rel="nofollow" href="https://connecteninternet.com/discount/Jupiter35">ConnecTen Internet
</a> &mdash; Get $35 off your order total with Jupiter35
</li><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike
</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM
</a></li><li><a title="The Quiet Renovation at Bitwarden" rel="nofollow" href="https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden">The Quiet Renovation at Bitwarden
</a></li><li><a title="My first 100 days at Bitwarden" rel="nofollow" href="https://bitwarden.com/blog/my-first-100-days-at-bitwarden/">My first 100 days at Bitwarden
</a> &mdash; Open source is the foundation of everything Bitwarden builds. The ability to audit the code, to self-host, to verify rather than simply believe are not just nice-to-haves, they are the reason Bitwarden is different from every other option in this space, and that will not change.
</li><li><a title="AfterTouch" rel="nofollow" href="https://gesellix.github.io/Bose-SoundTouch/">AfterTouch
</a> &mdash; Bose SoundTouch Toolkit
</li><li><a title="soundcork" rel="nofollow" href="https://github.com/deborahgu/soundcork">soundcork
</a> &mdash; Intercept API for Bose SoundTouch after they turn off the servers
</li><li><a title="Bose SoundTouch EOL Announcement" rel="nofollow" href="https://www.bose.com/soundtouch-end-of-life">Bose SoundTouch EOL Announcement
</a></li><li><a title="SoundTouch 30 Wi-Fi Music System | Bose Wikia | Fandom" rel="nofollow" href="https://bose.fandom.com/wiki/SoundTouch_30_Wi-Fi_Music_System">SoundTouch 30 Wi-Fi Music System | Bose Wikia | Fandom
</a></li><li><a title="Keeping Your Speakers Alive After the Bose Cloud Shutdown – AfterTouch" rel="nofollow" href="https://gesellix.github.io/Bose-SoundTouch/docs/guides/SURVIVAL-GUIDE/">Keeping Your Speakers Alive After the Bose Cloud Shutdown – AfterTouch
</a></li><li><a title="Bose SoundTouch is officially dead, but your speakers may still survive - SoundGuys" rel="nofollow" href="https://www.soundguys.com/bose-soundtouch-support-ending-2026-146530/">Bose SoundTouch is officially dead, but your speakers may still survive - SoundGuys
</a></li><li><a title="SoundTouch 30 Wi-Fi Music System | Bose Support" rel="nofollow" href="https://support.bose.ca/s/product/soundtouch-30-wifi-music-system/01t8c00000OydOTAAZ?language=en_CA">SoundTouch 30 Wi-Fi Music System | Bose Support
</a></li><li><a title="NASty" rel="nofollow" href="https://github.com/nasty-project/nasty">NASty
</a> &mdash; NASty is a NAS operating system built on NixOS and bcachefs. It turns commodity hardware into a storage appliance serving NFS, SMB, iSCSI, and NVMe-oF. Managed from a single web UI, updated atomically, and rolled back when things go sideways.
</li><li><a title="nasty-top" rel="nofollow" href="https://github.com/nasty-project/nasty-top">nasty-top
</a> &mdash; A top-like TUI for bcachefs filesystems.
</li><li><a title="hermes-agent - GitHub" rel="nofollow" href="https://github.com/nousresearch/hermes-agent">hermes-agent - GitHub
</a></li><li><a title="Hermes Agent" rel="nofollow" href="https://hermes-agent.org/">Hermes Agent
</a> &mdash; Open-Source AI Agent with Persistent Memory
</li><li><a title="Windows-MCP" rel="nofollow" href="https://github.com/CursorTouch/Windows-MCP">Windows-MCP
</a> &mdash; MCP Server for Computer Use in Windows
</li><li><a title="Greg KH Calls For More Rust Linux Developers" rel="nofollow" href="https://www.phoronix.com/news/Greg-KH-More-Rust-Linux">Greg KH Calls For More Rust Linux Developers
</a></li><li><a title="Rust for Linux" rel="nofollow" href="https://rust-for-linux.com/">Rust for Linux
</a> &mdash; Rust for Linux is the project adding support for the Rust language to the Linux kernel.
