The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: Package Forge and Soar
News: GNOME OS on smart phones, openSUSE fixes expired repository key, Ubuntu Pro users get new Enterprise Store, Debian begins Perl upgrade and votes on LLM use, FreeBSD freezes port tree
Questions and answers: Games which teach Linux
Released last week:....
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
Changed
Fixed
JMAP:
Email/copy should return alreadyExists when copying a message to a mailbox that already contains it.
Email/copy with onSuccessDestroyOriginal destroys the copy's creation id instead of the source Email id.
CalendarEvent/set does not generate a uid on create when the client omits it.
CalendarEvent/set does not refresh the updated property (iCalendar DTSTAMP) on create or update.
EmailSubmission/set rejects valid recipients whose domain is itself a public suffix (e.g. gov.in, co.uk).
Requests are rejected with notRequest when a method name contains a JSON-escaped solidus (e.g. Core\/echo).
MTA: Panic when MTA-STS is disabled and a remote MTA fetched /.well-known/mta-sts.txt.
Auth: Scoped credentials with SysApiKeyCreate or SysApiKeyUpdate permissions can regain its own account's full rights.
Web Push: Valid VAPID keys are rejected when PEM-encoded with explicit EC parameters, in SEC1 (EC PRIVATE KEY) format, or with a leading byte-order mark.
Encryption at rest: Appended messages are encrypted for accounts that did not opt in to encryptOnAppend.
Cache: Account caches silently discard entries larger than a single quick-cache shard, causing constant database rebuilds.
Registry: Id references (e.g. #certificate-...) fail to resolve on defaultCertificateId, defaultAdminRoleIds, listenerIds and publicKey.
Search: reindex drops calendar and contact index tasks for accounts with fewer than a full batch of items.
Migration: Abort --import when the target already contains data in the key range being imported.
Cluster: Broadcast subscriber re-subscribes after every message, losing bursts of cluster broadcasts during the reconnect window.
Enterprise: Per-tenant logo is not shown on the OAuth login password and OTP screens, which are served from the server's canonical host rather than the tenant domain.
The OpenWrt community is proud to announce the newest stable release of the OpenWrt 24.10 stable series.
This release fixes many security issues, several of them remotely triggerable in network services that are enabled by default. We strongly recommend everyone to upgrade.
The OpenWrt 24.10 series is in security maintenance (only security problems are fixed), with end of life (EoL) projected for September 2026. We recommend migrating to OpenWrt 25.12 before then.
Download firmware images using the OpenWrt Firmware Selector:
Main changes between OpenWrt 24.10.7 and OpenWrt 24.10.8
Only the main changes are listed below. See changelog-24.10.8 for the full changelog.
Security fixes
This release fixes several remotely triggerable vulnerabilities in core network
services that are enabled by default. Updating is strongly recommended.
odhcpd (DHCPv6/DHCPv4/RA server, enabled by default): multiple vulnerabilities reachable by a network-adjacent, unauthenticated attacker were fixed:
CVE-2026-53921 (Critical): stack buffer overflow in the DHCPv6 IA reply serialization, triggerable with crafted DHCPv6 REQUEST packets. GHSA-7fwx-hhrg-3496
Reconfigure-Accept stack buffer overflow (High, no CVE assigned): the Reconfigure-Accept reply block wrote 36 bytes into the response buffer without checking the remaining space, leading to a pre-auth out-of-bounds write. https://github.com/openwrt/openwrt/security/advisories/GHSA-q6wx-p68j-chp9
CVE-2026-53918 (High): use-after-free through a dangling first-lease pointer in the DHCPv6 IA handler. GHSA-44ff-jcwh-wgc2
CVE-2026-53920 (High): stack memory disclosure via a truncated DHCPv6 IA_NA/IA_PD option. GHSA-p769-5v73-pc4f
CVE-2026-53922 (Moderate): pre-auth denial of service via a size_t underflow in DHCPv6 IA handling. GHSA-7hcw-g2jh-pqv5
NDP hop-limit spoofing (Moderate, CVSS 5.4, no CVE assigned): the NDP relay accepted IPv6 Neighbor Solicitations with a hop limit other than 255 (RFC 4861 violation), letting an off-link attacker spoof NS packets through the relay. Only relevant when the NDP relay is enabled. https://github.com/openwrt/odhcpd/security/advisories/GHSA-qvg7-9jf5-wgjc
odhcpd / LuCI stored XSS: CVE-2026-62948 (Critical): an unauthenticated DHCPv6 client could inject lease-file lines through a crafted FQDN hostname, resulting in stored cross-site scripting on the LuCI DHCPv6 leases status page. Fixed by escaping client hostnames in the lease state file. GHSA-hhmc-92hw-535f
uhttpd (web server, serves LuCI): three HTTP request smuggling issues on keep-alive connections were fixed:
CVE-2026-55612 (High): invalid chunk-length state reset. GHSA-p55c-rmhc-qfm5
CVE-2026-55613 (Moderate): ubus POST body parse-error desync. GHSA-wgwp-64hh-f52p
In addition uhttpd received hardening without an assigned CVE: a one-byte overflow in uh_urldecode(), an off-by-one out-of-bounds read in uh_b64decode(), constant-time password comparison and stricter handling of $p$ crypt-hash entries in the authentication realm.
