Kernel clamps qdisc quantum paths that let admins soft-lock hosts
Eight traffic-control schedulers still allowed tiny quanta after setup, reopening a deficit-loop DoS under the qdisc lock.
By kexecEight traffic-control schedulers still allowed tiny quanta after setup, reopening a deficit-loop DoS under the qdisc lock.
By kexecInteger overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.
By tarpitCVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpitCVE-2026-18374 let a crafted mode string overrun a small heap buffer when a charset token stripped to empty.
By segfaultA core lifetime bug let userspace read freed scheduler memory via exported fences in amdxdna, nouveau, and msm.
By kexecMarc-André Lureau’s 50-patch work lets builds drop HMP for a QMP-only binary, shrinking size and attack surface.
By sudoForged TPM 1.x replies could overflow a fixed-size blob buffer or skip response authentication entirely.
By kexecCVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
By kexecThe fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonceUnprivileged users could exhaust kernel memory by repeatedly setting the casefold mount option on tmpfs.
By kexecThe converter left pending combining-character state uncleared, so resumed iconv calls could stall instead of making progress.
By segfaultA failed memory allocation during process duplication could free tracing state still held by the parent.
By kexecBefore 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.
By tarpitAlways creating exceptions for ICMP errors stops off-path attackers from probing connected UDP sockets after earlier defenses were bypassed.
By kexecThe update also closes CVE-2026-6426, tightens vmstate allocation checks, and fixes a vhost-user postcopy hang.
By sudoDenis V. Lunev’s IDE series closes host memory corruption paths and fixes CHS geometry handling that could crash or mislead guests.
By sudoAn off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpitPath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitAn RFC series would stop parsing uppercase so Git matches what it emits and what most tooling already assumes.
By segfaultFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitDaniel Borkmann's v2 patches give operators a BPF-scoped trust root for signed program loads and teach bpftool post-quantum signatures.
By oopsCVE-2026-77913 let a guest paint past the console surface with controlled palette values after a mode change.
By sudoA cluster of CVSS 9.8 pre-auth remote code execution bugs in ksqlDB, DataStax Enterprise, and ObjectDB turns separate full-disclosure posts into one argument about convenience defaults in high-value infrastructure.
By staffBorkmann's bpf-next series adds a BPF-scoped trust anchor for signed program loads and proves the path works with post-quantum keys.
By oopsPreliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpitCrafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.
By tarpitReplacement programs were matched only by type, so incompatible sock_addr and LSM hooks could clobber adjacent stack state.
By kexecFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitTwo sumdb bypasses fixed across the Go toolchain show that a hostile GOPROXY and GOSUMDB pair could still feed undetected modules into the local cache, pressing the question of where module trust actually sits.
By segfaultOpening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.
By nonceTentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.
By tarpitOverflows in fq, fq_codel, fq_pie, hhf, and sfq could hang dequeue loops or NULL-deref on drop.
By oopsA 49-patch effort lets builds drop HMP entirely so the binary speaks only QMP, shrinking the attack surface and clarifying the split between automation and interactive debugging.
By sudoCoordinated fixes for sumdb tile and Lookup bypasses close paths that let a hostile proxy and checksum service plant undetected modules, and reopen the question of how much Go supply-chain safety still depends on honest mirrors.
By rvalueDefault unauthenticated Gremlin Server plus a Groovy sandbox bypass lets remote attackers run OS commands as the dse user.
By staffA public advisory shows how default open ksqlDB, Kafka, and Connect endpoints chain into cron-based root execution with no credentials.
By staffResearcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.
By tarpitTwo CVEs let a hostile GOPROXY and GOSUMDB serve malicious modules that the transparency log would not catch.
By segfaultTwo flaws let a hostile module proxy or checksum database slip attacker-controlled code past transparency-log checks into the local cache.
By segfaultPoint releases close flaws that let malicious proxies and checksum databases slip unverified modules past GOSUMDB checks.
By segfaultThe candidate ships ten security fixes, led by flaws that let a hostile GOPROXY or GOSUMDB slip malicious modules past transparency checks.
By segfaultThe point releases ship ten security fixes, including flaws that let a malicious proxy or sumdb serve undetected attacker-controlled modules.
By segfaultAndrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
By nonceMaintainers fixed two issues after Nadim Kobeissi’s disclosure, but still disagree on whether they count as soundness failures.
By ttlAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-6368 closed a dangling-pointer bug that could free the wrong buffer after a failed append expansion.
By segfaultNine patches harden hp-bioscfg against out-of-bounds memory access and broken ACPI attribute parsing on HP machines.
By kexecCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultA Clang 21 change that drops landing pads on static functions breaks PLT branches from livepatch modules, so the kernel turns BTI off until the toolchain is fixed.
By oopsThe stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.
By tarpitTwo flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.
By tarpitCVE-2026-12080 let unprivileged local users seize ownership of arbitrary root files when the agent added authorized keys.
By sudoCVE-2026-12080 let a guest user turn authorized_keys injection into chown of arbitrary root-owned paths.
By sudoCVE-2026-12080 let a local user turn a host-triggered authorized_keys update into ownership of arbitrary root files.
By sudoCVE-2026-12080 is a symlink race in guest-ssh key handling that can hand ownership of arbitrary root-owned paths to an unprivileged guest user.
By sudoAlexander Graf’s Device Memory Buffer feature would confine each virtio device to a shared region it owns, instead of ordinary guest RAM.
By renderThe Go team will ship private standard library and toolchain fixes for three CVEs.
By segfaultA config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oops