#linux-kernel
16 stories taggedlinux-kernel.

Microsoft's AI bug-hunters logged 140 Windows CVEs in four months. The queue is now the problem.
FORGE Lab's agentic scanner is finding flaws faster than humans can validate and patch them, and the open-source world is feeling it too.

Linux patches two Spectre-style flaws in the kernel's BPF engine
Kernel maintainers shipped fixes for CVE-2026-64507 and CVE-2026-64508 after researchers showed old branch predictions could leak data from new code.

Ubuntu Still Shipping a Kernel Bug That Lets Containers Break Out to Root
A use-after-free in Linux's Unix socket garbage collector was patched upstream on August 6. Ubuntu's affected LTS releases are still waiting for the fix.

Arm64 KVM flaw lets a guest VM reach into the host's memory
CVE-2026-89775 is a critical Linux kernel bug in the Arm64 virtualization path. A researcher says a guest can read and write host memory when nested virtualization is on.

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them
Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws
The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

Vercel's $1 Million Sandbox Challenge Turned Up Linux Kernel Bugs Nobody Knew About
A two-week public hacking contest aimed at Vercel's AI code sandbox drew 1,285 submissions and uncovered two serious Linux kernel bugs that affect far more than one company.

AI Is Spitting Out Working Exploits for $3.61. Microsoft Says the Old Playbook Is Dead.
A senior Microsoft security chief told Black Hat USA that AI tools have made finding and weaponising software flaws so cheap and fast that the entire industry's approach to defence needs to change, starting now.

Zapscape flaw in Linux KVM lets a rogue guest break out to the host
A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses
MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

Linux Kernel Flaw 'OVSwrap' Hands Local Users Root on Around 800 Builds
A memory corruption bug in Open vSwitch, tracked as CVE-2026-64531, lets ordinary users on default Linux systems become administrator, and a working exploit is already public.

Siemens flags hundreds of Linux flaws in its S7-1500 MFP factory controllers
The firmware inside a widely used industrial controller ships with a Linux subsystem carrying more than 300 unpatched CVEs. Siemens says a fix is coming.

Researcher Publishes Linux Kernel Root Exploit Built With AI Help
CVE-2026-53264, a use-after-free flaw in the kernel's traffic-control code, lets an ordinary Linux user gain full system control on CentOS Stream 9.

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host
Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

Linux act_pedit OOB Write Poisons Page Cache, Hands Local Users Root
CVE-2026-46331 weaponizes a traffic-control bug to overwrite cached binaries. A working PoC dropped within a day of disclosure.