LinuxSecurity.com

Syndikovat obsah
The central voice for Linux and Open Source security news.
Aktualizace: 28 min 59 sek zpět

Anthropic Launches AI Vulnerability Scanner for Open-Source Projects

9 Říjen, 2026 - 23:05
Open-source maintainers can now apply for free security scans from Anthropic.
Kategorie: Hacking & Security

Go Security Update Fixes 15 Flaws in Servers and Toolchains

9 Říjen, 2026 - 23:00
Go 1.27.2 and 1.26.9 arrived on Oct 8, 2026 with corrections for 15 security flaws.
Kategorie: Hacking & Security

CI/CD Security Flaw in AWS CDK Could Pull Host Files Into Builds

9 Říjen, 2026 - 22:45
A file on a build machine could end up in a cloud deployment bundle because of a flaw disclosed by Amazon Web Services (AWS) on Oct 8, 2026.
Kategorie: Hacking & Security

OpenStack Fixes Zaqar Flaw Exposing Other Tenants’ Queues

8 Říjen, 2026 - 21:15
OpenStack disclosed a Zaqar security flaw on Oct 7, 2026 that lets an authenticated user access another project’s messaging queues.
Kategorie: Hacking & Security

Linux Security Update Fixes 12 X.Org and Xwayland Flaws

8 Říjen, 2026 - 21:00
X.Org has issued fixes for 12 vulnerabilities in its display software.
Kategorie: Hacking & Security

Linux TCP Fast Open Use After Free Leaves a Packet Pointer Behind

8 Říjen, 2026 - 20:45
A bug in Linux’s TCP Fast Open code can leave it reading memory that has already been released.
Kategorie: Hacking & Security

Apache Jackrabbit Fixes Critical WebDAV Session Hijacking Flaw

8 Říjen, 2026 - 20:35
Apache disclosed a critical Apache Jackrabbit session hijacking flaw on Oct 7, 2026.
Kategorie: Hacking & Security

Open Source Security: What 400+ Vulnerability Fixes Could Mean for Linux Users

8 Říjen, 2026 - 02:45
IBM and Red Hat say their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.
Kategorie: Hacking & Security

Defense in Depth Cybersecurity: How to Build Effective Layers

8 Říjen, 2026 - 02:20
Why is the orders application talking to the backup server?
Kategorie: Hacking & Security

vLLM Vulnerability Update Fixes RCE and Server-Crashing Flaws

8 Říjen, 2026 - 02:15
The vLLM project published security advisories on October 6, 2026, identifying version 0.31.0 as the fix for remote code execution (RCE), service crashes, and request-handling flaws.
Kategorie: Hacking & Security

Linux Filesystem Bug Lets Crafted JFS Names Overwrite Memory

8 Říjen, 2026 - 02:00
Deepanshu Kartikey has submitted a patch for a Linux filesystem bug that lets a crafted JFS disk image overwrite kernel memory during a directory listing.
Kategorie: Hacking & Security

Linux NTFS Bug Copies Crafted Index Data Before Checking Its Size

8 Říjen, 2026 - 01:48
Andrey Misiurov has proposed a patch for a Linux NTFS bug that lets a crafted disk image make the kernel read beyond a memory buffer.
Kategorie: Hacking & Security

NFC Security Bug Lets Linux Reuse Freed UART Memory During Shutdown

8 Říjen, 2026 - 00:59
Shubham Antil has submitted a revised two-patch series addressing an NFC security bug in Linux's device-shutdown code.
Kategorie: Hacking & Security

Nftables Interval Bug Can Leave Linux Using a Freed Chain Reference

8 Říjen, 2026 - 00:25
Jérémy Jean has confirmed that a maintainer's proposed patch stops the reproduced failure behind an nftables interval bug.
Kategorie: Hacking & Security

Security Configuration Management: Build a Linux Baseline Your Team Can Maintain

6 Říjen, 2026 - 23:00
“Which settings are we supposed to use?” is a reasonable question from an administrator building a server.
Kategorie: Hacking & Security

Apache Struts Fixes Four Flaws Including Possible Remote Code Execution

6 Říjen, 2026 - 22:45
Apache published four Struts security notices on October 5, 2026. The fixes are in the new 6.12.0 and 7.4.0 releases.
Kategorie: Hacking & Security

SubQuery Supply Chain Attack Targeted Cloud and CI Credentials

6 Říjen, 2026 - 22:45
An npm package used throughout the SubQuery project was poisoned.
Kategorie: Hacking & Security

SELinux NFS Security Update Fixes File Labeling Problems Effectively

6 Říjen, 2026 - 22:15
On an affected host, a second mount of the same NFSv4 share could alter SELinux label handling on the first.
Kategorie: Hacking & Security

Linux Kernel Vulnerability Fixed in Binder Device Creation

6 Říjen, 2026 - 05:10
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Kategorie: Hacking & Security

Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems

6 Říjen, 2026 - 05:00
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
Kategorie: Hacking & Security