</li><li><a title="OpenCode Go - Low cost coding models for everyone" rel="nofollow" href="https://opencode.ai/go">OpenCode Go - Low cost coding models for everyone
</a> &mdash; Go brings agentic coding to programmers around the world. Offering generous limits and reliable access to the most capable open-source models, so you can build with powerful agents without worrying about cost or availability.
</li><li><a title="Pick: Gnome Commander" rel="nofollow" href="https://gnome.pages.gitlab.gnome.org/gnome-commander/">Pick: Gnome Commander
</a> &mdash; A powerful file manager for the Linux desktop environment
</li><li><a title="Pick: halo" rel="nofollow" href="https://github.com/programmersd21/halo">Pick: halo
</a> &mdash; Terminal flow field screensaver with Perlin noise, Braille rendering, particles, and 24-bit ANSI color
</li><li><a title="Airwolf Theme 80s Retrowave Bass Remix | Retro Visualizer | DMCA Safe - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=WLRgUCX3qws">Airwolf Theme 80s Retrowave Bass Remix | Retro Visualizer | DMCA Safe - YouTube
</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Brent’s been hacking smart speakers, Wes has a surprise, and Chris gives up on OpenClaw.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://defined.net/unplugged">Nebula</a>: <a rel="nofollow" href="https://defined.net/unplugged">Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.
</a></li><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Jupiter Signal Network Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Put your support on automatic with our annual plan, and get one month of membership for free!
</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="ConnecTen Internet" rel="nofollow" href="https://connecteninternet.com/discount/Jupiter35">ConnecTen Internet
</a> &mdash; Get $35 off your order total with Jupiter35
</li><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike
</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM
</a></li><li><a title="The Quiet Renovation at Bitwarden" rel="nofollow" href="https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden">The Quiet Renovation at Bitwarden
</a></li><li><a title="My first 100 days at Bitwarden" rel="nofollow" href="https://bitwarden.com/blog/my-first-100-days-at-bitwarden/">My first 100 days at Bitwarden
</a> &mdash; Open source is the foundation of everything Bitwarden builds. The ability to audit the code, to self-host, to verify rather than simply believe are not just nice-to-haves, they are the reason Bitwarden is different from every other option in this space, and that will not change.
</li><li><a title="AfterTouch" rel="nofollow" href="https://gesellix.github.io/Bose-SoundTouch/">AfterTouch
</a> &mdash; Bose SoundTouch Toolkit
</li><li><a title="soundcork" rel="nofollow" href="https://github.com/deborahgu/soundcork">soundcork
</a> &mdash; Intercept API for Bose SoundTouch after they turn off the servers
</li><li><a title="Bose SoundTouch EOL Announcement" rel="nofollow" href="https://www.bose.com/soundtouch-end-of-life">Bose SoundTouch EOL Announcement
</a></li><li><a title="SoundTouch 30 Wi-Fi Music System | Bose Wikia | Fandom" rel="nofollow" href="https://bose.fandom.com/wiki/SoundTouch_30_Wi-Fi_Music_System">SoundTouch 30 Wi-Fi Music System | Bose Wikia | Fandom
</a></li><li><a title="Keeping Your Speakers Alive After the Bose Cloud Shutdown – AfterTouch" rel="nofollow" href="https://gesellix.github.io/Bose-SoundTouch/docs/guides/SURVIVAL-GUIDE/">Keeping Your Speakers Alive After the Bose Cloud Shutdown – AfterTouch
</a></li><li><a title="Bose SoundTouch is officially dead, but your speakers may still survive - SoundGuys" rel="nofollow" href="https://www.soundguys.com/bose-soundtouch-support-ending-2026-146530/">Bose SoundTouch is officially dead, but your speakers may still survive - SoundGuys
</a></li><li><a title="SoundTouch 30 Wi-Fi Music System | Bose Support" rel="nofollow" href="https://support.bose.ca/s/product/soundtouch-30-wifi-music-system/01t8c00000OydOTAAZ?language=en_CA">SoundTouch 30 Wi-Fi Music System | Bose Support
</a></li><li><a title="NASty" rel="nofollow" href="https://github.com/nasty-project/nasty">NASty
</a> &mdash; NASty is a NAS operating system built on NixOS and bcachefs. It turns commodity hardware into a storage appliance serving NFS, SMB, iSCSI, and NVMe-oF. Managed from a single web UI, updated atomically, and rolled back when things go sideways.
