#linux-kernel
12 stories taggedlinux-kernel.

AI Is Spitting Out Working Exploits for $3.61. Microsoft Says the Old Playbook Is Dead.
A senior Microsoft security chief told Black Hat USA that AI tools have made finding and weaponising software flaws so cheap and fast that the entire industry's approach to defence needs to change, starting now.

Zapscape flaw in Linux KVM lets a rogue guest break out to the host
A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses
MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

Linux Kernel Flaw 'OVSwrap' Hands Local Users Root on Around 800 Builds
A memory corruption bug in Open vSwitch, tracked as CVE-2026-64531, lets ordinary users on default Linux systems become administrator, and a working exploit is already public.

Siemens flags hundreds of Linux flaws in its S7-1500 MFP factory controllers
The firmware inside a widely used industrial controller ships with a Linux subsystem carrying more than 300 unpatched CVEs. Siemens says a fix is coming.

Researcher Publishes Linux Kernel Root Exploit Built With AI Help
CVE-2026-53264, a use-after-free flaw in the kernel's traffic-control code, lets an ordinary Linux user gain full system control on CentOS Stream 9.

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD
Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host
Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

Linux act_pedit OOB Write Poisons Page Cache, Hands Local Users Root
CVE-2026-46331 weaponizes a traffic-control bug to overwrite cached binaries. Working PoC dropped a day after disclosure.

DirtyClone: New DirtyFrag-Family Kernel Bug Hands Local Users Root
CVE-2026-43503 (CVSS 8.8) corrupts file-backed memory through a cloned skb. A working PoC is now public.

Public Exploit Drops for nf_tables UAF: CVE-2026-23111 Gives Local Root, Container Escape
Exodus Intelligence published a full walkthrough four months after the upstream patch. The kernel bug is a one-liner. The exploit is not.

CIFSwitch: Linux Kernel Key-Handling Bug Hands Out Root Across Major Distros
A local privilege escalation in the kernel's CIFS authentication path lets an unprivileged user forge key descriptions and walk away with root.