Rust Supply-Chain Attack Compromises Popular arrayref Crate
Rust’s security team has disclosed a supply-chain attack involving a malicious arrayref 0.3.10 release and several related crates on crates.io.
Rust’s security team has disclosed a supply-chain attack involving a malicious arrayref 0.3.10 release and several related crates on crates.io.
The SCTPhantom vulnerability, CVE-2026-64564, affects Linux SCTP code and can be exploited for root access and container escape.
CVE-2026-43499, dubbed GhostLock by Nebula Security, exposes a long-standing Linux kernel futex bug that can lead to local root access.
The Guix team urges users to upgrade after vulnerabilities were found in its substitute handling and channel update mechanisms.
Greg Kroah-Hartman says Linux leads CVE counts for the first half of 2026, arguing the numbers reflect responsible reporting, not poor security.
Canonical says Ubuntu kernel updates are available for DirtyClone, a high-severity Linux local privilege escalation flaw tracked as CVE-2026-43503.
AWS, Anthropic, Google, Microsoft/GitHub, Red Hat, NVIDIA, and others are backing a new effort to coordinate OSS security response.
After DirtyFrag, DirtyClone exposes another Linux kernel flaw that may let local attackers gain root access on vulnerable systems.
A new HTTP/2 Bomb DoS attack can exhaust memory on major web servers, causing denial-of-service in seconds.
The flaw affects the boundary between the Linux CIFS client and cifs-utils, allowing local root access on some systems.