</li><li><a title="nasty-top" rel="nofollow" href="https://github.com/nasty-project/nasty-top">nasty-top
</a> &mdash; A top-like TUI for bcachefs filesystems.
</li><li><a title="hermes-agent - GitHub" rel="nofollow" href="https://github.com/nousresearch/hermes-agent">hermes-agent - GitHub
</a></li><li><a title="Hermes Agent" rel="nofollow" href="https://hermes-agent.org/">Hermes Agent
</a> &mdash; Open-Source AI Agent with Persistent Memory
</li><li><a title="Windows-MCP" rel="nofollow" href="https://github.com/CursorTouch/Windows-MCP">Windows-MCP
</a> &mdash; MCP Server for Computer Use in Windows
</li><li><a title="Greg KH Calls For More Rust Linux Developers" rel="nofollow" href="https://www.phoronix.com/news/Greg-KH-More-Rust-Linux">Greg KH Calls For More Rust Linux Developers
</a></li><li><a title="Rust for Linux" rel="nofollow" href="https://rust-for-linux.com/">Rust for Linux
</a> &mdash; Rust for Linux is the project adding support for the Rust language to the Linux kernel.
</li><li><a title="OpenCode Go - Low cost coding models for everyone" rel="nofollow" href="https://opencode.ai/go">OpenCode Go - Low cost coding models for everyone
</a> &mdash; Go brings agentic coding to programmers around the world. Offering generous limits and reliable access to the most capable open-source models, so you can build with powerful agents without worrying about cost or availability.
</li><li><a title="Pick: Gnome Commander" rel="nofollow" href="https://gnome.pages.gitlab.gnome.org/gnome-commander/">Pick: Gnome Commander
</a> &mdash; A powerful file manager for the Linux desktop environment
</li><li><a title="Pick: halo" rel="nofollow" href="https://github.com/programmersd21/halo">Pick: halo
</a> &mdash; Terminal flow field screensaver with Perlin noise, Braille rendering, particles, and 24-bit ANSI color
</li><li><a title="Airwolf Theme 80s Retrowave Bass Remix | Retro Visualizer | DMCA Safe - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=WLRgUCX3qws">Airwolf Theme 80s Retrowave Bass Remix | Retro Visualizer | DMCA Safe - YouTube
</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>665: Patch Me If You Can</title>
  <link>https://linuxunplugged.com/665</link>
  <guid isPermaLink="false">b737a45c-c67b-4f40-94b9-999592e4f5d9</guid>
  <pubDate>Sun, 03 May 2026 18:30:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/f31a453c-fa15-491f-8618-3f71f1d565e5/b737a45c-c67b-4f40-94b9-999592e4f5d9.mp3" length="77463114" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We dig into the Copy Fail vulnerability and test a proof-of-concept against our own box. Plus, Jon Seager, VP of Engineering at Canonical joins us, and we kick off the BSD Challenge!</itunes:subtitle>
  <itunes:duration>1:20:41</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
  <description>&lt;p&gt;We dig into the Copy Fail vulnerability and test a proof-of-concept against our own box. Plus, Jon Seager, VP of Engineering at Canonical joins us, and we kick off the BSD Challenge! Special Guest: Jon Seager.&lt;/p&gt;
</description>
  <itunes:keywords>Jupiter Broadcasting, Linux Podcast, Linux Unplugged, open source, NASty, NixOS, bcachefs, FreeBSD, GhostBSD, Defuse, background removal, ODROID, Copy Fail, CVE-2026-31431, Linux kernel vulnerability, local LLM, Ubuntu 26.04 LTS, Resolute Raccoon, 🦝, Ubuntu, Snaps, Rust, GNU coreutils, Rust coreutils, uutils coreutils, Ubuntu engineering, AI developer, Ubuntu LTS, Wayland, TPM-backed Full Disk Encryption, AI in Ubuntu, ZFS, BSD jails, declarative configuration, container escape, page cache attack, kernel security, Canonical, security, Jon Seager, Canonical VP Engineering, Patch Sunday, BSD Challenge, FreeBSD setup, Python, Linux exploit, frontier AI for Ubuntu, CUDA, AMD ROCm, Ventoy, rescue nix config, bcachefs NAS, NixOS NAS, backup system, NAS OS</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We dig into the Copy Fail vulnerability and test a proof-of-concept against our own box. Plus, Jon Seager, VP of Engineering at Canonical joins us, and we kick off the BSD Challenge!</p><p>Special Guest: Jon Seager.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://defined.net/unplugged">Nebula</a>: <a rel="nofollow" href="https://defined.net/unplugged">Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.
