(more Linux and FOSS news in previous posts of thread)

ACP Registry debuts in Zed Editor with built-in IDE support:
https://alternativeto.net/news/2026/1/acp-registry-debuts-in-zed-editor-with-built-in-ide-support/

GNU C Library Moving From Sourceware To Linux Foundation Hosted CTI:
https://www.phoronix.com/news/GNU-C-Library-To-CTI-LF

Ollama debuts 'ollama launch' to run coding tools with local or cloud models:
https://alternativeto.net/news/2026/1/ollama-debuts-ollama-launch-to-run-coding-tools-with-local-or-cloud-models/

Immich 2.5 adds space-saving option, non-destructive image editing, UI upgrades, and more:
https://alternativeto.net/news/2026/1/immich-2-5-adds-space-saving-option-non-destructive-image-editing-ui-upgrades-and-more/

GNU gettext Reaches Version 1.0 After 30+ Years In Development - Adds LLM Features:
https://www.phoronix.com/news/GNU-gettext-1.0

Electronic Frontier Foundation calls for stronger privacy with Encrypt It Already campaign:
https://betanews.com/article/electronic-frontier-foundation-calls-for-stronger-privacy-with-encrypt-it-already-campaign/

The free and open source Godot Engine 4.6 is out now with major upgrades:
https://www.gamingonlinux.com/2026/01/the-free-and-open-source-godot-engine-4-6-is-out-now-with-major-upgrades/

Netflix Animation Studios are now funding Blender development:
https://www.gamingonlinux.com/2026/01/netflix-animation-studios-are-now-funding-blender-development/

Vulkan 1.4.342 Published With Cooperative Matrix Conversion Extension:
https://www.phoronix.com/news/Vulkan-1.4.342-Released

Pandas 3.0 debuts str dtype and Copy-on-Write for dataframes:
https://alternativeto.net/news/2026/1/pandas-3-0-debuts-str-dtype-and-copy-on-write-for-dataframes/

Jan v3 model debuts, with updates to Jan Desktop v0.7.6:
https://alternativeto.net/news/2026/1/jan-v3-model-debuts-with-updates-to-jan-desktop-v0-7-6/

The viral AI agent Clawdbot rebrands a third time, and now has a social network for bots:
https://alternativeto.net/news/2026/1/the-viral-ai-agent-clawdbot-rebrands-a-third-time-and-now-has-a-social-network-for-bots/

OPNsense 26.1 enhances security, network visibility, automation, and threat intelligence:
https://alternativeto.net/news/2026/1/opnsense-26-1-enhances-security-network-visibility-automation-and-threat-intelligence/

#WeeklyNews #OpenSource #FOSSNews #FOSS #Zed #ZedEditor #ACP #GNUCLibrary #Ollama #Immich #GNUgettext #GodotEngine #Godot #Vulkan #Pandas #Jan #Clawdbot #Moltbot #OpenClaw #OPNsense #AI #ArtificialIntelligence #Programming #Python #Coding #Development #Dev #GameDev #GameDevelopment #IDE #FosseryTech

ACP Registry debuts in Zed Editor with built-in IDE support

Zed Editor introduces the ACP Registry, providing instant agent registration and updates across ACP-compatible clients. Built-in support extends to JetBrains IDEs.

AlternativeTo

(more Linux and FOSS news in previous posts of thread)

Ollama launches experimental local image generation on macOS with Z-Image Turbo and FLUX.2:
https://alternativeto.net/news/2026/1/ollama-launches-experimental-local-image-generation-on-macos-with-z-image-turbo-and-flux-2/

Penpot 2.13 update: box shadow tokens, improved i18n, and enhanced file management:
https://alternativeto.net/news/2026/1/penpot-2-13-update-box-shadow-tokens-improved-i18n-and-enhanced-file-management/

Radicle 1.6.0 Amaryllis released: major updates and Windows build support:
https://alternativeto.net/news/2026/1/radicle-1-6-0-amaryllis-released-major-updates-and-windows-build-support/
(Never heard of this Git platform before, but I find the concept of peer-to-peer based code sharing platform pretty interesting, never seen such thing before, so I thought I include it here.)

