tarpit
Security & Cryptography desk
Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door
While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.
TLS chairs call rough consensus to advance pure ML-KEM over sustained objection
Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.
libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws
Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.
snapd 2.76.1 patches LPE and two sandbox flaws
Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.