The central voice for Linux and Open Source security news.
Përditësimi: 4 orë 36 min më parë
Pre, 25/09/2026 - 11:00md
A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.
Pre, 25/09/2026 - 10:55md
Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own set of software packages, dependencies and updates.
Pre, 25/09/2026 - 10:35md
Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.
Pre, 25/09/2026 - 10:15md
A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.
Pre, 25/09/2026 - 10:15md
A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.
Pre, 25/09/2026 - 9:45md
A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.
Pre, 25/09/2026 - 12:30pd
A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.
Pre, 25/09/2026 - 12:30pd
Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user's permissions applied. CVE-2026-2270 affects kube-controller-manager, the service that runs several controllers responsible for bringing a cluster into line with its declared configuration. A namespace is meant to keep one group's resources separate from another's. Here, a user with permission to change two objects in one namespace could influence a controller that wor...
Pre, 25/09/2026 - 12:15pd
A Linux device driver can keep an open file alive while freeing the hardware state that file still needs.
Pre, 25/09/2026 - 12:15pd
Linux integrity checks depend on more than a correct policy or a trusted hash. The kernel must also keep that security state alive for the entire decision. A new patch series reports two places where Integrity Policy Enforcement could continue reading after policy or dm-verity data had been freed. Integrity Policy Enforcement, usually shortened to IPE, is a Linux Security Module that can allow or deny access according to integrity properties. dm-verity supplies read-only block-device verifica...
Pre, 25/09/2026 - 12:00pd
A Linux console font change could leave the framebuffer console with a buffer sized for 256 characters even after a 512-character font was installed.
Mër, 23/09/2026 - 9:45md
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.
Mër, 23/09/2026 - 9:45md
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.
Mër, 23/09/2026 - 9:30md
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.
Mër, 23/09/2026 - 9:25md
Linux DAMON, the kernel's Data Access Monitor, samples memory use to show which pages a workload touches.
Mër, 23/09/2026 - 8:15md
A GitHub Enterprise Server security fix addresses a way to turn the appliance's notebook viewer into a route to its own internal services.
Mër, 23/09/2026 - 3:25pd
Seccomp limits which Linux system calls a process can make.
Mër, 23/09/2026 - 3:15pd
Privilege escalation in a container does not always begin with a new exploit.
Mër, 23/09/2026 - 3:15pd
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Mër, 23/09/2026 - 2:59pd
A container normally starts under the security rules of the system receiving it.
Faqet