</a></li><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Jupiter Signal Network Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Put your support on automatic with our annual plan, and get one month of membership for free!
</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike
</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM
</a></li><li><a title="Copy Fail — CVE-2026-31431" rel="nofollow" href="https://copy.fail/#exploit">Copy Fail — CVE-2026-31431
</a> &mdash; "An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root." — Theori
</li><li><a title="Copy Fail: 732 Bytes to Root - Xint" rel="nofollow" href="https://xint.io/blog/copy-fail-linux-distributions">Copy Fail: 732 Bytes to Root - Xint
</a> &mdash; "A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017." — Xint
</li><li><a title="Linux Kernel Bug Explained - Jorijn" rel="nofollow" href="https://jorijn.com/en/blog/copy-fail-cve-2026-31431-linux-kernel-bug-explained/">Linux Kernel Bug Explained - Jorijn
</a> &mdash; "CopyFail is more portable. One script, every distro, no offsets. Dirty Pipe needed kernel ≥ 5.8; Copy Fail covers 2017–2026." — Jorijn"Kubernetes Pod Security Standards (Restricted) and default seccomp do NOT block the syscall used." — Jorijn
</li><li><a title="Ars: Most Severe Linux Threat in Years" rel="nofollow" href="https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/">Ars: Most Severe Linux Threat in Years
</a> &mdash; "The most severe Linux threat to surface in years catches the world flat-footed." — Ars Technica
</li><li><a title="Sysdig: CVE-2026-31431 Analysis" rel="nofollow" href="https://www.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds/">Sysdig: CVE-2026-31431 Analysis
</a> &mdash; "The flaw was introduced in 2017 via commit 72548b093ee3, which switched AEAD operations to in-place processing." — Sysdig
</li><li><a title="CERT-EU Advisory" rel="nofollow" href="https://cert.europa.eu/publications/security-advisories/2026-005/">CERT-EU Advisory
</a></li><li><a title="Ubuntu Security Tracker" rel="nofollow" href="https://ubuntu.com/security/CVE-2026-31431">Ubuntu Security Tracker
</a></li><li><a title="The Register: Crypto Flaw" rel="nofollow" href="https://www.theregister.com/2026/04/30/linux_cryptographic_code_flaw/">The Register: Crypto Flaw
</a></li><li><a title="Kernel Patch (reverts 2017 optimization)" rel="nofollow" href="https://github.com/torvalds/linux/commit/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5.diff">Kernel Patch (reverts 2017 optimization)
</a> &mdash; "This mostly reverts commit 72548b093ee3 except for the copying of the associated data." — Kernel Commit
</li><li><a title="Buggy Commit: 72548b093ee3 (2017)" rel="nofollow" href="https://github.com/torvalds/linux/commit/72548b093ee3">Buggy Commit: 72548b093ee3 (2017)
</a></li><li><a title="DeepWiki: AF_ALG Internals" rel="nofollow" href="https://deepwiki.com/theori-io/copy-fail-CVE-2026-31431/3.1-linux-crypto-api-(af_alg)-internals">DeepWiki: AF_ALG Internals
</a></li><li><a title="oss-security Disclosure" rel="nofollow" href="https://www.openwall.com/lists/oss-security/2026/04/29/23">oss-security Disclosure
</a></li><li><a title="PSA + GRUB Mitigation - Jan Wildeboer" rel="nofollow" href="https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/">PSA + GRUB Mitigation - Jan Wildeboer
</a></li><li><a title="Ubuntu 26.04 LTS (Resolute Raccoon) Released" rel="nofollow" href="https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon">Ubuntu 26.04 LTS (Resolute Raccoon) Released
