Linux News Articles
Recent news articles refferecing the vendors vulnerabilities.
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
3 days ago
SharedRoot Exposes Claude Cowork: How One Kernel Flaw Let AI Agents Roam Free on Macs
SharedRoot let Claude Cowork agents escape their Linux VM on Macs via CVE-2026-46331 and a full-host filesystem mount. Accomplish AI researchers showed one prompt granted read-write access to SSH keys and credentials for up to 500,000 users. Anthropic defaulted to cloud execution but issued no local...
4 days ago
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host Mac.
1 week ago
Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover
Linux kernel vulnerability CVE-2026-64600 exposes an estimated 16.4 million RHEL and enterprise Linux systems to silent root takeover via a nine-year-old XFS filesystem race condition. SELinux,
1 week ago
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
1 week ago
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot
1 week ago
Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access - IT Security News
A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-writeā¦Read more ā
1 week ago
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
A new Linux vulnerability dubbed "RefluXFS" ā a race condition in the Linux kernel's XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode.
1 week ago

Rocky Linux Ships Januscape Patch: Two KVM CVEs Required for Full Protection
Rocky Linux Januscape patch (RLSA-2026:36957) gives administrators their first vendor-supported fix for the 16-year-old KVM guest-to-host escape, but both CVE-2026-53359 and the companion
3 weeks ago
GhostLock's 15-Year Shadow: How One Kernel Flaw Powered a One-Click Android Root
Nebula Security's IonStack chains a Firefox JIT bug with GhostLock (CVE-2026-43499), a 15-year-old Linux kernel stack UAF, to root Android 17 with one click. The flaw affected every distribution until April 2026. Patching remains urgent as supply chain risks mount.
3 weeks ago
Linux KVM Guest-to-Host Escape Hits Both Intel and AMD: Two CVEs Required
Linux KVM vulnerability CVE-2026-53359, named Januscape, lets a cloud tenantās virtual machine crash the host or take root on it ā exposing 16 years of undetected kernel code in the shadow MMU.
3 weeks ago
15-Year-Old Linux Vulnerability āGhostLockā Earns Researchers $92k From Google
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel vulnerability that allows attackers to gain root privileges.
3 weeks ago
Public Exploit Turns 15-Year Linux Kernel Flaw Into 5-Second Root Attack
Linux kernel privilege escalation vulnerability GhostLock (CVE-2026-43499) has lurked undetected in every major distribution since 2011. A public exploit now lets any logged-in user gain full root in
3 weeks ago
15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions - IT Security News
A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed āGhostLock,ā has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logicā¦Read more ā
3 weeks ago
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers atĀ Nebula SecurityĀ have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take fullĀ rootĀ control
3 weeks ago
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
GhostLock (CVE-2026-43499), a 15-year-old use-after-free in Linux's futex code, gives any local user root.
3 weeks ago
Januscape Linux VM Escape Flaw Affects Intel and AMD SystemsĀ | eSecurity Planet
Januscape (CVE-2026-53359) enables guest-to-host VM escape in Linux KVM on Intel and AMD systems.
3 weeks ago
New Januscape Linux flaw allows VM escape on Intel, AMD devices
A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host.
3 weeks ago
16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory - IT Security News
A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed āJanuscape,ā exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remainedā¦...
3 weeks ago
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
A 16-year-old Linux KVM flaw (CVE-2026-53359) dubbed Januscape can allow attackers to escape virtual machines and execute code on Intel and AMD host systems.
4 weeks ago
Proof-of-Concept Exploit Released for Linux āBad Epollā Root Access Vulnerability
Exploit for "Bad Epoll" Linux kernel vulnerability (CVE-2026-46242) can lead to root access on desktops, servers, and Android phones.
4 weeks ago
New Bad Epoll Bug Impacts Android and Linux, Allows Root Access - IT Security News
A recently found Linux kernel vulnerability called āBad Epollā (CVE-2026-46242) allows an ordinary person without any special privilege to take complete command of a device as a root. This has impacted Linux systems, Android, and servers, and a patch isā¦Read more ā
4 weeks ago
Bad Epoll: Kernel Race Bug Beats AI Auditing, Hits 99% Root Exploit Rate
Linux kernel privilege escalation vulnerability Bad Epoll (CVE-2026-46242) lets any unprivileged local user become root on servers, desktops, and Android devices running kernel v6.4 or later. No
1 month ago
Bad Epoll Vulnerability Lets Any Linux User Get Root
The Bad Epoll vulnerability (CVE-2026-46242) lets an unprivileged Linux or Android user gain root. Here is how the exploit works and what to patch now.
1 month ago
New āBad Epollā 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices - IT Security News
A newly disclosed Linux kernel flaw dubbed āBad Epollā (CVE-2026-46242) allows an unprivileged local user to escalate to root on Linux servers, desktops, and Android devices by exploiting a race condition and a use-after-free (UAF) in the kernelās epoll subsystem.ā¦Read more ā
1 month ago