rpcd: ACL bypass through symlinks (High): the file plugin matched ACL grants against the textual path but then followed symlinks unchecked, so a symlink inside an ACL-covered directory let a limited account read or write arbitrary root-owned files. The path is now re-resolved and re-authorized for every operation that dereferences the final component. https://github.com/openwrt/openwrt/security/advisories/GHSA-q5gr-86pq-vvwr
cgi-io (file upload/download helper used by LuCI, installed by default with LuCI):
CVE-2026-62947 (Moderate): ACL bypass and arbitrary root file read β the download and exec paths were checked against the ACL before being canonicalized, so path traversal let an authenticated user with wildcard read permission read any root-readable file (e.g. /etc/shadow). GHSA-jw5r-xhf5-2xcq
LuCI (web interface): several issues in LuCI modules and applications were fixed. The privilege-escalation issues only apply if the affected app is installed and a limited (delegated) account with the relevant ACL exists:
luci-app-ddns (High): the ucode status backend passed DDNS UCI values such as lookup_host, dns_server and the section name to system() as an unquoted shell string, so anyone able to write DDNS configuration could execute commands as root. The invocations now use the array form of system(). https://github.com/openwrt/openwrt/security/advisories/GHSA-32r4-3wh2-qvq3
luci-app-samba4 (High): the read ACL granted exec permission for smbd in general rather than only smbd -V, allowing read-only accounts to run arbitrary commands as root. GHSA-vx64-mmp7-h36c
luci-app-upnp (High): stored XSS β an unauthenticated LAN client can inject JavaScript through a UPnP port-mapping description, which the underlying daemon does not sanitize. The description is now HTML-escaped. GHSA-8v49-6387-7f89
luci-mod-status (High): stored XSS via a DHCP/DHCPv6 lease hostname shown in the lease status tables. Together with the odhcpd fix above this closes the injection path from an unauthenticated DHCP client into the LuCI admin UI. GHSA-686p-p8p9-x6fh
luci-base: the dispatcher now escapes the URL path and user name when logging, so crafted login requests can no longer pollute the system log.
The LuCI rpcd ACL files were adjusted for the symlink-aware rpcd ACL check mentioned above, so that /proc paths that are symlinks (such as /proc/mounts) keep working.
umdns (mDNS responder): CVE-2026-55492 (Moderate, CVSS 6.5): an unauthenticated attacker on the local network segment could flood the daemon with unique mDNS records; the unbounded cache exhausted the heap and took the whole device into out-of-memory. Fixed by bounding the cache size and clamping hostile TTLs. GHSA-jg8f-fhfw-jg46
ead (Emergency Access Daemon): CVE-2026-55490 (Moderate): an integer underflow in handle_send_a() allowed an unauthenticated attacker on the local segment to crash the daemon with a single crafted packet. GHSA-9558-77jp-g3fw
dropbear (SSH): security fixes from upstream 2026.90 were backported:
CVE-2019-6111: a malicious server could make the scp client overwrite unexpected local files (missing OpenSSH patch). Note the accompanying upstream behaviour change: scp -r is now rejected when the target directory already exists.
CVE-2026-35385: scp did not clear setuid/setgid bits on received files.
An authenticated user could bypass an authorized_keysforced_command option when dropbear runs with -t; authorized_keys is now opened non-blocking (local denial of service via special files); and a close() on a file descriptor obtained from an out-of-bounds read was fixed.
musl libc: backport of the upstream fixes for CVE-2026-6042 (algorithmic-complexity denial of service in iconv) and CVE-2026-40200 (stack corruption in qsort with sufficiently large inputs).
In addition, the packages feed shipped with this release moved a number of
optional packages to newer upstream versions that contain security fixes, among
them curl (8.12.1 to 8.19.0), expat (2.7.4 to 2.8.2), BIND (9.20.23 to 9.20.26),
PHP 8 (8.3.29 to 8.3.32), Tor (0.4.8.22 to 0.4.9.10), unbound (1.24.2 to 1.25.1),
lighttpd (1.4.82 to 1.4.85), haproxy (3.0.19 to 3.0.25) and rsync (3.4.2 to 3.4.3).
collectd also received a fix for a use-after-free in the ping plugin. These
packages are not part of the default images β you have to update the installed
packages on your device to receive them.
