
-
I. Background The libarchive(3) library provides a flexible interface for reading and writing streaming archive files such as tar(1) and cpio(1), and has been the basis for the FreeBSD implementation of the tar(1) and cpio(1) utilities since FreeBSD 5.3. II. Problem Description An integer overflow in the archive_read_format_rar_seek_data() function may lead to a double free problem. III. Impact Exploiting a double free vulnerability can cause memory corruption. This in turn could enable a threat actor to execute arbitrary code. It might also result in denial of service.
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc
-

What’s Changed
- The launcher now has a download mirror option for users in China, and no longer auto-downloads on first run. The version check should now also work with SOCKS proxies.
- Feat/expected_workload_with_existing_cards implementation by @Luc-Mcgrady in #4243
- Update stale comment by @user1823 in #4235
- Feat/Show health check and already optimal at the same time by @Luc-Mcgrady in #4238
- “Workload” variable typo by @Luc-Mcgrady in #4239
- Fix/use real step count to simulate by @L-M-Sherlock in #4240
- Feat/Card stats update review time by @Luc-Mcgrady in #4236
- Statistics “Reviews” graph, make the color of “New” and “Learning” cards consistent with the color of card count by @thomasrixen in #4245
- Fix simulator graph not visible when viewport height < 400px by @iamllama in #4248
- Fix show_exception’s messagebox always formatting as plaintext by @iamllama in #4246
- Limit time studied today to minutes by @user1823 in #4242
- Fix Cards with Missing Last Review Time During Database Check by @L-M-Sherlock in #4237
- Use space-around for tabbed values by @Luc-Mcgrady in #4252
- Fix/Retention help button bounds by @Luc-Mcgrady in #4253
- Fix/Exclude new cards from is_due_in_days by @user1823 in #4249
- Feat/Neaten dr graph x-axis by @Luc-Mcgrady in #4251
-
This Reddit user did it.

-
Highlights:
- Available for all major mobile and desktop operating systems.
- Completely free. No ads, no tracking.
- Does not require a Proton account, but syncing is difficult without one.

-
According to the mailing list Debian 13 is expected on August 9th.

https://lists.debian.org/debian-devel-announce/2025/07/msg00003.html









