freenode

← freenode

tarpit

Security & Cryptography desk

Security & Cryptography4d ago

Zapscape: KVM/x86 use-after-free lets guests escape to host

CVE-2026-64561 corrupts host shadow pages from untrusted guests when nested virtualization is exposed, especially on multi-tenant clouds.

Security & Cryptography4d ago

PowerDNS patches high-severity DNS packet resource exhaustion bug

CVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.

Security & Cryptography4d ago

Linux SCTP bug lets local users hit root and escape containers

A use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.

Security & Cryptography5d ago

Bouncy Castle Java 1.85 closes 32 CVEs in core crypto paths

The July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.

Security & Cryptography6d ago

X.Org patches libXfont2 font client flaws that can escalate privileges

Version 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.

Security & Cryptography6d ago

AI cryptanalysis forces HAWK out and hardens the SSH ML-DSA fight

An Anthropic lattice break that halved HAWK’s dimension, and an IETF call for ML-DSA drafts that immediately invoked machine-assisted attacks, have turned AI from a future worry into a live input on which post-quantum algorithms survive standardization.

Security & Cryptography6d ago

Django patches high-severity spatial lookup file-write flaw

Staff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.

Security & Cryptography7d ago

Apache NiFi auth flaw let read-only users override parameter checks

CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.

Security & Cryptography7d ago

NIST leans toward seed-only keys for HQC in draft FIPS 207

The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.

Security & Cryptography9d ago

Lean 4 kernel bug lets metaprograms forge proofs of False

A nested inductive projection flaw accepted axiom-free proofs of 0 = 1 until a late July nightly fix.

Security & Cryptography10d ago

GNOME cuts vuln embargo to 30 days, stops AI-ban forwards

Longtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.

Security & Cryptography11d ago

PHP security releases fix SQL injection and out-of-bounds write

Four branches ship fixes for PostgreSQL injection, Phar crashes, libgd, and a BCMath flaw limited to newer lines.

Security & Cryptography11d ago

Researcher discloses 33 flaws in stagnant cJSON library

Memory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.

Security & Cryptography11d ago

Apache Traffic Server patches 38 flaws, some CVSS 10

Versions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.

Security & Cryptography13d ago

Xen ships batch of fixes for guest escapes spanning grant tables, pygrub, and more

Six advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.

Security & Cryptography14d ago

Resolver stacks buckle together under DNSSEC and transport CVEs

Same-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.

Security & Cryptography18d ago

OpenStack Ironic Python Agent allows root command execution via NTP config

Unsanitized ntp_server values let project managers run arbitrary commands during ramdisk startup.

Security & Cryptography18d ago

Knot Resolver 6.3.0 DoQ overflow allows unauthenticated RCE

A single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.

Security & Cryptography19d ago

IETF TLS list: structural CoI question over Security AD meets moderation warning

A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.

Security & Cryptography19d ago

Linux UDP corking bugs yield local root on kernels since 6.1

Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.

Security & Cryptography19d ago

Linux XFS privilege escalation, BIND and Unbound DNS flaws, and Exim local bugs land together

A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.

Security & Cryptography19d ago

TLS chairs refuse to release the weighting behind a contested ML-KEM consensus call

After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.

Security & Cryptography20d ago

Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door

While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.

Security & Cryptography20d ago

TLS chairs call rough consensus to advance pure ML-KEM over sustained objection

Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.

Security & Cryptography20d ago

libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws

Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.

Security & Cryptography20d ago

snapd 2.76.1 patches LPE and two sandbox flaws

Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.