</a> &mdash; "Ubuntu 26.04 LTS sets the example for providing best-in-class resilience while simultaneously embracing innovation and the advancement of open source." — Jon Seager, VP Ubuntu Engineering
</li><li><a title="The Future of AI in Ubuntu - Jon Seager" rel="nofollow" href="https://discourse.ubuntu.com/t/the-future-of-ai-in-ubuntu/81130">The Future of AI in Ubuntu - Jon Seager
</a> &mdash; "Throughout 2026 we'll be working on enabling access to frontier AI for Ubuntu users in a way that is deliberate, secure, and aligned with our open source values." — Jon Seager
</li><li><a title="Ubuntu 26.04 Release Notes" rel="nofollow" href="https://documentation.ubuntu.com/release-notes/26.04/">Ubuntu 26.04 Release Notes
</a></li><li><a title="Ubuntu AI Features Throughout 2026 - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-AI-Features-2026">Ubuntu AI Features Throughout 2026 - Phoronix
</a> &mdash; "Canonical's approach to AI is refreshingly thoughtful — Microsoft should take note." — ZDNet
</li><li><a title="Canonical DDoS Attack Update" rel="nofollow" href="https://discourse.ubuntu.com/t/update-concerning-ddos-attack-on-canonical-and-ubuntu/81482">Canonical DDoS Attack Update
</a> &mdash; "Canonical's web infrastructure is under a sustained, cross-border attack and we are working to address it." — arcticp, Canonical
</li><li><a title="Ubuntu Weekly Newsletter #942" rel="nofollow" href="https://discourse.ubuntu.com/t/ubuntu-weekly-newsletter-issue-942/81204">Ubuntu Weekly Newsletter #942
</a></li><li><a title="Canonical AI Approach - ZDNet" rel="nofollow" href="https://www.zdnet.com/article/canonical-ai-approach-thoughtful-microsoft-should-take-note/">Canonical AI Approach - ZDNet
</a></li><li><a title="9to5Linux: Opt-In LLM Tools" rel="nofollow" href="https://9to5linux.com/canonical-plans-to-integrate-opt-in-llm-based-tools-in-future-ubuntu-releases/">9to5Linux: Opt-In LLM Tools
</a></li><li><a title="uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils" rel="nofollow" href="https://github.com/uutils/coreutils">uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils
</a></li><li><a title="LINUX Unplugged 636: Engineering the Future" rel="nofollow" href="https://linuxunplugged.com/636">LINUX Unplugged 636: Engineering the Future
</a></li><li><a title="LiveCD fails to start X session on QEMU · Issue #354 · ghostbsd/issues" rel="nofollow" href="https://github.com/ghostbsd/issues/issues/354">LiveCD fails to start X session on QEMU · Issue #354 · ghostbsd/issues
</a></li><li><a title="Monty&#39;s “rescue” drive NixOS config" rel="nofollow" href="https://github.com/pmontgo33/nix-config">Monty's “rescue” drive NixOS config
</a></li><li><a title="Magnolia Mayhem&#39;s BSD Challenge Report" rel="nofollow" href="https://www.ministryofmayhem.space/posts/bsdptdeux/">Magnolia Mayhem's BSD Challenge Report
</a></li><li><a title="Pick: NASty" rel="nofollow" href="https://github.com/nasty-project/nasty">Pick: NASty
</a> &mdash; NASty is a NAS operating system built on NixOS and bcachefs. It turns commodity hardware into a storage appliance serving NFS, SMB, iSCSI, and NVMe-oF — managed from a single web UI, updated atomically, and rolled back when things go sideways.
</li><li><a title="Pick: Defuse" rel="nofollow" href="https://github.com/shonebinu/Defuse">Pick: Defuse
</a> &mdash; Defuse is a GTK4 application for removing image backgrounds locally.
