Dear deepin Users and Community Members, A local privilege escalation vulnerability codenamed ActPedit (also known as pedit COW) has recently been disclosed in the Linux kernel. This vulnerability falls under the same category of page cache write vulnerabilities as the previously disclosed Dirty Frag and Copy Flaws. An attacker with low-privilege local access can exploit this flaw to tamper with the page cache of read-only files, escalate privileges and gain root access. Proof-of-Concept (PoC) codes and detailed exploitation techniques for this vulnerability have been released to the public. Given its high severity and broad impact, we strongly recommend all users ...Read more
(中文) 新突破!deepin-wine11-stable 上线,原生支持 Wayland,Treeland 解锁企业微信新体验!
Sorry, this entry is only available in 中文.
Urgent Security Update: Fix for Dirty Frag Kernel CVES – Upgrade ASAP
Dear deepin users and community partners, Recently, a local privilege escalation vulnerability in the Linux kernel was disclosed, referred to in the industry as Dirty Frag or Copy Fail 2. This vulnerability is a variant of the same class as the Copy Fail vulnerability. An attacker who has already obtained local low-privilege code execution may exploit this vulnerability to tamper with the page cache of read-only files, further escalate privileges, and gain root access. According to publicly available information, exploit code for this vulnerability has already been circulated. Given its severity and widespread impact, we strongly recommend that all users ...Read more
Urgent Security Update | Fix for Linux Kernel Copy Fail Local Privilege Escalation Vulnerability – Upgrade Immediately!
Dear deepin users and community partners, Recently, the deepin community detected a high-risk local privilege escalation vulnerability in the Linux kernel. This vulnerability, dubbed "Copy Fail" (CVE-2026-31431), exists in the Linux kernel cryptographic subsystem (the algif_aead module). It originates from a code optimization introduced in 2017, which causes the AF_ALG cryptographic interface to potentially share the same kernel page cache page between the source and destination buffers when processing AEAD cryptographic operations. Given its severity and widespread impact, we strongly recommend that all users upgrade as soon as possible to ensure the security of your systems. I. Vulnerability Information CVE ...Read more
deepin App Store Upgraded!
deepin, a prominent open-source operating system recognized globally with an impressive ranking on DistroWatch, consistently focuses on optimizing the desktop experience. Recently, the official App Store has completed a new round of upgrades. This all-in-one application management platform now features over 100,000 commonly used applications spanning scenarios like office work, daily life, and entertainment. These officially verified, reliable resources comprehensively meet the needs of both individual and enterprise users, ensuring safety and peace of mind. This upgrade focuses on practical features, visual experience, and bug fixes. It delivers comprehensive enhancements across operational experience, ecosystem integration, interface layout, and management efficiency, ...Read more
