Over at the bad place, @evilsocket has reported an unauthenticated RCE in all GNU/Linux systems.
Canonical, RedHat and others have confirmed the severity, rating it a 9.9. Despite this, no working fix or CVE has been issued. Simone says the devs responsible are being defensive and dragging their feet.
Are things really as bad as Simone says?