Beyond the issues listed above, this release fixes a number of further security
and robustness problems in odhcpd, odhcp6c, rpcd and uhttpd for which no CVE
number or dedicated advisory was assigned. We strongly recommend upgrading to
the latest OpenWrt release and installing all available package updates.
Device support
No new devices were added in this security maintenance release.
Device fixes:
airoha: update the PCS driver to a newer proposed upstream version (EN7581 Ethernet SerDes)
ipq806x: Extreme Networks AP3935 - disable PHY hibernation on LAN1, which otherwise stayed dead when no cable was connected at power-on
WiFi fixes and improvements
mac80211: update the backported wireless stack and drivers from 6.12.61 to 6.12.96, containing many upstream fixes for ath10k, ath11k, rtw88, rtlwifi and iwlwifi, among them:
ath10k: skip WMI and beacon transmission when the device is wedged
ath11k: fix a warning on unbind and fix peer resolution on the RX path
rtw88: fix memory leaks on USB write failures
mac80211/nl80211: reject oversized EMA RNR lists and fix multi-link element defragmentation
hostapd / wpa_supplicant: multi-link (MLO) parsing validation fixes, see the security section above
wireless-regdb: update to 2026.05.30
Network and service improvements
odhcpd received many DHCPv6/DHCPv4 correctness and robustness fixes on top of the security fixes listed above, among them bounded nested relay recursion, correct handling of DHCPv4 Pad/End option encoding, fixed reallocation error handling and a memory leak on reload
odhcp6c: several fixes to DHCPv6 option parsing, RFC 6603 prefix-exclude handling, Reconfigure message validation and script invocation
rpcd: fixes for a use-after-free in the async exec reply path, a double close of exec pipe descriptors, an integer overflow in the UCI apply timeout and several memory leaks
umdns: update to a current version with the cache limits mentioned above
Other changes
busybox: the shell command history is now saved again. To avoid flash wear, it is written only when a shell session exits and it is stored in /tmp, so it is lost on reboot. The location can be changed in /etc/profile.d/busybox-history-file.sh.
Core components update
Linux kernel: update from 6.6.141 to 6.6.144
OpenSSL: update from 3.0.20 to 3.0.21 (multiple security fixes, see above)
dnsmasq: update from 2.90 to 2.93
mac80211: update from 6.12.61 to 6.12.96
wireless-regdb: update from 2026.03.18 to 2026.05.30
ca-certificates: update from 20260223 to 20260601 (refreshed root CA bundle)
Upgrading to 24.10
Sysupgrade can be used to upgrade a device from 23.05 to 24.10, and configuration will be preserved in most cases.
For for upgrades inside the OpenWrt 24.10 stable series for example from a OpenWrt 24.10 release candidate Attended Sysupgrade is supported in addition which allows preserving the installed packages too.
Sysupgrade from 22.03 to 24.10 is not officially supported.
There is no configuration migration path for users of the ipq806x target for Qualcomm Atheros IPQ806X SoCs because it switched to DSA. You have to upgrade without saving the configuration.
''Image version mismatch. image 1.1 device 1.0 Please wipe config during upgrade (force required) or reinstall. Config cannot be migrated from swconfig to DSA Image check failed''
User of the Linksys E8450 aka. Belkin RT3200 running OpenWrt 23.05 or earlier will need to run installer version v1.1.3 or later in order to reorganize the UBI layout for the 24.10 release. A detailed description is in the OpenWrt wiki. Updating without using the installer will break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of the Xiaomi AX3200 aka. Redmi AX6S running OpenWrt 23.05 or earlier have to follow a special upgrade procedure described in the wiki. This will increase the flash memory available for OpenWrt. Updating without following the guide in the wiki break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
Users of Zyxel GS1900 series switches running OpenWrt 23.05 or earlier have to perform a new factory install with the initramfs image due to a changed partition layout. Sysupgrade will show a warning before doing an incompatible upgrade and is not possible. After upgrading, the config file /etc/config/system should not be restored from a backup, as this will overwrite the new compat_version value.
Users of scp from the dropbear package: recursive copies (scp -r) into an already existing target directory are now rejected. This is an intentional upstream change that comes with the fix for CVE-2019-6111. Use rsync or copy into a non-existing directory instead.
Known issues
LEDs for Airoha AN8855 are not yet supported. Devices like the Xiaomi AX3000T with an Airoha switch will have their switch LEDs powered off. This will not be addressed in the OpenWrt 24.10 series any more, it is fixed in OpenWrt 25.12.
