Linux News Articles

Recent news articles refferecing the vendors vulnerabilities.

Linux Kernel Flaw CVE-2026-46333 Exposes Systems to Local Root Attacks via ptrace Race

CVE-2026-46333 exposes a nine-year-old race in the Linux kernel's ptrace exit path. Unprivileged users can steal file descriptors from dying SUID processes to read SSH keys, /etc/shadow, or run commands as root on default systems. Vendors issued patches quickly, but temporary mitigations via Yama sc...

1 week ago

Linux Kernel Flaw Lets Unprivileged Users Access Root-Only Files, Execute Arbitrary Commands as Root - Slashdot

Qualys's Threat Research Unit (TRU) has discovered and published a logic flaw in Linux kernel "that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions." Friday their blog pointed out "The bug...

1 week ago

9-Year-Old Linux bug Found by Researchers, Could Leak Data - IT Security News

Experts have revealed details of a bug in the Linux kernel that stayed unnoticed for nine years. The flaw is tracked as CVE-2026-46333 (CVSS score: 5.5).  Improper bug management  The incident is improper privilege management that could have allowed threat…Read more →

1 week ago

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

Ravie LakshmananMay 21, 2026Linux / Vulnerability

1 week ago

Qualys publishes advisory for Linux kernel flaw CVE-2026-46333 - Cyber Risk Leaders

Qualys Threat Research Unit (TRU) has published an advisory for CVE-2026-46333, a local logic flaw in the Linux kernel’s __ptrace_may_access() function that it says could allow an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of s...

1 week ago

Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys

A newly disclosed Linux kernel flaw lets attackers steal SSH keys and gain root access on affected systems.

1 week ago

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

CVE-2026-46333 is a nine-year Linux kernel improper privilege management flaw introduced in November 2016 with a CVSS score of 5.5.

1 week ago

Nine-Year-Old Kernel Flaw Puts Linux SSH Private Keys at Risk - IT Security News

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, poses a serious risk to SSH private keys and other sensitive credentials. The flaw, present in the kernel since 2016, allows a local attacker to escalate from a basic shell account…Read more →

1 week ago

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege

2 weeks ago

DirtyDecrypt Linux Kernel Vulnerability PoC Exploit Code Released - IT Security News

A working proof-of-concept (PoC) exploit for a high-severity Linux kernel local privilege escalation vulnerability dubbed DirtyDecrypt, also tracked as DirtyCBC, enables local attackers to gain full root access on affected systems. Security analyst Will Dormann technically attributes the flaw to CVE...

2 weeks ago

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

DirtyDecrypt PoC targets CVE-2026-31635 in CONFIG_RXGK Linux systems, enabling local privilege escalation.

2 weeks ago

PoC Released for DirtyDecrypt Linux Kernel Vulnerability

PoC code has been released for DirtyDecrypt, a recently patched Linux kernel vulnerability allowing privilege escalation to root.

2 weeks ago

Linux kernel flaw opens root-only files to unprivileged users

Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs

2 weeks ago

Linux kernel flaw opens root-only files to unprivileged users

Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs

2 weeks ago

Fragnesia Flaw Hands Linux Users Root Access: Third Kernel Bug in Two Weeks, Born From Patch

A newly disclosed Linux kernel flaw nicknamed Fragnesia — tracked as CVE-2026-46300 — lets any unprivileged local user gain root on essentially every major Linux distribution shipped before May 13,

2 weeks ago

Fragnesia Exposes Linux Kernel's Fragile Networking Code Yet Again

Fragnesia (CVE-2026-46300) delivers yet another local root exploit in the Linux kernel, exploiting XFRM ESP-in-TCP logic to write to read-only page cache. Following Dirty Frag by days, it forces rapid patching across distributions while exposing persistent weaknesses in networking and memory managem...

2 weeks ago

Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) - IT Security News

Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affects…Read more →

2 weeks ago

Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) - Help Net Security

Researchers have found and disclosed yet another LPE vulnerability in the Linux kernel: CVE-2026-46300, aka "Fragnesia".

2 weeks ago

New Fragnesia Linux flaw lets attackers gain root privileges

Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root.

2 weeks ago

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

Fragnesia CVE-2026-46300 corrupts Linux page cache via XFRM ESP-in-TCP, enabling local root access on major distros.

2 weeks ago

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

Linux distributions are affected by Fragnesia, a new kernel vulnerability tracked as CVE-2026-46300 that can be exploited for root escalation

2 weeks ago

Linux Kernel's Proposed Killswitch Offers Admins a Runtime Escape Hatch After CopyFail and Dirty Frag

Linux kernel maintainer Sasha Levin proposes a killswitch allowing admins to force vulnerable functions to return fixed values at runtime without executing their code. Prompted by CopyFail (CVE-2026-31431) and Dirty Frag exploits that raced ahead of patches, the feature uses kprobes to create an imm...

3 weeks ago

Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet

This Linux kernel vulnerability has defenders scrambling. Here's which systems are affected - and what you should do ASAP.

3 weeks ago

Dirty Frag Exploit Poised to Blow Up on Enterprise Linux Distros

The privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation.

3 weeks ago

Rushed Patches Follow Broken Embargo on Linux Kernel Vulnerabilities

Two new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributions

3 weeks ago

No more news articles to load.