Normale weergave
BookStack v26.03.1
Security Release
This is a security release to address a vulnerability where page content, which should be hidden by permissions, could be visible during certain markdown exports.
We strongly advise that you update your instance if you use permissions to control page visibility.
Thanks to Ghufran Raza Khan (GitHub Profile, LinkedIn Profile) for responsibly reporting this issue.
Also thanks to Alex Dan (GitHub Profile) for also reporting this before public announcement.
Full List of Changes
- Updated queries used for pages in markdown exports.
- Updated handling of filenames for file serving.
- Updated PHP package versions.
-
QNAP
- QNAP en CyberLink breiden partnerschap uit om media-creatie te optimaliseren met betrouwbare opslagoplossingen
QNAP en CyberLink breiden partnerschap uit om media-creatie te optimaliseren met betrouwbare opslagoplossingen
-
QNAP
- QNAP breidt QuWAN-architectuur uit met QuWAN Express om de flexibiliteit van NAS point-to-point VPN-connectiviteit te verbeteren
QNAP breidt QuWAN-architectuur uit met QuWAN Express om de flexibiliteit van NAS point-to-point VPN-connectiviteit te verbeteren
Counter-Strike 2 Update
- [p]Players in Germany and Netherlands will have an X-Ray Scanner tab in their Inventory. For those players, containers can only be opened via X-ray Scanner. The X-Ray Scanner will come preloaded with a one-time exclusive non-tradable "Genuine P250 | X-ray", which must be claimed before using the X-Ray Scanner to reveal items in other containers.[/p][/*]
- [p]Keyless Containers, like Souvenir Packages, can be opened without the X-Ray Scanner.[/p][/*]
FileZilla Client 3.70.0-rc1 released
New features:
- SFTP support is now based on the fzssh library
Bugfixes and minor changes:
- Fix detection of OTP requests from FileZilla Pro Enterprise Server if using non-default FTP encryption options
- MSW: Improve handling of volumes mounted as path instead of as drive letter
- *nix, macOS: Remove custom send buffer option, rely on operating system auto-tuning
March 16th, 2026, FFmpeg 8.1 "Hoare"
A new minor release, FFmpeg 8.1 "Hoare", is now available for download. Here are some of the highlights:
- Decoders: xHE-AAC Mps212 (experimental) MPEG-H decoding via libmpeghdec
- EXIF Metadata Parsing
- LCEVC: support for parsing and forwarding metadata
- Vulkan compute-based codecs: ProRes encoding and decoding, DPX decoding
- D3D12: D3D12 H.264/AV1 encoding, scale_d3d12, mestimate_d3d12, deinterlace_d3d12 filters
- Rockchip H.264/HEVC hardware encoding
- IAMF: Projection mode Ambisonic Audio Elements muxing and demuxing
- Formats: hxvs demuxer
- Filters: drawvg, vpp_amf
This release features a lot of internal changes and bugfixes. The groundwork for the upcoming swscale rewrite is progressing. The Vulkan compute-based codecs, and a few filters, no longer depend on runtime GLSL compilation, which speeds up their initialization.
A companion post about the Vulkan Compute-based codec implementations has been published on the Khronos blog, featuring technical details on the implementations and future plans.
We recommend users, distributors, and system integrators to upgrade unless they use current git master.
DistroWatch Weekly, Issue 1164
Review: d77void GNU/Linux
News: SUSE may be for sale, MidnightBSD responds to age verification laws, TrueNAS takes its build system private, System76 pushes back against new age declaration bills, Debian updates Trixie media
Questions and answers: All about age verification laws and Linux
Released last week:....
Distribution Release: SparkyLinux 2026.03
Part-DB 2.9.1
Part-DB 2.9.1
Tip
If you like Part-DB, consider donating to support the development. Press the sponsor button on the main github page, for more info.