5GHz WiFi is non-functional on certain devices with ath10k chipsets. Affected models include the Phicomm K2T, TP-Link Archer C60 v3 and possibly others. For details, see issue #14541.
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Aiden McClelland has announced the release of a major new version of StartOS, a Debian-based Linux distribution optimised for personal servers, available for AArch64, riscv64 and x86_64 architectures: "Version 0.4.0 is a complete rewrite of StartOS. After six years of building, we believe we have arrived at the....
The NVIDIA SDK was updated to version 13 in this release. This means that the minimum supported driver version is now 570. If you experience any issues with NVENC, please ensure that your GPU driver version is fully up to date.
32.2.1 Hotfix Changes
Fixed game capture failing after updating OBS if the previous hook was still in use [notr1ch]
32.2 New Features
Replaced add source dropdown with new dialog [Warchamp7]
Added copy paste functions to frontend API [exeldro]
Added filter to compose SDR into HDR [jpark37]
Added delete as a hotkey to delete sources on macOS [PatTheMav]
Added dynamic bitrate support to multitrack video [lexano-ivs]
Added missing file support for filters [exeldro]
Added ability for plugins to set custom icons for new source types [cg2121]
Improved FPS selector UX [jcm93]
Included .webp files when adding a directory to Image Slide Show source [TarunCore]
32.2 Changes
Forced Intel-based installations to update to Apple Silicon version on macOS [PatTheMav]
This change means that OBS Studio versions built for Intel-based Macs but running on Apple Silicon Macs will automatically update to OBS Studio built for Apple Silicon Macs. If an installation was using third-party plugins, those plugins will no longer load until replaced with Apple Silicon versions.
Fixed audio mixer state getting out of sync when changing settings via websockets or plugins [Warchamp7]
Added theming for checked QToolButtons [glikely]
Added minimum width to spinboxes [Warchamp7]
Changed new capture devices to use fallback frame rate by default [PatTheMav]
Improved OpenGL performance slightly on low-end machines [kkartaltepe]
Set minimum size for color source to 1 pixel [exeldro]
Disallowed overwriting the crash handler [sebastian-s-beckmann]
Applied process mitigation policies for Windows [notr1ch]
Adjusted description of multitrack video [jhnbwrs]
Improved DLL loading behavior on Windows [notr1ch]
Limited multitrack video config to Custom service [PatTheMav]
Removed redundant "Monitor Only" from the Advanced Audio Properties window [Warchamp7]
Mute and Monitor are handled independently in the new Audio Mixer
Removed Close button from What's New dialog [Warchamp7]
Removed margins from What's New dialog [Warchamp7]
32.2 Bug Fixes
Fixed OAuth and dock state save corruption [PatTheMav]
Fixed group bounds not resizing when removing items [howellrl]
Fixed canvas mixes not being restored after video reset [dsaedtler]
Fixed some erroneous crashes during shutdown [Warchamp7]
Fixed display capture sometimes capturing black after a duplicator failure [ThrowTop]
Fixed color of controls dock output buttons in System theme [shiina424]
Fixed virtual camera reset failures [stephematician]
Fixed potential crash when user discards changes in the settings window [suogesi]
Fixed incorrect return value in virtualcam filter [xtfo]
Fixed source toolbar buttons not working after dragging a source into a group [Warchamp7]
Fixed properties hint icon spacing [Warchamp7]
Fixed potential crash when a video device reconnects on macOS [jcm93]
Fixed an issue where PipeWire could fail on NVIDIA GPUs [hoshinolina]
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Saeed Badreldin has announced the release of Helwan Linux 5.0, a significant update of the project's Arch-based distribution designed primarily for developers: "We are proud to announce the launch of Helwan Linux 5.0, a version that marks a qualitative leap in our distribution philosophy and development. What's new....
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The UBports project has published a new feature update, UBports 24.04-2.0, which introduces web browser updates and support for "notch" areas in output displays. "Ubuntu Touch 24.04-2.0 is a feature update under the same Ubuntu 24.04 base as the previous release. Nonetheless, this release contains exciting updates and....
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Shadowfetch Linux distribution is a Debian-based project which features the Plasma desktop. The latest release of Shadowfetch, version 2.0.0, enables automatic Btrfs snapshots prior to package changes, making rolling back to working snapshots easier. The project has also revamped its welcome screen. "Boot straight into a working....
In the 1.60 update, we have introduced the Improved Material System for selected trucks for both Euro Truck Simulator 2 and American Truck Simulator. And today, we bring you a look behind the scenes at how this feature came to life!
