Linux News Articles
Recent news articles refferecing the vendors vulnerabilities.
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers - SwapUpdate
Swati KhandelwalAug 07, 2026Linux / Vulnerability
2 weeks ago
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers - IT Security News
2026-08-08 11:08 SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address...
2 weeks ago
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host - IT Security News
2026-08-07 21:08 A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and...
2 weeks ago
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host
A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host.
2 weeks ago

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges - IT Security News
2026-08-07 16:08 A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux...
2 weeks ago
CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges
A Linux kernel flaw, tracked as CVE-2026-64561 (Zapscape), allows KVM guests to escape to the Linux host with root privileges.
2 weeks ago

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Linux SCTP flaw CVE-2026-64564 dates back to 2008 and Tencent researchers say it could escape containers and gain host root.
2 weeks ago
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Swati KhandelwalAug 06, 2026Virtualization Security / Linux
2 weeks ago
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape could let guest root escape nested KVM and execute code on the Linux host through a shadow-MMU use-after-free; no in-wild exploitation is cla
2 weeks ago
New Release: Tails 7.10.1 | Tor Project
This release is an emergency release to fix critical security vulnerabilities in the Linux kernel and the expat XML library. Changes and updates Update the Linux kernel to 6.12.100, which fixes...
2 weeks ago
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular Linux distributions.
2 weeks ago

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
CVE-2026-64531 lets local users exploit Open vSwitch kernel memory corruption to gain root, with a public PoC covering roughly 800 builds.
2 weeks ago
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
4 weeks ago
SharedRoot Exposes Claude Cowork: How One Kernel Flaw Let AI Agents Roam Free on Macs
SharedRoot let Claude Cowork agents escape their Linux VM on Macs via CVE-2026-46331 and a full-host filesystem mount. Accomplish AI researchers showed one prompt granted read-write access to SSH keys and credentials for up to 500,000 users. Anthropic defaulted to cloud execution but issued no local...
4 weeks ago
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
SharedRoot exploits CVE-2026-46331 in local Claude Cowork sessions to gain guest root and read or write files across the host Mac.
1 month ago
Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover
Linux kernel vulnerability CVE-2026-64600 exposes an estimated 16.4 million RHEL and enterprise Linux systems to silent root takeover via a nine-year-old XFS filesystem race condition. SELinux,
1 month ago
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
1 month ago
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
CVE-2026-64600 lets local users overwrite root-owned files on reflink-enabled XFS systems, preserving metadata and persistent root access after reboot
1 month ago
Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access - IT Security News
A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write…Read more →
1 month ago
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
A new Linux vulnerability dubbed "RefluXFS" — a race condition in the Linux kernel's XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in Enforcing mode.
1 month ago

Rocky Linux Ships Januscape Patch: Two KVM CVEs Required for Full Protection
Rocky Linux Januscape patch (RLSA-2026:36957) gives administrators their first vendor-supported fix for the 16-year-old KVM guest-to-host escape, but both CVE-2026-53359 and the companion
GhostLock's 15-Year Shadow: How One Kernel Flaw Powered a One-Click Android Root
Nebula Security's IonStack chains a Firefox JIT bug with GhostLock (CVE-2026-43499), a 15-year-old Linux kernel stack UAF, to root Android 17 with one click. The flaw affected every distribution until April 2026. Patching remains urgent as supply chain risks mount.
Linux KVM Guest-to-Host Escape Hits Both Intel and AMD: Two CVEs Required
Linux KVM vulnerability CVE-2026-53359, named Januscape, lets a cloud tenant’s virtual machine crash the host or take root on it — exposing 16 years of undetected kernel code in the shadow MMU.
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel vulnerability that allows attackers to gain root privileges.
Public Exploit Turns 15-Year Linux Kernel Flaw Into 5-Second Root Attack
Linux kernel privilege escalation vulnerability GhostLock (CVE-2026-43499) has lurked undetected in every major distribution since 2011. A public exploit now lets any logged-in user gain full root in