You are here

LinuxSecurity.com

Subscribe to Feed LinuxSecurity.com
The central voice for Linux and Open Source security news.
Përditësimi: 4 orë 36 min më parë

Why an io_uring Queue Handoff Can Become a Use-After-Free

Pre, 25/09/2026 - 11:00md
A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.

Linux Patch Management For Enterprises: A Complete Guide

Pre, 25/09/2026 - 10:55md
Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own set of software packages, dependencies and updates.

Linux ext4 Patch Blocks an Out-of-Bounds Read From Damaged Metadata

Pre, 25/09/2026 - 10:35md
Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.

USB/IP Teardown Race Can Rearm a Freed Linux Kernel Timer

Pre, 25/09/2026 - 10:15md
A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.

Why an Unlocked ext4 Buffer Can Restore Stale Directory Data

Pre, 25/09/2026 - 10:15md
A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.

A Linux eBPF Trampoline Can Outlive the Program It Calls

Pre, 25/09/2026 - 9:45md
A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.

Linux Cgroup Namespace Race Could Expose a Freed Root Object

Pre, 25/09/2026 - 12:30pd
A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.

Kubernetes Security Fix Blocks Cross-Namespace Pod Creation

Pre, 25/09/2026 - 12:30pd
Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user's permissions applied. CVE-2026-2270 affects kube-controller-manager, the service that runs several controllers responsible for bringing a cluster into line with its declared configuration. A namespace is meant to keep one group's resources separate from another's. Here, a user with permission to change two objects in one namespace could influence a controller that wor...

Linux Device Driver Race Leaves Open Files Using Freed Memory

Pre, 25/09/2026 - 12:15pd
A Linux device driver can keep an open file alive while freeing the hardware state that file still needs.

Linux Integrity Checks Could Read Freed dm-verity Policy Data

Pre, 25/09/2026 - 12:15pd
Linux integrity checks depend on more than a correct policy or a trusted hash. The kernel must also keep that security state alive for the entire decision. A new patch series reports two places where Integrity Policy Enforcement could continue reading after policy or dm-verity data had been freed. Integrity Policy Enforcement, usually shortened to IPE, is a Linux Security Module that can allow or deny access according to integrity properties. dm-verity supplies read-only block-device verifica...

Linux Console Font Bug Could Read Past Its Memory Buffer

Pre, 25/09/2026 - 12:00pd
A Linux console font change could leave the framebuffer console with a buffer sized for 256 characters even after a 512-character font was installed.

MCP Toolbox Flaw Could Expose Google Service Tokens

Mër, 23/09/2026 - 9:45md
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

Emacs Security Flaw Could Run Code From an Untrusted File

Mër, 23/09/2026 - 9:45md
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.

Linux HID Flaw Could Leak Kernel Memory Through Input Events

Mër, 23/09/2026 - 9:30md
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.

Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory

Mër, 23/09/2026 - 9:25md
Linux DAMON, the kernel's Data Access Monitor, samples memory use to show which pages a workload touches.

GitHub Enterprise Server Flaw Could Let Attackers Run Code

Mër, 23/09/2026 - 8:15md
A GitHub Enterprise Server security fix addresses a way to turn the appliance's notebook viewer into a route to its own internal services.

Why Seccomp Must Be Rechecked After Container Restore

Mër, 23/09/2026 - 3:25pd
Seccomp limits which Linux system calls a process can make.

How Container Restore Can Reopen Privilege Escalation Paths

Mër, 23/09/2026 - 3:15pd
Privilege escalation in a container does not always begin with a new exploit.

What CRIU Restores Beyond Application Memory in Linux Containers

Mër, 23/09/2026 - 3:15pd
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.

Why Container Security Needs a Separate Restore Boundary

Mër, 23/09/2026 - 2:59pd
A container normally starts under the security rules of the system receiving it.

Faqet