Important
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Improvements
- Removed MPN fallback from LCSC barcode scanner, the SPN field is used instead for part matching (#1302)
- Automatically detect the delimiter on generic CSV BOM imports
Bug fixes
- Fixed intendation of EDA visibility checkboxes
- Fixed SAML login button (#1308, thanks to @mowoe)
- Fixed problem of GenericWeb info provider when used behind traefik (#1296)
- Fixed 500 error, when mapping in generic CSV BOM import fails (#1298)
- Fixed 500 error with displaying part prices, when a user has a currency preference different of base currency, and there is no conversion rate known for it (#1317)
Miscellaneous
- Updated dependencies
- Updated translations
- Updated kicad symbols
New Contributors
Full Changelog: v2.9.0...v2.9.1
BookStack v26.03
Links
Upgrade Notices
- Email/SMTP - The way BookStack sends messages has changed slightly (Specifically, the SMTP HELO domain). This isn't expected to be a breaking change but testing of emails (Using the test send action in Settings > Maintenance) is advised after updating to be sure there's no impact.
- Theme System - Within a theme directory, the
modules/folder is now dedicated to theme modules. If you happened to already have a folder of this name in your theme, it's advised to use a different folder name instead.
Full List of Changes
Released in v26.03
- Added new module system to the theme system. (#5998)
- Added logical theme events for page content render and pre-save. (#6049)
- Added logical theme event and class to allow inserting custom views before/after others. (#5998)
- Added logical theme event to allow customising the OIDC authentication URL. (#6014)
- Updated book delete to return to the parent shelf in a shelf context. (#6029)
- Updated book read API endpoint to provide parent shelf information. (#6006)
- Updated cursor to pointer for drawio diagrams. Thanks to @lublak. (#5864)
- Updated description for per-page display limits. (#6005)
- Updated emails to use the domain from the APP_URL in the SMTP HELO. (#5990)
- Updated translations with latest Crowdin changes. (#6007)
- Fixed empty extra space showing for descriptions when the input is left empty. (#5724)
Updated Debian 13: 13.4 released
trixie). This point release mainly adds corrections for security issues, along with a few adjustments for serious problems. Security advisories have already been published separately and are referenced where available.
Stable Channel Update for Desktop
The Stable channel has been updated to 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 1 security fix. Please see the Chrome Security Page for more information.
[N/A][491421267] High CVE-2026-3909: Out of bounds write in Skia. Reported by Google Threat Analysis Group on 2026-03-10
Google is aware that an exploit for CVE-2026-3909 exists in the wild.
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Srinivas Sista
CPU-Z 2.19
- AMD Ryzen AI 7/PRO 450G/E, AI 5/PRO 440G/E & 435G/E (Kraken Point 2).
- AMD Ryzen AI 9 HX 470.
- Fix AMD Ryzen 5 5500U (Lucienne) reported as 7350U (Cezanne).
- Preliminary support of Intel Wildcat Lake.
- CQDIMM (4-ranks CUDIMM) memory support.
- Fix DLL hijacking vulnerability thanks to Kwangyun Kem.
- New Chinese translation thanks to Shinjo Kurumi.
Distribution Release: GLF OS 25.11
Minecraft 26.1-pre-2 (snapshot) Released
FileZilla Server 1.12.4 released
Bugfixes and minor changes:
- FTP: Fixed path display in NSLT output
Distribution Release: EndeavourOS 2026.03.06
Distribution Release: LinuxHub Prime 2026.03.10
Distribution Release: Univention Corporate Server 5.2-5
Distribution Release: Zentyal Server 8.1
Development Release: Fedora 44 Beta
BSD Release: FreeBSD 14.4
DistroWatch Weekly, Issue 1163
Review: Quick looks at three Linux distributions
News: Guix System offers 64-bit Hurd option, Ubuntu and Fedora communities discuss age declaration laws, Linux Mint unveils new Cinnamon screensaver, Redox OS introduces new COSMIC features
Questions and answers: Would one big collection of packages help?
Released last....
Distribution Release: CachyOS 260308
Distribution Release: Zenclora OS 2.0
Mobile OS Release: iodéOS 7.3
Stable Channel Update for Desktop
The Stable channel has been updated to 146.0.7680.75/76 for Windows/Mac and 146.0.7680.75 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Updated 2026-03-13: The previous version of these notes included CVE-2026-3909, the fix
for which will instead be available in a future update.
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 1 security fix. Please see the Chrome Security Page for more information.[N/A][491410818] High CVE-2026-3910: Inappropriate implementation in V8. Reported by Google Threat Analysis Group on 2026-03-10
Google is aware that an exploit for CVE-2026-3910 exists in the wild.
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Srinivas Sista