You are here

Agreguesi i feed

KubeCap Finds Excess Linux Capabilities in Kubernetes Workloads

LinuxSecurity.com - Pre, 28/08/2026 - 9:45md
A Kubernetes workload can run with more Linux capabilities than its code needs. When capability settings are missing or broad, that excess authority may remain invisible because the application still works.

Linux Kernel 7.1-rc5 Tracing Reader Use-After-Free Bug Discovery

LinuxSecurity.com - Pre, 28/08/2026 - 9:15md
Removing a Linux trace instance should end its lifetime. An open tracefs reader can currently keep using that instance after another task removes it, creating a kernel use-after-free path in the tracing subsystem.

eBPF Security Research Adds State-Aware Syscall Filtering

LinuxSecurity.com - Pre, 28/08/2026 - 9:05md
A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup often has to keep every required call available for the service's entire lifetime.

Faqet

Subscribe to AlbLinux agreguesi