E018 – Newsupdate 04/2026: Linux 7.0, Nix-CVE, Document Foundation, Euro-Office, Trivy-Incident
Der Linux-Kernel erscheint in Version 7.0 und mit Gaim taucht ein alter neuer Messenger auf. Im PyPi taucht Schadcode auf während ein CVE die Nix-Community auf Trab hält. Rund um die Documentation Foundation und dem neuen Euro-Office-Projekt entsteht ein Eklat. Der Trivy-Vorfall sorgt international für Aufsehen und KeePassXC wird geforkt.
Intro
- Artemis II astronaut finds two Outlook instances running on computers, calls on Houston to fix Microsoft anomaly (Tom’s Hardware): https://www.tomshardware.com/software/microsoft-office/artemis-ii-astronaut-finds-two-outlook-instances-running-on-computers-call-on-houston-to-fix-microsoft-anomaly-puzzled-caller-describes-two-outlooks-and-neither-one-of-those-are-working
- Halbleiter für Weltraum-Missionen | Bit-Rauschen 2026/6 (Bit-Rauschen: Der Prozessor-Podcast von c’t): https://bit-rauschen.podigee.io/139-halbleiter-fur-weltraum-missionen-bit-rauschen-2026-6
- WTF: Polizei rückte Samstagnacht wegen Zero-Day aus (Heise Security): https://www.heise.de/news/WTF-Polizei-rueckte-Samstagnacht-wegen-Zero-Day-aus-11221345.html
- DOS Game Club wird zu Windows Game Club: https://dosgame.club/@dosgameclub/116325526374113651
- Stellenanzeige „Senior Meme Engineer“: (LinkedIn): https://www.linkedin.com/jobs/view/4396661466
- Gentoo GNU/Hurd – Gentoo Linux (gentoo.org): https://www.gentoo.org/news/2026/04/01/gentoo-hurd.html
- Gentoo Releases Experimental Images Using GNU/Hurd (phoronix.com): https://www.phoronix.com/news/Gentoo-GNU-Hurd-Experimental
- April 1 Linux Patches: Verified Birth Date For File Creation, Block Emacs From Running (phoronix.com): https://www.phoronix.com/news/April-1-Linux-Patches-2026
- Chemnitzer Linux Tage 2006-Playlist (media.ccc.de): https://media.ccc.de/b/conferences/clt/2026
- LMP003 Chemnitzer Linux-Tage 2026 (Linux-Magazin): https://www.linux-magazin.de/podcast/lmp003/
- 15 Jahre elementaryOS: https://mastodon.social/@elementary/116325070550735763
- 15 Years of Forking – Waterfox Blog (Waterfox): https://www.waterfox.com/blog/15-years-of-forking/
Feedback und Ankündigungen
- Feedback von Clemens: https://user.space/e017-newsupdate-04-2026-linux-7-0-steam-machine-preise-ccc-benennt-sich-um-proxmox-ve-9-2-mit-kubernetes-neue-docker-pull-limits/#comment-25
- Feedback von Christoph: https://chaos.social/@inlovewithpda/116300091541891769
- Feedback von mlnf: https://mastodontech.de/@mlnf/116330487015653293
- Read the email Oracle is sending to laid-off employees (Business Insider): https://www.businessinsider.com/read-oracle-layoff-email-employees-job-cuts-2026-3
- Feedback von Mark: https://social.linux.pizza/@thesaigoneer/116385201967586516
- Commodore Software – Kipperterm 64 v1.0.30 (commodore.software): https://commodore.software/downloads/download/66-miscellaneous-terminal-programs/12867-kipperterm-64-v1-0-30
Follow-Up
- Copilot erzeugt Werbung in PRs: https://mastodon.social/@danluu/116317069604398190
- Redox OS Establishes AI Policy To Forbid Contributions Made Using LLMs (phoronix.com): https://www.phoronix.com/news/Redox-OS-March-2026
- Draft: Add parental controls to the Accounts portal by davidedmundson · Pull Request #1922 · flatpak/xdg-desktop-portal (GitHub): https://github.com/flatpak/xdg-desktop-portal/pull/1922