The two main people working on this feature are our colleagues Daniel and Martin, who were and still are implementing the system for trucks in both games, and also for cars in the upcoming Road Trip project for American Truck Simulator.
Daniel - Vehicle Technical Leader
"I've been working at SCS Software for over thirteen years. I started as a 3D Generalist, then worked as a 3D Vehicle Artist and Vehicle Team Lead. Today, my role is the Vehicle Technical Leader.
My work bridges the gap between the graphical and technical aspects of development. I collaborate with programmers to implement vehicle features into the engine, while also helping artists establish efficient workflows. I also design new tools and technical improvements.
My task on the improved material system was to identify the problem, propose a solution, and collaborate with programmers on its implementation into the engine. Next, we needed to set up a practical workflow for the vehicle team so that the system could be used consistently across other vehicles. The programmers created the necessary support in the engine and shaders. The graphic designers then converted and fine-tuned the materials for specific trucks."
Martin -Β Senior 3D Graphic Designer
"I work as a Senior 3D Graphic Designer specializing in vehicles. I also worked as Head of Content for the Road Trip project. I participated in selecting the vehicles and their specific variants, handled research and pre-production, provided expert consultation, and subsequently worked on the actual creation of the vehicles. I also helped Dan fine-tune changes to the material system.
Cars have been a long-standing passion of mine, especially sports cars and classic cars - particularly American ones. Thanks to this, I was able to bring my own experience and knowledge of American automotive culture, history, and the technical development of individual models to the project.
My main task was the 1967 Ford Mustang and everything related to its visual and content preparation. I was involved in selecting the specific car and its variant, conducting research, gathering references, consulting during data collection, and the actual creation of the model and materials.
During the development of the new material system, I prepared and fine-tuned the individual surfaces on the Mustang. Together with Dan, we used this car to verify how the new technical solution behaved in practice and which values provided the most accurate results."
How did this project start?
"Development began while we were working on the Road Trip project. The interiors of passenger cars are smaller and darker than those of trucks, so the shortcomings of the original system were more noticeable in them.
Aside from direct light, the original system had no way to render light within the interiors. In the real world, a large portion of the visuals consists of so-called indirect, or reflected light (GI). However, the game did not work with this concept at all and was not designed for it. We knew we needed to change this somehow.
The second problem was that the interiors of the trucks contain many different materials, such as fabric, leather, plastic, painted surfaces, metal, and glass. The original system was unable to render them accurately, especially under indirect lighting; everything looked very flat.
"Road Trip provided us with a suitable, isolated environment for development and testing. From the start, however, we designed the system so that it could also be used for trucks," says Daniel.
What did you have to do before actually starting to implement the improved system?
"We needed to map out the actual vehicles and the materials used in their interior in detail through extensive research. I studied magazines, photographs, available documentation, and individual trim levels. While gathering data, we had the opportunity to see the specific car in person, speak with its owner, and document its construction and appearance in detail.
It wasn't enough to simply determine that a certain part of the interior was made of, for example, plastic, leather, or metal. We also had to examine the surface texture, the degree of gloss, the way the material reflects light, its wear and tear, the color shade, and the differences between individual parts.
This research laid the foundation upon which we could later assess whether the materials in the game corresponded to the actual vehicle," Martin told us.
"We also had to decide which direction to take. One of the key requirements was maintaining performance, so we looked for approaches that didn't require complex computational operations and sought techniques that would achieve good results with minimal changes to computational complexity. I believe the result of our efforts is a noticeable improvement in graphics with minimal impact on performance," Daniel shared with us.
How did the process of bringing the new system into the game look?
"We needed to implement changes to the engine regarding how the game loads and handles reflective textures. A reflective texture is essentially a cube where each face shows a reflection in a different direction relative to the player. Using it is significantly more efficient than calculating actual light reflections using ray tracing. We made several changes to the code to gain direct access to individual mipmaps. A mipmap is a scaled-down copy of the original image, typically used when a textured object is farther away from the player to eliminate unappealing texture aliasing. In our specific case, however, a lower resolution automatically results in a softer reflection, which can be used for materials that do not have a 100% glossy surface but rather a physically rougher surface, causing the reflection on the material to be more diffuse.
This way, we created several different levels of reflection smoothness, ranging from perfectly glossy surfaces like chrome, through smoother reflections such as those found on leather seat materials, to rough, nearly non-reflective materials like fabrics, where one side of the reflection cube is only 2x2px. In our case, it replaces the Iradience map, which means it primarily serves to project the surrounding light palette onto the given material (color cast). The game was already calculating the mipmaps themselves, which means this change costs us practically nothing in terms of performance - and that is the main reason we decided to use this approach.