Rust 1.93 brings musl 1.2.5, allocator improvements, and cfg attributes on asm! lines:
https://alternativeto.net/news/2026/1/rust-1-93-brings-musl-1-2-5-allocator-improvements-and-cfg-attributes-on-asm-lines/

jQuery 4.0 trims legacy code, drops deprecated APIs, migrates to ES modules, and more:
https://alternativeto.net/news/2026/1/jquery-4-0-trims-legacy-code-drops-deprecated-apis-migrates-to-es-modules-and-more/

Scala 3.8 requires JDK 17, standard library now built with Scala 3:
https://alternativeto.net/news/2026/1/scala-3-8-requires-jdk-17-standard-library-now-built-with-scala-3/

Swift cross platform framework, Skip, is now free and open source with licensing removed:
https://alternativeto.net/news/2026/1/swift-cross-platform-framework-skip-is-now-free-and-open-source-with-licensing-removed/

PyTorch 2.10 Released With More Improvements For AMD ROCm & Intel GPUs:
https://www.phoronix.com/news/PyTorch-2.10-Released

GNU C Library 2.43 Released With More C23 Features, mseal & openat2 Functions:
https://www.phoronix.com/news/GNU-C-Library-Glibc-2.43

AMD Ryzen AI Software 1.7 Released For Improved Performance On NPUs, New Model Support:
https://www.phoronix.com/news/AMD-Ryzen-AI-Software-1.7

ReactOS Celebrates 30 Years In Striving To Be An Open-Source Windows Implementation:
https://www.phoronix.com/news/ReactOS-30-Years-Old

ReactOS For "Open-Source Windows" Achieves Massive Networking Performance Boost:
https://www.phoronix.com/news/ReactOS-Async-Net-Connect

DragonFlyBSD Now Allows Optional AMD GCN 1.1 Support In AMDGPU Driver:
https://www.phoronix.com/news/AMD-CIK-AMDGPU-DragonFlyBSD

ChaosBSD Is A New BSD For "Broken Drivers, Half-Working Hardware, Vendor Trash" Test Bed:
https://www.phoronix.com/news/ChaosBSD
(Interesting concept, never seen such a system before, not even on Linux land with its few thousand distros lol)

#WeeklyNews #OpenSource #FOSSNews #FOSS #AI #Ollama #Penpot #Radicle #Rust #jQuery #Scala #Swift #PyTorch #GNUCLibrary #AMDRyzenAI #ReactOS #DragonflyBSD #BSD #ChaosBSD #Dev #FosseryTech

(more Linux and FOSS news in previous posts of thread)

Keep Android Open movement fights back against Google's developer verification:
https://keepandroidopen.org/

GNU C Library Adds Linux "mseal" Function For Memory Sealing:
https://www.phoronix.com/news/Glibc-Linux-mseal-Function

GCC Compiler Developers Begin Considering C++20 Default:
https://www.phoronix.com/news/GCC-Considering-CPP-20-Default

LoongArch LA32 Target Proposed For The GCC Compiler:
https://www.phoronix.com/news/LoongArch-32-bit-GCC-Patches

ollama 0.12.11 Brings Vulkan Acceleration:
https://www.phoronix.com/news/ollama-0.12.11-Vulkan

Rust 1.91.1 Released With Two Critical Bug Fixes:
https://ostechnix.com/rust-1-91-1-released/

Vulkan 1.4.333 Released With New Ray-Tracing Extension:
https://www.phoronix.com/news/Vulkan-1.4.333-Released

Flutter 3.38 & Dart 3.10 released with GenUI, new language features, and Gemini AI tools:
https://alternativeto.net/news/2025/11/flutter-3-38-and-dart-3-10-released-with-genui-new-language-features-and-gemini-ai-tools/

Homebrew 5.0 brings download concurrency by default, Linux ARM64/AArch64 support, and more:
https://alternativeto.net/news/2025/11/homebrew-5-0-brings-download-concurrency-by-default-linux-arm64-aarch64-support-and-more/

F# 10 adds #warnon, property accessor control, and struct ValueOption:
https://alternativeto.net/news/2025/11/f-10-adds-warnon-property-accessor-control-and-struct-valueoption/

IBM Joins OpenSearch Software Foundation to Advance AI-Powered Search and RAG:
https://itsfoss.com/news/ibm-joins-opensearch-software-foundation/

