Linux News Articles

Recent news articles refferecing the vendors vulnerabilities.

AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access - IT Security News

2026-09-30 12:09 Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory...

4 days ago

Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access - IT Security News

2026-09-30 10:09 A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root. This exploitation involves an...

4 days ago

Ubuntu Container Escape Vulnerability Gets Public Exploit Before Kernel Patch Arrives | Linux Journal

Ubuntu administrators running containerized workloads have a new Linux kernel security problem to watch closely. Public exploit code is now available for CVE-2026-80521, a Linux kernel use-after-free...

1 week ago

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A Linux KVM flaw on ARM64 can expose host kernel memory to guests and enable guest-to-host escape when nested virtualization is enabled.

2 weeks ago

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

2 weeks ago

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

CISA added three actively exploited Linux kernel flaws to its KEV catalog, including bugs that can enable local privilege escalation and DoS.

2 weeks ago

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers - SwapUpdate

Swati KhandelwalAug 07, 2026Linux / Vulnerability

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers - IT Security News

2026-08-08 11:08 SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address...

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host - IT Security News

2026-08-07 21:08 A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and...

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host.

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges - IT Security News

2026-08-07 16:08 A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux...

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges

A Linux kernel flaw, tracked as CVE-2026-64561 (Zapscape), allows KVM guests to escape to the Linux host with root privileges.

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Linux SCTP flaw CVE-2026-64564 dates back to 2008 and Tencent researchers say it could escape containers and gain host root.

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Swati KhandelwalAug 06, 2026Virtualization Security / Linux

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape could let guest root escape nested KVM and execute code on the Linux host through a shadow-MMU use-after-free; no in-wild exploitation is cla

New Release: Tails 7.10.1 | Tor Project

This release is an emergency release to fix critical security vulnerabilities in the Linux kernel and the expat XML library. Changes and updates Update the Linux kernel to 6.12.100, which fixes...

New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular Linux distributions.

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

CVE-2026-64531 lets local users exploit Open vSwitch kernel memory corruption to gain root, with a public PoC covering roughly 800 builds.

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.

SharedRoot Exposes Claude Cowork: How One Kernel Flaw Let AI Agents Roam Free on Macs

SharedRoot let Claude Cowork agents escape their Linux VM on Macs via CVE-2026-46331 and a full-host filesystem mount. Accomplish AI researchers showed one prompt granted read-write access to SSH keys and credentials for up to 500,000 users. Anthropic defaulted to cloud execution but issued no local...

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host Mac.

Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover

Linux kernel vulnerability CVE-2026-64600 exposes an estimated 16.4 million RHEL and enterprise Linux systems to silent root takeover via a nine-year-old XFS filesystem race condition. SELinux,

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access - IT Security News

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write…Read more →

No more news articles to load.