ModuleJail Blocks Unused Linux Kernel Modules to Limit Attack Surface
ModuleJail is a new project that blacklists unused Linux kernel modules, helping reduce the attack surface exposed by recent local privilege escalation flaws.
ModuleJail is a new project that blacklists unused Linux kernel modules, helping reduce the attack surface exposed by recent local privilege escalation flaws.
Fragnesia exposes another Linux kernel page-cache attack path, allowing local root escalation through ESP handling.
Linux kernel developers are reviewing a killswitch proposal that can disable vulnerable functions after recent CVE disclosures.
Dirty Frag follows Copy Fail with a new Linux kernel local privilege escalation risk affecting major distributions and server environments.
Copy Fail (CVE-2026-31431) is a Linux kernel vulnerability that allows local unprivileged users to gain root access on affected systems.
A new vulnerability, CVE-2024-6409, in OpenSSH versions 8.7 and 8.8 risks remote code execution; Fedora 36/37 and RHEL 9 are affected.
Critical CVE-2024-32462 exposed in Flatpak, allowing unauthorized code execution. Update urgently to fixed versions 1.14.6 and above.
PuTTY's security flaw (CVE2024-31497) in ECDSA P521 keys risks private data exposure. Urgent update is needed.
A week after finding a malicious backdoor, GitHub has safely restored access to the XZ Utils repo for developers worldwide.
Canonical rebuilds Ubuntu 24.04 LTS packages for Noble Numbat Beta, ensuring safety from CVE-2024-3094 threat.