LinuxSecurity.com
Linux Perf Filter Can Expose the Kernel’s Randomized Address
A newly reported Linux perf filter flaw lets an unprivileged user find where the kernel is loaded on a tested x86-64 configuration.
Kategorie: Hacking & Security
Linux Perf Filter Can Expose the Kernel’s Randomized Address
A newly reported Linux perf filter flaw lets an unprivileged user find where the kernel is loaded on a tested x86-64 configuration.
Kategorie: Hacking & Security
Linux File Truncation Patch Targets Data Loss Beyond the Requested Range
A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.
Kategorie: Hacking & Security
Linux Tracing Patch Addresses a Probe Use-After-Free Race
A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.
Kategorie: Hacking & Security
Linux Memory Fault Bug Can Release a Lock Twice on SuperH
A proposed Linux patch addresses a double unlock in the SuperH architecture’s page-fault handling.
Kategorie: Hacking & Security
How to Review Linux Security Boundaries: Three Kernel Examples
A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.
Kategorie: Hacking & Security
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers
Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.
Kategorie: Hacking & Security
crun Blocks Container Images From Choosing Host MicroVM Settings
crun has tightened the boundary between container-controlled configuration and host-controlled microVM behavior.
Kategorie: Hacking & Security
Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch
Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a program.
Kategorie: Hacking & Security
Linux GPU Security Fix Prevents Stale Mappings Across Containers
A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.
Kategorie: Hacking & Security
runc 1.5.2 Shields Containers From a Linux cgroup v2 Memory-Corruption Bug
runc 1.5.2 adds a workaround for a Linux cgroup v2 memory-corruption bug that can make the privileged container runtime crash unpredictably.
Kategorie: Hacking & Security
Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines
A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hypervisor stacks and the lifetime of memory-management state used by nested virtual machines.
Kategorie: Hacking & Security
Managed Detection and Response for Manufacturing: How to Evaluate Providers
Manufacturing security tends to fail at the seam between information technology and operational technology.
Kategorie: Hacking & Security
Why an io_uring Queue Handoff Can Become a Use-After-Free
A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.
Kategorie: Hacking & Security
Linux Patch Management For Enterprises: A Complete Guide
Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own set of software packages, dependencies and updates.
Kategorie: Hacking & Security
Linux ext4 Patch Blocks an Out-of-Bounds Read From Damaged Metadata
Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.
Kategorie: Hacking & Security
USB/IP Teardown Race Can Rearm a Freed Linux Kernel Timer
A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.
Kategorie: Hacking & Security
Why an Unlocked ext4 Buffer Can Restore Stale Directory Data
A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.
Kategorie: Hacking & Security
A Linux eBPF Trampoline Can Outlive the Program It Calls
A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.
Kategorie: Hacking & Security
Linux Cgroup Namespace Race Could Expose a Freed Root Object
A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.
Kategorie: Hacking & Security



