Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

FSF News: Statement regarding GNU Savannah security reports

Дата публикации: 19-06-2026 21:13:07



Основное содержимое страницы с новостью.

In early May, security researchers from Hacktron reported vulnerabilities affecting GNU Savannah and demonstrated an exploit. We have been working with these researchers since their initial report, and have also addressed additional security issues they submitted. All reported issues have been patched thanks to the hard work of GNU and FSF volunteers, as well as FSF staff.

After thorough review, we have found no reason to believe that sensitive project data or credentials were accessed, nor that there has been any compromise of Savannah's software supply chain. Nevertheless, we take the security of the GNU system, the tools which make it possible, and the projects we host very seriously. This body of software has become essential to millions (if not billions) of users around the world. We are therefore taking additional precautionary steps.

Though the initial security issue was reported to us in early May, the vulnerabilities were discovered in software that was published approximately two years prior. We will be communicating directly with Savannah-hosted projects about steps they can take to review and strengthen the security of their projects.

We have also communicated with the other Savane instances we're aware of to assist their review of their own environments, and take any steps needed to help protect their users. If you host your own instance of the Savane forge and believe you may be affected, you can contact us for guidance on mitigation steps and patching your systems. We thank Hacktron for informing us about these issues.

As we have previously documented, maintaining critical free software infrastructure requires sustained effort, specialized expertise, and long-term resilience. These requirements have increased exponentially in the last few years. Systems like Savannah support essential collaboration across the free software movement, and keeping them reliable and secure depends on the work of dedicated volunteers and staff. If you would like to help us with the increased security challenges we are facing, please consider becoming an associate member or making a donation.

This statement is intended as an initial notice. We expect to publish a report on the incident within 30 days.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1FSF News: FSF publishes incident report on GNU Savannah vulnerabilities08.107-08-2026
2GNU Taler news: Confidentiality and the digital euro08.5209-06-2026
3FSF Blogs: July GNU Spotlight with Amin Bandali featuring fourteen new GNU releases: Screen, Anastasis, and more!08.8604-08-2026
4osip @ Savannah: osip2 [5.3.2]011.7722-07-2026
5GNU Taler news: LibEuFin Connector for Dolibarr is out08.6201-05-2026
6cssc @ Savannah: CSSC-1.5.0 released06.305-07-2026
7findutils @ Savannah: GNU findutils 4.11.0 released05.4711-07-2026
8Росгвардия сообщила о нескольких DDos-атаках на сайт ведомства из-за рубежа0005-02-2021
9Обвиняемые в разбое сотрудники ФСБ уволены0002-06-2020
10В посольстве РФ прокомментировали доклад Госдепа о дезинформации0006-08-2020

Классификация: Международные. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10. Источник: planet.gnu.org.