Linux Tops 2026 CVE Charts, Greg KH Says That’s a Good Thing
Greg Kroah-Hartman says Linux leads CVE counts for the first half of 2026, arguing the numbers reflect responsible reporting, not poor security.
Greg Kroah-Hartman says Linux leads CVE counts for the first half of 2026, arguing the numbers reflect responsible reporting, not poor security.
After DirtyFrag, DirtyClone exposes another Linux kernel flaw that may let local attackers gain root access on vulnerable systems.
Linux kernel 7.1 is out with rewritten NTFS support, Btrfs and exFAT updates, broad driver work, and cleanup of obsolete kernel code.
KernelScript 0.1 introduces an experimental type-safe DSL for writing eBPF, userspace, and kernelspace code from one codebase.
ModuleJail is a new project that blacklists unused Linux kernel modules, helping reduce the attack surface exposed by recent local privilege escalation flaws.
Linus Torvalds has merged new Linux kernel docs clarifying what counts as a security bug and how reports should be triaged.
Fragnesia exposes another Linux kernel page-cache attack path, allowing local root escalation through ESP handling.
Linux kernel developers are reviewing a killswitch proposal that can disable vulnerable functions after recent CVE disclosures.
Dirty Frag follows Copy Fail with a new Linux kernel local privilege escalation risk affecting major distributions and server environments.
Copy Fail (CVE-2026-31431) is a Linux kernel vulnerability that allows local unprivileged users to gain root access on affected systems.