</li><li><a title="Defuse on Flathub" rel="nofollow" href="https://flathub.org/en/apps/io.github.shonebinu.Defuse">Defuse on Flathub
</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We dig into the Copy Fail vulnerability and test a proof-of-concept against our own box. Plus, Jon Seager, VP of Engineering at Canonical joins us, and we kick off the BSD Challenge!</p><p>Special Guest: Jon Seager.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://defined.net/unplugged">Nebula</a>: <a rel="nofollow" href="https://defined.net/unplugged">Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.
</a></li><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Jupiter Signal Network Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=117630r">Put your support on automatic with our annual plan, and get one month of membership for free!
</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike
</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM
</a></li><li><a title="Copy Fail — CVE-2026-31431" rel="nofollow" href="https://copy.fail/#exploit">Copy Fail — CVE-2026-31431
</a> &mdash; "An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root." — Theori
</li><li><a title="Copy Fail: 732 Bytes to Root - Xint" rel="nofollow" href="https://xint.io/blog/copy-fail-linux-distributions">Copy Fail: 732 Bytes to Root - Xint
</a> &mdash; "A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017." — Xint
</li><li><a title="Linux Kernel Bug Explained - Jorijn" rel="nofollow" href="https://jorijn.com/en/blog/copy-fail-cve-2026-31431-linux-kernel-bug-explained/">Linux Kernel Bug Explained - Jorijn
</a> &mdash; "CopyFail is more portable. One script, every distro, no offsets. Dirty Pipe needed kernel ≥ 5.8; Copy Fail covers 2017–2026." — Jorijn"Kubernetes Pod Security Standards (Restricted) and default seccomp do NOT block the syscall used." — Jorijn
</li><li><a title="Ars: Most Severe Linux Threat in Years" rel="nofollow" href="https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/">Ars: Most Severe Linux Threat in Years
</a> &mdash; "The most severe Linux threat to surface in years catches the world flat-footed." — Ars Technica
</li><li><a title="Sysdig: CVE-2026-31431 Analysis" rel="nofollow" href="https://www.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds/">Sysdig: CVE-2026-31431 Analysis
</a> &mdash; "The flaw was introduced in 2017 via commit 72548b093ee3, which switched AEAD operations to in-place processing." — Sysdig
</li><li><a title="CERT-EU Advisory" rel="nofollow" href="https://cert.europa.eu/publications/security-advisories/2026-005/">CERT-EU Advisory
</a></li><li><a title="Ubuntu Security Tracker" rel="nofollow" href="https://ubuntu.com/security/CVE-2026-31431">Ubuntu Security Tracker
</a></li><li><a title="The Register: Crypto Flaw" rel="nofollow" href="https://www.theregister.com/2026/04/30/linux_cryptographic_code_flaw/">The Register: Crypto Flaw
</a></li><li><a title="Kernel Patch (reverts 2017 optimization)" rel="nofollow" href="https://github.com/torvalds/linux/commit/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5.diff">Kernel Patch (reverts 2017 optimization)
</a> &mdash; "This mostly reverts commit 72548b093ee3 except for the copying of the associated data." — Kernel Commit
</li><li><a title="Buggy Commit: 72548b093ee3 (2017)" rel="nofollow" href="https://github.com/torvalds/linux/commit/72548b093ee3">Buggy Commit: 72548b093ee3 (2017)
</a></li><li><a title="DeepWiki: AF_ALG Internals" rel="nofollow" href="https://deepwiki.com/theori-io/copy-fail-CVE-2026-31431/3.1-linux-crypto-api-(af_alg)-internals">DeepWiki: AF_ALG Internals
</a></li><li><a title="oss-security Disclosure" rel="nofollow" href="https://www.openwall.com/lists/oss-security/2026/04/29/23">oss-security Disclosure
</a></li><li><a title="PSA + GRUB Mitigation - Jan Wildeboer" rel="nofollow" href="https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/">PSA + GRUB Mitigation - Jan Wildeboer