Along with the material changes, we also needed to rebalance the contrast and lighting throughout the game to eliminate extremely dark areas and achieve a more realistic sense of lighting.
Unlike the original solution, where reflective textures were used only for highly reflective materials, particularly metals, the revised system applies a reflective texture to every single material in the vehicle's interior. However, they differ in how strongly the reflection is visible in the final image and in the softness of the reflection applied. This ensures that even less reflective materials - especially plastics - convey a sense of reflected light, color cast, and improved contrast, particularly in shaded areas of the interior. Players will now notice that the entire interior actually reacts to the truck's surroundings; for example, when driving past trees, the part of the interior near the windows takes on a subtle green tint. This makes the game feel much more realistic than before, even without the computationally expensive global illumination (GI) calculation.
Once the technology was ready, we needed to determine how to adjust the individual materials under the new conditions. Since each material now includes a reflective component, we had to completely rebalance all the settings for each material. To ensure that existing textures would function correctly with the new settings, we also had to rebalance their color and specular components to the standard values we had established during our extensive testing.
The final step for system-wide deployment was to create a material library so that we wouldn't have to configure each material type separately for every vehicle," Daniel explains.
What were the biggest challenges in implementing the system?
"The biggest challenge was the diversity of the vehicles. The individual trucks were created at different times and used different source data, textures, and rendering methods. There is no single conversion that works for all trucks. Each completed interior has its own structure and requires a customized approach," says Daniel.
"Also, the individual properties of materials influence one another. Changing the reflectance or roughness might improve the appearance of one surface, but at the same time cause the material to behave poorly in a different lighting situation. Or a material that looked right in direct daylight might be too shiny in a dark interior or react unnaturally while driving at night. It was therefore necessary to constantly strike a balance between realism, visibility, and consistent behavior. The goal was not to make all surfaces more prominent or shinier, but to accurately capture the differences between them.
We reworked many of these steps several times during development. However, the result was not just materials for one specific car, but also experience and guidelines that will significantly facilitate work on future vehicles.
The process wasn't straightforward. It wasn't enough to simply set a few parameters according to a pre-prepared table. We had to figure out many of the values ourselves, and together with Dan, we tested them repeatedly right in the game," Martin added.
How did you manage to do the changes without affecting performance?
"Our players use a wide range of hardware. We didn't want to create visual enhancements that would significantly reduce the game's performance or even make the game unplayable for some players. Therefore, the system is not based on a new, resource-intensive lighting simulation. It extends the existing rendering pipeline and utilizes already available data more efficiently.
Performance was continuously profiled during development. The goal was to achieve a visible improvement with minimal impact on the graphics card and memory. Furthermore, the system is configured to function with a certain trade-off even when set to medium or low - in such cases, while reflections are not rendered in real time and some benefits, such as realistic color cast from the vehicle's surroundings, are lost, the materials themselves still look realistic and can be distinguished from one another," says Daniel.
So far, we've implemented the improved material system on four trucks across ETS2 and ATS. Rather than making the community wait until every truck has been updated, we'll continue rolling out the improved material system for other trucks gradually, allowing you to enjoy the improvements on some vehicles already while we complete the rest. As Daniel explains here:
"Each truck requires individual adjustments, a visual inspection, and testing of all variants in daylight, at night, in the rain, and in cloudy weather. Therefore, it was not possible to update the entire fleet at once. This smaller initial group will allow us to verify the entire production process, maintain quality, and gather feedback from players."
We hope you have enjoyed this in-depth look at how we work on the improved material system. Make sure to also add theΒ Ford Car Pack and the RAM & Dodge Car Pack to your Steam wishlist, so you can enjoy this feature on cars when we release them.
Fix the issue that proxmox-ve can not boot after install in grub2 mode.
Languages update.
================================================================
Wana boot and install OS through network (PXE)? Welcome to my new project iVentoy.
About iVentoy https://www.iventoy.com/
iVentoy is an enhanced version of the PXE server.
Extremely easy to use
Many advanced features
x86 Legacy BIOS, IA32 UEFI, x86_64 UEFI and ARM64 UEFI mode supported
110+ common types of OS supported (Windows/WinPE/Linux/VMware)
Turn any PC, laptop, server, NAS, or Raspberry Pi into a PXE server instantly!
......
The Stable channel has been updated to 150.0.7871.186/.187 for Windows andMac and 150.0.7871.186 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havenβt yet fixed.
This update includes 4 security fixes. Please see the Chrome Security Page for more information.