Wikimedia urges AI firms to stop scraping its content and to use its paid Enterprise API:
https://alternativeto.net/news/2025/11/wikimedia-urges-ai-firms-to-stop-scraping-its-content-and-to-use-its-paid-enterprise-api/

FFmpeg Calls Google's AI Bug Reports "CVE Slop":
https://itsfoss.com/news/ffmpeg-google-fiasco/

Privacy-focused mobile OS /e/OS 3.2 now warns you of applications leaking your data:
https://alternativeto.net/news/2025/11/privacy-focused-mobile-os-e-os-3-2-now-warns-you-of-applicaions-leaking-your-data/

Haiku OS Made Many Kernel & App Improvements In October:
https://www.phoronix.com/news/Haiku-OS-October-2025

#WeeklyNews #OpenSource #FOSSNews #OpenSourceNews #FOSS #Android #KeepAndroidOpen #GNUCLibrary #GCC #Ollama #Rust #Vulkan #Flutter #Dart #Homebrew #FSharp #AI #ArtificialIntelligence #FFmpeg #eOS #Haiku #OS #OperatingSystem #PackageManager #ProgrammingLanguage #Development #Programming #Coding #FosseryTech

Keep Android Open

Advocating for Android as a free, open platform for everyone to build apps on.

The #Maneage #reproducibility system for scientific research papers that starts from a minimal POSIX-like host OS does not yet build [1] the #GNUCLibrary = #GLibC . We have a draft implementation building glibc *after* #GCC [2]; and an alternative proposal arguing that building glibc *first* and gcc second would be more long-term sustainable [[1] comment18].

Should GLibC be built first? Why (or why not)?

[1] https://savannah.nongnu.org/task/?15390
[2] https://gitlab.com/maneage/project-dev/-/blob/glibc/reproduce/software/make/core-gnu.mk#L718

build glibc first
50%
build gcc first
50%
Poll ended at .

Buffer Overflow in GNU C Library Affects Older Versions

Date: April 17, 2024

CVE: CVE-2024-2961

Vulnerability Type: Out-of-bounds Write

CWE: [[CWE-787]]

Sources: SecurityVulnerability.io, NVD Mitigation blog

Issue Summary

A critical buffer overflow vulnerability has been identified in the GNU C Library's iconv function when converting charsets to certain Chinese Extended encodings. This flaw occurs when converting strings to the ISO-2022-CN-EXT character set in versions prior to 2.40, potentially leading to application crashes or memory corruption.

Technical Key Findings

The vulnerability stems from improper boundary checks during character set conversion, allowing up to 4 bytes of overflow. This could enable attackers to execute arbitrary code or disrupt program operation by manipulating memory locations adjacent to the buffer.

Vulnerable Products

All versions of GNU C Library older than 2.40 are susceptible. (That's potentially 24 years of a buffer overflow presence in the glibc!)

Impact Assessment

The vulnerability poses a high risk, potentially affecting the confidentiality, integrity, and availability of systems utilizing the affected library versions. There is no evidence of active exploitation yet, but the severity of potential impacts warrants prompt attention.

Patches or Workaround

The GNU C Library has released patches for this vulnerability. Users are advised to update to version 2.40 or later. If you are unable to (or it's not available on your OS yet), you can mitigate this issue by disabling the affected charsets in gconv.

Check if you are vulnerable

// The first line of the linker version info should include the version of glibc (either as GLIBC or GNU libc).

ldd --version

// Check if the vulnerable encodings are enabled in iconv:

iconv -l | grep -E 'CN-?EXT'

If they are, you will see an output like:

ISO-2022-CN-EXT//
ISO2022CNEXT//

Tags

#GNUCLibrary #CVE-2024-2961 #BufferOverflow #SecurityPatch #ISO2022CNEXT #CVE20242961 #iconv #iconvglibc

Buffer Overflow Vulnerability in GNU C Library's iconv() Function (CVE-2024-2961) | SecurityVulnerability.io

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

Looney Tunables, a new Linux vulnerability, exploits a weakness in the GNU C Library's dynamic loader https://www.fosslife.org/new-linux-vulnerability-affects-glibc #LooneyTunables #GNUCLibrary #Linux #vulnerability #security #FOSS