</a></li><li><a title="Ubuntu 26.04 LTS (Resolute Raccoon) Released" rel="nofollow" href="https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon">Ubuntu 26.04 LTS (Resolute Raccoon) Released
</a> &mdash; "Ubuntu 26.04 LTS sets the example for providing best-in-class resilience while simultaneously embracing innovation and the advancement of open source." — Jon Seager, VP Ubuntu Engineering
</li><li><a title="The Future of AI in Ubuntu - Jon Seager" rel="nofollow" href="https://discourse.ubuntu.com/t/the-future-of-ai-in-ubuntu/81130">The Future of AI in Ubuntu - Jon Seager
</a> &mdash; "Throughout 2026 we'll be working on enabling access to frontier AI for Ubuntu users in a way that is deliberate, secure, and aligned with our open source values." — Jon Seager
</li><li><a title="Ubuntu 26.04 Release Notes" rel="nofollow" href="https://documentation.ubuntu.com/release-notes/26.04/">Ubuntu 26.04 Release Notes
</a></li><li><a title="Ubuntu AI Features Throughout 2026 - Phoronix" rel="nofollow" href="https://www.phoronix.com/news/Ubuntu-AI-Features-2026">Ubuntu AI Features Throughout 2026 - Phoronix
</a> &mdash; "Canonical's approach to AI is refreshingly thoughtful — Microsoft should take note." — ZDNet
</li><li><a title="Canonical DDoS Attack Update" rel="nofollow" href="https://discourse.ubuntu.com/t/update-concerning-ddos-attack-on-canonical-and-ubuntu/81482">Canonical DDoS Attack Update
</a> &mdash; "Canonical's web infrastructure is under a sustained, cross-border attack and we are working to address it." — arcticp, Canonical
</li><li><a title="Ubuntu Weekly Newsletter #942" rel="nofollow" href="https://discourse.ubuntu.com/t/ubuntu-weekly-newsletter-issue-942/81204">Ubuntu Weekly Newsletter #942
</a></li><li><a title="Canonical AI Approach - ZDNet" rel="nofollow" href="https://www.zdnet.com/article/canonical-ai-approach-thoughtful-microsoft-should-take-note/">Canonical AI Approach - ZDNet
</a></li><li><a title="9to5Linux: Opt-In LLM Tools" rel="nofollow" href="https://9to5linux.com/canonical-plans-to-integrate-opt-in-llm-based-tools-in-future-ubuntu-releases/">9to5Linux: Opt-In LLM Tools
</a></li><li><a title="uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils" rel="nofollow" href="https://github.com/uutils/coreutils">uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils
</a></li><li><a title="LINUX Unplugged 636: Engineering the Future" rel="nofollow" href="https://linuxunplugged.com/636">LINUX Unplugged 636: Engineering the Future
</a></li><li><a title="LiveCD fails to start X session on QEMU · Issue #354 · ghostbsd/issues" rel="nofollow" href="https://github.com/ghostbsd/issues/issues/354">LiveCD fails to start X session on QEMU · Issue #354 · ghostbsd/issues
</a></li><li><a title="Monty&#39;s “rescue” drive NixOS config" rel="nofollow" href="https://github.com/pmontgo33/nix-config">Monty's “rescue” drive NixOS config
</a></li><li><a title="Magnolia Mayhem&#39;s BSD Challenge Report" rel="nofollow" href="https://www.ministryofmayhem.space/posts/bsdptdeux/">Magnolia Mayhem's BSD Challenge Report
</a></li><li><a title="Pick: NASty" rel="nofollow" href="https://github.com/nasty-project/nasty">Pick: NASty
</a> &mdash; NASty is a NAS operating system built on NixOS and bcachefs. It turns commodity hardware into a storage appliance serving NFS, SMB, iSCSI, and NVMe-oF — managed from a single web UI, updated atomically, and rolled back when things go sideways.
</li><li><a title="Pick: Defuse" rel="nofollow" href="https://github.com/shonebinu/Defuse">Pick: Defuse
</a> &mdash; Defuse is a GTK4 application for removing image backgrounds locally.
</li><li><a title="Defuse on Flathub" rel="nofollow" href="https://flathub.org/en/apps/io.github.shonebinu.Defuse">Defuse on Flathub
</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