[N/A][518237034] High CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30
[N/A][522064153] High CVE-2026-16806: Use after free in WebMCP. Reported by Google on 2026-06-10
[N/A][523292588] High CVE-2026-16805: Use after free in Blink. Reported by Google on 2026-06-12
[N/A][524721670] High CVE-2026-16804: Use after free in Input. Reported by Google on 2026-06-16
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Interested in switching release channels? Find out howhere. If you find a new issue, please let us know byfiling a bug. Thecommunity help forum is also a great place to reach out for help or learn about common issues.
fix error message (#5922) 'all' is a synonym for 'all_others'
fix clearing lists with environment variables (#5410) (#5924) MTX_AUTHINTERNALUSERS_0_IPS, MTX_LOGDESTINATIONS and MTX_RTSPTRANSPORTS can now be used to clear their corresponding list by setting them to an empty value.
add runOnOnline / runOnOffline hooks (#5399) (#5956) These are triggered and a stream is online (i.e. not just provided by an offline segment).
rename runOnReady into runOnAvailable, runOnNotReady into runOnUnavailable (#5957)
fix wrong PTS and wrong playback of alwaysAvailableFile (#5436) (#5960) PTS offset of samples was not properly considered, and sleep between samples was PTS-based instead of being DTS-based.
avoid potential timing attack when validating SHA256 credentials (#5961) The == operator is vulnerable to timing attacks as it short-circuits on a mismatch. Use ConstantTimeCompare to avoid this vector. Co-authored-by: Tristan Matthews tmatth@videolan.org
normalize authentication error messages (#5421) (#5959) Log authentication errors as soon as possible, use the "warn" level, use the same message whatever the author or protocol.
adjust code to prevent security scan false positives (#5963) about string escaping.
ask for credentials only in case of protocols that support it (#5966) When clients connect with some protocols (SRT, RTMP), they are unable to provide credentials even if they are asked to. In this case, it's useless to wait for credentials, and it's better to immediately log authentication errors and apply the anti-brute force algorithm.
generate most of OpenAPI automatically (#5918) enums and structs are now generated automatically. This eliminates some inconsistencies and makes development easier.
Media-Over-QUIC
fix race condition during startup (#5965) allocate the HTTP server only after the MoQ server has been initialized.
fix several panics and OOM errors (#5964) Check for limits before allocating memory by using sizes passed from the remote peer. Also add fuzzing to all MoQ primitives.
support draft-19 of the specification (#5968) * support draft-19 of the specification * support subscribing the same track multiple times.
prevent excessive CPU consumption in reorderer (#5976) do not iterate by maxGroupID (passed by user) but iterate by internal pending packets (uncontrolled by user).
WebRTC
prevent cross-origin unauthorized access (#5975) when a user had previously inserted credentials into a MediaMTX instance through a browser, and AllowOrigins was set to a wildcard, third-party websites visited by the user were allowed to read streams without restrictions. This is now prevented by returning "*" in Access-Control-Allow-Origins when AllowOrigins is a wildcard, a behavior that prevents browsers from sharing credentials with third-party websites.
RTSP
restrict UDP port range to 32768-60999 (#5398) (#5958) this is the default Linux ephemeral port range.
use session ID in requests to the external authentication server (#5977) Co-authored-by: Cycle1337 Cycle1337@outlook.com
prevent cross-origin unauthorized access (#5975) when a user had previously inserted credentials into a MediaMTX instance through a browser, and AllowOrigins was set to a wildcard, third-party websites visited by the user were allowed to read streams without restrictions. This is now prevented by returning "*" in Access-Control-Allow-Origins when AllowOrigins is a wildcard, a behavior that prevents browsers from sharing credentials with third-party websites.
SRT
fix compatibility with StreamToStudio app (#5414) (#5928)
Dependencies
code.cloudfoundry.org/bytefmt updated from v0.78.0 to v0.82.0
github.com/alecthomas/kong updated from v1.15.0 to v1.16.0
github.com/bluenviron/gohlslib/v2 updated from v2.4.0 to v2.4.1
github.com/bluenviron/gortmplib updated from v0.4.0 to v0.4.1
github.com/bluenviron/gortsplib/v5 updated from v5.6.1 to v5.6.2
github.com/bluenviron/mediacommon/v2 updated from v2.9.1 to v2.9.2
github.com/matthewhartstonge/argon2 updated from v1.5.5 to v1.5.6
github.com/pion/ice/v4 updated from v4.2.8-0.20260604162030-72f5001c4596 to v4.3.0
github.com/pion/interceptor updated from v0.1.45 to v0.1.46
github.com/pion/rtcp updated from v1.2.16 to v1.2.17
github.com/pion/rtp updated from v1.10.2 to v1.10.5
github.com/pion/webrtc/v4 updated from v4.2.15 to v4.2.17
github.com/pires/go-proxyproto updated from v0.12.0 to v0.15.0
github.com/quic-go/webtransport-go updated from v0.11.0 to v0.11.1
golang.org/x/crypto updated from v0.53.0 to v0.54.0
golang.org/x/net updated from v0.56.0 to v0.57.0
golang.org/x/sync updated from v0.21.0 to v0.22.0
golang.org/x/sys updated from v0.46.0 to v0.47.0
golang.org/x/term updated from v0.44.0 to v0.45.0
github.com/pion/datachannel updated from v1.6.0 to v1.6.2
github.com/pion/dtls/v3 updated from v3.1.4 to v3.1.5
github.com/pion/sctp updated from v1.10.0 to v1.11.0
github.com/pion/stun/v3 updated from v3.1.5 to v3.1.6
github.com/pion/turn/v5 updated from v5.0.9 to v5.0.12
golang.org/x/text updated from v0.38.0 to v0.40.0
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
UpSnap is, and always will be, free and open source software.
