The Lab · 2026-04-01 13:27:24 · GitHub Issues
A new Linux kernel security update patches two critical vulnerabilities that could allow attackers to seize control of systems or crash them entirely. The flaws, tracked as CVE-2026-23231 and CVE-2025-71238, reside deep within core kernel components, posing a direct threat to server stability and data integrity. The up...
The Lab · 2026-04-03 15:27:05 · GitHub Issues
A critical security vulnerability has been identified in a kernel's cryptographic random number generator (RNG). The system's fallback mechanism, designed to operate when the primary hardware RDRAND instruction is unavailable, is deterministic and predictable, rendering all cryptographic operations insecure. This flaw,...
The Lab · 2026-04-07 18:26:53 · Ars Technica
The sprawling Linux ecosystem, long celebrated for its backward compatibility, is making a definitive cut. Linux kernel maintainers, including Linus Torvalds, are following through on plans to remove support for Intel's 80486 processor. Code commits indicate that Linux kernel version 7.1 will be the first where it beco...
The Lab · 2026-04-11 17:22:22 · GitHub Issues
A critical security vulnerability exists in the Rust standard library implementation for the ThingOS target. The `SYS_GETRANDOM` system call (number `0x7001`) is present in the kernel's dispatch table but is not wired to the `std::sys::random` module. This leaves the operating system's hash map implementation defensele...
The Lab · 2026-04-21 19:23:03 · GitHub Issues
The openSUSE project has restructured its kernel module blacklist, splitting a single, monolithic configuration file into targeted, per-module entries. The key change is the generalization of the `unblacklist` tool, which now works for any blacklisted module, not just filesystems. This directly addresses a significant ...
The Lab · 2026-04-30 08:24:08 · Golem.de
Sicherheitsforscher haben eine seit Jahren im Linux-Kernel schlummernde Schwachstelle aufgedeckt, die Angreifern mit minimalem Aufwand Root-Rechte auf betroffenen Systemen einräumen kann. Der zugehörige Exploit umfasst lediglich 732 Bytes und ist auf GitHub öffentlich verfügbar. Die Lücke soll seit 2017 bestehen – was ...
The Lab · 2026-04-30 22:54:08 · Ars Technica
A critical Linux kernel vulnerability that grants root access to virtually all Linux distributions has been publicly exploited, catching organizations worldwide off guard as security teams scramble to assess exposure across data centers and enterprise infrastructure. The flaw, tracked as CVE-2026-31431 and dubbed "Copy...
The Lab · 2026-05-09 04:01:40 · Mastodon:mastodon.social:#infosec
Security researchers have disclosed a newly identified Linux kernel vulnerability dubbed "Dirty Frag," which allows any local user on an affected system to escalate privileges to root. The flaw, classified as a zero-day, affects most major Linux distributions and has raised significant concern within the information se...
The Lab · 2026-05-09 04:31:45 · r/cybersecurity
A critical Linux kernel vulnerability, internally tracked as "Dirty Frag," has leaked into public view ahead of coordinated disclosure, leaving system administrators with no available patch at the time of exposure. The flaw reportedly enables local privilege escalation, allowing an attacker with limited access to immed...
The Lab · 2026-05-09 07:01:40 · Mastodon:mastodon.social:#cybersecurity
Een nieuwe Linux-kernel kwetsbaarheid is openbaar gemaakt die lokale gebruikers in staat stelt root-rechten te verkrijgen. De kwetsbaarheid, die de naam 'Electric Boogaloo' draagt, vertegenwoordigt een ernstig beveiligingsrisico voor systemen waar meerdere gebruikers toegang tot hebben, zoals gedeelde hosting-omgevinge...
The Lab · 2026-05-09 22:31:46 · Mastodon:mastodon.social:#cybersecurity
A newly surfaced Linux vulnerability identified as CVE-2026-43284, informally referred to as "Dirty Frag," has sparked urgent discussion within cybersecurity circles. The flaw appears to enable privilege escalation to root-level access, prompting security professionals to call for immediate patching across affected sys...
The Lab · 2026-05-12 17:18:27 · Mastodon:mastodon.social:#cybersecurity
Linux maintainers have issued emergency patches for a second severe vulnerability within weeks, raising fresh concerns about the security of one of the world's most widely deployed operating systems. The development signals mounting pressure on system administrators to accelerate patch deployment cycles amid an unusual...
The Lab · 2026-05-13 16:48:30 · Hacker News
A new Linux kernel vulnerability dubbed 'Fragnesia' has been publicly disclosed as a local privilege escalation flaw, security researchers report. The vulnerability, now cataloged under a dedicated CVE identifier, represents the latest addition to a growing list of kernel-level security weaknesses affecting Linux syste...
The Lab · 2026-05-14 04:48:36 · Mastodon:hachyderm.io:#cybersecurity
Uma nova vulnerabilidade de elevação de privilégios locais no kernel Linux foi revelada ao público. Denominada Fragnesia, a falha reside em uma seção separada do código ESP/XFRM e explora um erro de lógica que permite gravações de bytes arbitrários no page cache do kernel de arquivos somente leitura.
A descoberta adic...
The Lab · 2026-05-14 07:48:22 · GitHub Issues
A formal security assessment has been initiated to determine whether the PMSS kernel hardening framework adequately covers the "Fragnesia" privilege-escalation exploit, a kernel vulnerability bearing structural similarities to the known dirty fragmentation (dirtyfrag) class of flaws. The review, triggered by community-...
The Lab · 2026-05-14 08:48:22 · BleepingComputer Echo RSS
A newly identified high-severity vulnerability in the Linux kernel, tracked as CVE-2026-46300 and dubbed Fragnesia, is prompting emergency patching across multiple distributions. The flaw enables privilege escalation, allowing malicious actors who have already gained a foothold on a targeted system to execute code with...