Linux 7.0
- Linux 7.0 erschienen – mehr als ein Nummernsprung (heise online): https://www.heise.de/news/Linux-7-0-erschienen-mehr-als-ein-Nummernsprung-11255745.html
- Linux 7.0 Features Include More Preparations For AMD Zen 6 & Intel Nova Lake Review (phoronix.com): https://www.phoronix.com/review/linux-7-features-changes
- Linux 7.0 Ready For Release With Many Exciting Changes (phoronix.com): https://www.phoronix.com/news/Linux-7.0-Changes
- Linus Torvalds Merged The Code Beginning To Remove Intel 486 CPU Support In Linux 7.1 (phoronix.com): https://www.phoronix.com/news/Linux-7.1-Begins-Removing-i486
- SHORK-486 mit Linux 7.0.0: https://toot.wales/@sharktastica/116397545264951823
- SharktasticA/SHORK-486: A Linux distribution for 486 and Pentium (P5) vintage PCs (GitHub): https://github.com/SharktasticA/SHORK-486
D-Trust zieht Zertifikate zurück
- Admins müssen D-Trust-Zertifikate tauschen – bis Ostermontag (heise online): https://www.heise.de/news/Fieses-Osterei-D-Trust-verlangt-Zertifikatstausch-bis-Ostermontag-11245930.html
- 2029013 – D-Trust: Missing Pre-Signing Linting for TLS Issuance (bugzilla.mozilla.org): https://bugzilla.mozilla.org/show_bug.cgi?id=2029013
Nix-CVE
- Nix security advisory: Privilege escalation via symlink following during FOD output registration (NixOS Discourse): https://discourse.nixos.org/t/nix-security-advisory-privilege-escalation-via-symlink-following-during-fod-output-registration/76900
- NVD – CVE-2026-39860 (nvd.nist.gov): https://nvd.nist.gov/vuln/detail/CVE-2026-39860
Frankreich macht sich für Open Source stark
- Frankreichs Plan: Weg von Windows, hin zu Linux (iX Magazin): https://www.heise.de/news/Frankreichs-Plan-Weg-von-Windows-hin-zu-Linux-11251566.html
- Europa, schau auf Frankreich! (iX Magazin): https://www.heise.de/meinung/Europa-schau-auf-Frankreich-11254323.html
Turbulenzen bei der Document Foundation
- Streit mit Collabora: LibreOffice verliert zahlreiche Hauptentwickler (Linux-Magazin): https://www.linux-magazin.de/news/streit-mit-collabora-libreoffice-verliert-zahlreiche-hauptentwickler/
- LibreOffice am Abgrund: Wie die Document Foundation ihre eigenen Gründer vor die Tür setzte – Linux Guides Community (Linux Guides Community): https://forum.linuxguides.de/core/index.php?article/54-libreoffice-am-abgrund-wie-die-document-foundation-ihre-eigenen-gr%C3%BCnder-vor-die/
- Let’s put an end to the speculation – TDF Community Blog (TDF Community Blog): https://blog.documentfoundation.org/blog/2026/04/05/lets-put-an-end-to-the-speculation/
- Setzen wir den Spekulationen ein Ende! (listarchives.libreoffice.org): https://listarchives.libreoffice.org/de/discuss/2026/msg00023.html
Flatpak-CVE
- CVE-2026-34078: Complete sandbox escape leading to host file access and code execution in the host context (GitHub): https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg
Pidgin 3.0-Alpha und Fork
- Pidgin 3.0 Alpha 1 2.95.0 has been released! (Instant Messaging Freedom’s Discourse): https://discourse.imfreedom.org/t/pidgin-3-0-alpha-1-2-95-0-has-been-released/378
- Gaim 3 Is In Development For Restoring The Original Gaim Instant Messaging App In GTK4 (phoronix.com): https://www.phoronix.com/news/Gaim-3-In-Development
