You are here

LinuxSecurity.com

Subscribe to Feed LinuxSecurity.com
The central voice for Linux and Open Source security news.
Përditësimi: 1 ditë 23 orë më parë

Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race

Pre, 02/10/2026 - 2:00pd
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.

Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race

Pre, 02/10/2026 - 1:45pd
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.

Proposed Linux QNX6 Fixes Address Filesystem Memory Errors

Pre, 02/10/2026 - 1:35pd
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.

LightLLM Profiling Flaw Allows Code Execution Without a Login

Pre, 02/10/2026 - 1:20pd
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.

ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

Pre, 02/10/2026 - 12:35pd
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.

Linux Device Driver Fix Prevents Clock Lookups From Reading Freed Memory

Enj, 01/10/2026 - 3:15pd
A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.

Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Enj, 01/10/2026 - 3:15pd
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux Storage Fix Stops Cleanup From Freeing the Same Object Twice

Enj, 01/10/2026 - 3:00pd
A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.

Apache Karaf Flaws Can Let Limited Users Run Commands or Rewrite Files

Enj, 01/10/2026 - 2:45pd
Apache released Karaf 4.4.12 on September 27, 2026, to fix three authorization flaws in its Java server runtime.

Command Injection Flaw in shell-quote Can Execute Linux Commands

Enj, 01/10/2026 - 1:00pd
The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.

Linux Perf Filter Can Expose the Kernel’s Randomized Address

Mër, 30/09/2026 - 2:45pd
A newly reported Linux perf filter flaw lets an unprivileged user find where the kernel is loaded on a tested x86-64 configuration.

Linux File Truncation Patch Targets Data Loss Beyond the Requested Range

Mër, 30/09/2026 - 2:30pd
A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.

Linux Tracing Patch Addresses a Probe Use-After-Free Race

Mër, 30/09/2026 - 2:23pd
A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.

Linux Memory Fault Bug Can Release a Lock Twice on SuperH

Mër, 30/09/2026 - 2:15pd
A proposed Linux patch addresses a double unlock in the SuperH architecture’s page-fault handling.

How to Review Linux Security Boundaries: Three Kernel Examples

Mër, 30/09/2026 - 1:35pd
A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.

GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Mar, 29/09/2026 - 8:25pd
Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

crun Blocks Container Images From Choosing Host MicroVM Settings

Mar, 29/09/2026 - 5:45pd
crun has tightened the boundary between container-controlled configuration and host-controlled microVM behavior.

Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch

Mar, 29/09/2026 - 1:45pd
Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a program.

Linux GPU Security Fix Prevents Stale Mappings Across Containers

Mar, 29/09/2026 - 12:45pd
A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.

runc 1.5.2 Shields Containers From a Linux cgroup v2 Memory-Corruption Bug

Mar, 29/09/2026 - 12:25pd
runc 1.5.2 adds a workaround for a Linux cgroup v2 memory-corruption bug that can make the privileged container runtime crash unpredictably.

Faqet