Linux News Articles

Recent news articles refferecing the vendors vulnerabilities.

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.

3 days ago

SharedRoot Exposes Claude Cowork: How One Kernel Flaw Let AI Agents Roam Free on Macs

SharedRoot let Claude Cowork agents escape their Linux VM on Macs via CVE-2026-46331 and a full-host filesystem mount. Accomplish AI researchers showed one prompt granted read-write access to SSH keys and credentials for up to 500,000 users. Anthropic defaulted to cloud execution but issued no local...

4 days ago

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host Mac.

1 week ago

Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover

Linux kernel vulnerability CVE-2026-64600 exposes an estimated 16.4 million RHEL and enterprise Linux systems to silent root takeover via a nine-year-old XFS filesystem race condition. SELinux,

1 week ago

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.

1 week ago

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot

1 week ago

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access - IT Security News

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write…Read more →

1 week ago

RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access

A new Linux vulnerability dubbed "RefluXFS" — a race condition in the Linux kernel's XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode.

1 week ago

Rocky Linux Ships Januscape Patch: Two KVM CVEs Required for Full Protection

Rocky Linux Januscape patch (RLSA-2026:36957) gives administrators their first vendor-supported fix for the 16-year-old KVM guest-to-host escape, but both CVE-2026-53359 and the companion

3 weeks ago

GhostLock's 15-Year Shadow: How One Kernel Flaw Powered a One-Click Android Root

Nebula Security's IonStack chains a Firefox JIT bug with GhostLock (CVE-2026-43499), a 15-year-old Linux kernel stack UAF, to root Android 17 with one click. The flaw affected every distribution until April 2026. Patching remains urgent as supply chain risks mount.

3 weeks ago

Linux KVM Guest-to-Host Escape Hits Both Intel and AMD: Two CVEs Required

Linux KVM vulnerability CVE-2026-53359, named Januscape, lets a cloud tenant’s virtual machine crash the host or take root on it — exposing 16 years of undetected kernel code in the shadow MMU.

3 weeks ago

15-Year-Old Linux Vulnerability ā€˜GhostLock’ Earns Researchers $92k From Google

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel vulnerability that allows attackers to gain root privileges.

3 weeks ago

Public Exploit Turns 15-Year Linux Kernel Flaw Into 5-Second Root Attack

Linux kernel privilege escalation vulnerability GhostLock (CVE-2026-43499) has lurked undetected in every major distribution since 2011. A public exploit now lets any logged-in user gain full root in

3 weeks ago

15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions - IT Security News

A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed ā€œGhostLock,ā€ has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logic…Read more →

3 weeks ago

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Researchers atĀ Nebula SecurityĀ have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take fullĀ rootĀ control

3 weeks ago

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

GhostLock (CVE-2026-43499), a 15-year-old use-after-free in Linux's futex code, gives any local user root.

3 weeks ago

Januscape Linux VM Escape Flaw Affects Intel and AMD SystemsĀ  | eSecurity Planet

Januscape (CVE-2026-53359) enables guest-to-host VM escape in Linux KVM on Intel and AMD systems.

3 weeks ago

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host.

3 weeks ago

16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory - IT Security News

A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed ā€œJanuscape,ā€ exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained…...

3 weeks ago

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A 16-year-old Linux KVM flaw (CVE-2026-53359) dubbed Januscape can allow attackers to escape virtual machines and execute code on Intel and AMD host systems.

4 weeks ago

Proof-of-Concept Exploit Released for Linux ā€˜Bad Epoll’ Root Access Vulnerability

Exploit for "Bad Epoll" Linux kernel vulnerability (CVE-2026-46242) can lead to root access on desktops, servers, and Android phones.

4 weeks ago

New Bad Epoll Bug Impacts Android and Linux, Allows Root Access - IT Security News

A recently found Linux kernel vulnerability called ā€˜Bad Epoll’ (CVE-2026-46242) allows an ordinary person without any special privilege to take complete command of a device as a root. This has impacted Linux systems, Android, and servers, and a patch is…Read more →

4 weeks ago

Bad Epoll: Kernel Race Bug Beats AI Auditing, Hits 99% Root Exploit Rate

Linux kernel privilege escalation vulnerability Bad Epoll (CVE-2026-46242) lets any unprivileged local user become root on servers, desktops, and Android devices running kernel v6.4 or later. No

1 month ago

Bad Epoll Vulnerability Lets Any Linux User Get Root

The Bad Epoll vulnerability (CVE-2026-46242) lets an unprivileged Linux or Android user gain root. Here is how the exploit works and what to patch now.

1 month ago

New ā€œBad Epollā€ 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices - IT Security News

A newly disclosed Linux kernel flaw dubbed ā€œBad Epollā€ (CVE-2026-46242) allows an unprivileged local user to escalate to root on Linux servers, desktops, and Android devices by exploiting a race condition and a use-after-free (UAF) in the kernel’s epoll subsystem.…Read more →

1 month ago

No more news articles to load.