- Gaim (gaim.imfreedom.org): https://gaim.imfreedom.org/
Trivy-Incident
- Update: Ongoing Investigation and Continued Remediation (AquaSec): https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
Ubuntu 26.10 soll GRUB2 verschlanken
- Canonical’s GRUB Saboteur Has a 10-Year Plan (Sam Bent): https://www.sambent.com/canonicals-grub-saboteur-has-a-10-year-plan/
- Streamlining secure boot for 26.10 (Ubuntu Community Hub): https://discourse.ubuntu.com/t/streamlining-secure-boot-for-26-10/79069/96
Kompromittierte Pakete im PyPI
- LiteLLM on PyPI is compromised (LWN.net): https://lwn.net/Articles/1064479/
- The telnyx packages on PyPI have been compromised (LWN.net): https://lwn.net/Articles/1065059/
Euro-Office Eklat
- Microsoft-Alternative: Nextcloud und Ionos entwickeln quelloffenes „Euro-Office“ (c’t Magazin): https://www.heise.de/news/Microsoft-Alternative-Nextcloud-und-Ionos-entwickeln-quelloffenes-Euro-Office-11227544.html
- Euro-Office (GitHub): https://github.com/Euro-Office
- „Euro-Office“: OnlyOffice wirft Projekt Lizenzverletzungen vor (heise online): https://www.heise.de/news/Euro-Office-OnlyOffice-wirft-Projekt-Lizenzverletzungen-vor-11241092.html
- FSF clarifies its stance on AGPLv3 additional terms (LWN.net): https://lwn.net/Articles/1067771/
KeePassXC geforkt
- KeePassChi (Codeberg.org): https://codeberg.org/keepasschi
- About KeePassXC’s Code Quality Control – KeePassXC (keepassxc.org): https://keepassxc.org/blog/2025-11-09-about-keepassxcs-code-quality-control/
Patch-Management News
- NVD – CVE-2026-1961 (nvd.nist.gov): https://nvd.nist.gov/vuln/detail/CVE-2026-1961
- Foreman 3.16.3 is now available (TheForeman): https://community.theforeman.org/t/foreman-3-16-3-is-now-available/46098
- Foreman 3.17.2 is now available (TheForeman): https://community.theforeman.org/t/foreman-3-17-2-is-now-available/46099
- Foreman 3.18.1 is now available (TheForeman): https://community.theforeman.org/t/foreman-3-18-1-is-now-available/46100
Kurznews
- Ubuntu MATE Leader Stepping Down, Seeking New Contributors (phoronix.com): https://www.phoronix.com/news/Ubuntu-MATE-Needs-Leader
- Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice (GitHub): https://github.com/Keychron/Keychron-Keyboards-Hardware-Design
- Ausgehenden Traffic unter Linux kontrollieren: Little Snitch ist da (iX Magazin): https://www.heise.de/news/Ausgehenden-Traffic-unter-Linux-kontrollieren-Little-Snitch-ist-da-11250677.html
- Update für APT: Debian-Pakete installieren, zurückspulen, weitermachen (iX Magazin): https://www.heise.de/news/Update-fuer-APT-Debian-Pakete-installieren-zurueckspulen-weitermachen-11250318.html
Veranstaltungstipps
- MRMCD 2026 (talks.mrmcd.net): https://talks.mrmcd.net/2026/cfp
- Augsburger Linux-Infotag 2026 (Augsburger Linux-Infotag 2026): https://www.luga.de/static/LIT-2026/
- Augsburger Linux-Infotag 2023 (cstan.io): https://cstan.io/post/2023/05/augsburger-linux-infotag-2023
- Linux App Summit: https://linuxappsummit.org/
- Jax 2026: https://jax.de/mainz/
- Container Days Manufacturing: https://www.containerdays.io/containerday-manufacturing-2026/
Tool- und Medientipps
- Warum MeshCore? (MeshCore Wiki DE): https://meshcore-de.fyi/warum_meshhcore
- iximiuz/cdebug: cdebug – a swiss army knife of container debugging (GitHub): https://github.com/iximiuz/cdebug