If someone is asking you to pay money for access to UpSnap binaries, source code, or licenses, you are being scammed.
The official and only trusted source for UpSnap is this repository (and its linked releases).
Do not pay third parties for something that is provided here for free.
If you've been following our rework projects in American Truck Simulator, you may be wondering what's next after our recent focus on Route 66. Today, we're excited to share the answer! Our next major undertaking will be the Nevada Rework Project, where we'll give the Silver State a complete overhaul.
As part of this next phase, our map designers will focus on the entire state of Nevada, reworking all of its existing cities and road networks to bring them up to the quality standards of our latest content. Since Nevada was one of the original states released with American Truck Simulator, this rework will allow us to rebuild many locations from the ground up while preserving the character and atmosphere that make the state so unique.
In addition to refreshing familiar places, we're also taking the opportunity to expand Nevada with locations and road connections that were missing from the original version. One example is the city of Fallon, located east of Carson City. Alongside it, we'll also add the missing sections of US-95 that pass through Fallon from south to north, creating a more complete and authentic driving experience.
Throughout the state, you can also look forward to a variety of brand-new custom depots, offering more diverse delivery destinations and making freight transportation across Nevada feel even more immersive than before.
This is just the beginning of the Nevada Rework Project, and we're looking forward to sharing more previews from development as work progresses. Be sure to follow us onΒ X/Twitter, Facebook, Instagram, TikTok,Β Bluesky, and YouTube, or sign up for our newsletterΒ so you don't miss any future updates. Until next time, keep on truckin'!
Ever since we introduced the idea of a community-powered device database at State of the Open Home 2025, our goal has been clear: create a βWikipedia of smart home devicesβ based on real-world usage. In February, we took the first step by inviting Home Assistant users to voluntarily share anonymized device data to help us build it.
Β The Stable channel has been updated to 151.0.7922.47/.48 for Windows andMac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in thelog.
You can find more details about early Stable releases here.
Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Our wheels keep turning, and today weβre ready to share a teaser of another U.S. state currently in development for American Truck Simulator. Letβs see how good your guessing game is!
So, here are your clues! Take a close look at the screenshot and teaser video below. It may seem a little fishy at first, but sometimes the smallest hints can lead to the answer.
This next destination is known for its wide-open spaces, long-haul roads, and a landscape where the horizon seems to stretch on forever. Itβs a place shaped by hardworking industries, strong prairie winds, and a pioneering spirit that still runs deep today.
Think youβve caught on to where weβre heading next? Drop your guesses in the comments below, and when the time is right, we look forward to sharing more about what awaits on the road ahead in this part of the U.S. Until then, be sure to follow our blog and our social channels on X, Instagram, Facebook, and TikTok so you donβt miss a thing.
We are pleased to announce the third release candidate preview release of Jellyfin 12.0!
This is a preview release, intended for those interested in testing 12.0 before its final public release. We welcome testers to help find as many bugs as we can before the final release.
As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!
A note about versioning
Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.
What's new?
The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.
Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!
Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.
Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.
Installing
This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.
For all non-Docker environments, you can find the files for manual download in our repository by selecting "Stable Preview" for your OS.
For Docker, you can pull the 12.0-rc3 or preview tags.
We are pleased to announce the third release candidate preview release of Jellyfin 12.0!
This is a preview release, intended for those interested in testing 12.0 before it's final public release. We welcome testers to help find as many bugs as we can before the final release.
As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!
A note about versioning
Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.
What's new?
The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.
Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!
Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.
Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.
Installing
This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.
For all non-Docker environments, you can find the files for manual download in our repository by selecting "Stable Preview" for your OS.
For Docker, you can pull the 12.0-rc3 or preview tags.