<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Linux Kernel</title><description>Cybersecurity articles tagged #Linux Kernel on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</guid><description>CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.</description><pubDate>Tue, 01 Sep 2026 02:57:10 GMT</pubDate><category>CVE-2026-53362</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>IPv6</category><category>CISA KEV</category></item><item><title>CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access</title><link>https://runtimerebel.com/blog/cve-2026-53264-linux-traffic-control-bug-escalates-to-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53264-linux-traffic-control-bug-escalates-to-root-access</guid><description>A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.</description><pubDate>Tue, 28 Jul 2026 10:37:19 GMT</pubDate><category>CVE-2026-53264</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>STAR Labs</category><category>CentOS Stream 9</category></item><item><title>Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws</title><link>https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</guid><description>Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 17:42:24 GMT</pubDate><category>DolphinX</category><category>Emerald Sleet</category><category>Winter Vivern</category><category>UNC4841</category><category>Zimbra</category><category>Linux Kernel</category><category>Siemens ROX II</category><category>Industrial Control Systems</category><category>APT</category><category>Ransomware</category><category>LockBit</category></item><item><title>CVE-2026-64600: Local Root via Linux XFS Race Condition — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-64600-local-root-via-linux-xfs-race-condition-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64600-local-root-via-linux-xfs-race-condition-patch-now</guid><description>A nine-year-old race condition in the Linux kernel XFS filesystem, known as RefluXFS, allows local attackers to achieve root privileges via file overwrites.</description><pubDate>Thu, 23 Jul 2026 14:07:00 GMT</pubDate><category>CVE-2026-64600</category><category>Linux Kernel</category><category>XFS</category><category>Privilege Escalation</category><category>RefluXFS</category></item><item><title>CVE-2026-64600: RefluXFS Race Condition Grants Root on RHEL Systems</title><link>https://runtimerebel.com/blog/cve-2026-64600-refluxfs-race-condition-grants-root-on-rhel-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64600-refluxfs-race-condition-grants-root-on-rhel-systems</guid><description>Technical analysis of CVE-2026-64600, a nine-year-old race condition in the Linux XFS driver allowing local privilege escalation on RHEL and Amazon Linux.</description><pubDate>Thu, 23 Jul 2026 10:24:28 GMT</pubDate><category>CVE-2026-64600</category><category>RHEL</category><category>Linux Kernel</category><category>XFS</category><category>Privilege Escalation</category><category>Qualys</category></item><item><title>CVE-2026-43499: GhostLock Linux Kernel Privilege Escalation Analysis</title><link>https://runtimerebel.com/blog/cve-2026-43499-ghostlock-linux-kernel-privilege-escalation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-43499-ghostlock-linux-kernel-privilege-escalation-analysis</guid><description>A 15-year-old Linux kernel flaw, CVE-2026-43499 (GhostLock), enables local root access and container escape across major distributions since 2011.</description><pubDate>Wed, 08 Jul 2026 06:29:58 GMT</pubDate><category>CVE-2026-43499</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Nebula Security</category></item><item><title>Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors</title><link>https://runtimerebel.com/blog/linux-kernel-januscape-flaw-vm-escape-on-kvm-hypervisors</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-kernel-januscape-flaw-vm-escape-on-kvm-hypervisors</guid><description>Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.</description><pubDate>Tue, 07 Jul 2026 11:10:21 GMT</pubDate><category>Linux Kernel</category><category>KVM</category><category>VM Escape</category><category>Januscape</category><category>Virtualization Security</category><category>Intel</category><category>AMD</category></item><item><title>CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android</title><link>https://runtimerebel.com/blog/cve-2026-46242-linux-kernel-bad-epoll-flaw-grants-root-on-servers-android</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46242-linux-kernel-bad-epoll-flaw-grants-root-on-servers-android</guid><description>Critical Linux kernel &apos;Bad Epoll&apos; flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.</description><pubDate>Fri, 03 Jul 2026 21:09:03 GMT</pubDate><category>CVE-2026-46242</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Android</category><category>Bad Epoll</category><category>Local Root</category></item><item><title>DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation</title><link>https://runtimerebel.com/blog/dirtyclone-linux-kernel-privilege-escalation-via-page-cache-manipulation</link><guid isPermaLink="true">https://runtimerebel.com/blog/dirtyclone-linux-kernel-privilege-escalation-via-page-cache-manipulation</guid><description>DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.</description><pubDate>Mon, 29 Jun 2026 13:39:43 GMT</pubDate><category>DirtyClone</category><category>Dirty Frag</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Local Root</category></item><item><title>CVE-2026-46331: Linux pedit COW Exploit Grants Root Access</title><link>https://runtimerebel.com/blog/cve-2026-46331-linux-pedit-cow-exploit-grants-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46331-linux-pedit-cow-exploit-grants-root-access</guid><description>A critical Linux kernel flaw, &apos;pedit COW&apos; (CVE-2026-46331), allows local unprivileged users to gain root access via an out-of-bounds write. Public exploits exist.</description><pubDate>Fri, 26 Jun 2026 16:47:07 GMT</pubDate><category>CVE-2026-46331</category><category>Linux Kernel</category><category>Pedit COW</category><category>Privilege Escalation</category><category>Local Exploit</category></item><item><title>CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access</title><link>https://runtimerebel.com/blog/cve-2026-43503-linux-kernel-dirtyclone-flaw-grants-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-43503-linux-kernel-dirtyclone-flaw-grants-root-access</guid><description>DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.</description><pubDate>Fri, 26 Jun 2026 12:51:06 GMT</pubDate><category>CVE-2026-43503</category><category>DirtyClone</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Dirty Frag</category></item><item><title>CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape</title><link>https://runtimerebel.com/blog/cve-2026-23111-linux-kernel-nf-tables-lpe-and-container-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-23111-linux-kernel-nf-tables-lpe-and-container-escape</guid><description>A one-character use-after-free vulnerability in the Linux kernel nf_tables subsystem allows local root access and container escapes. Patch immediately.</description><pubDate>Mon, 08 Jun 2026 20:57:15 GMT</pubDate><category>CVE-2026-23111</category><category>Linux Kernel</category><category>Nf Tables</category><category>Privilege Escalation</category><category>Container Escape</category></item><item><title>Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626</title><link>https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</guid><description>CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.</description><pubDate>Wed, 03 Jun 2026 17:46:16 GMT</pubDate><category>CVE-2024-36971</category><category>CVE-2024-21626</category><category>CISA KEV</category><category>Android Security</category><category>Linux Kernel</category><category>Container Breakout</category></item><item><title>CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595</title><link>https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</guid><description>CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.</description><pubDate>Tue, 02 Jun 2026 21:13:18 GMT</pubDate><category>CVE-2022-0492</category><category>CVE-2025-48595</category><category>CISA KEV</category><category>Linux Kernel</category><category>Android Security</category></item><item><title>CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems</title><link>https://runtimerebel.com/blog/cve-2024-52336-how-cifswitch-grants-root-access-on-linux-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-52336-how-cifswitch-grants-root-access-on-linux-systems</guid><description>The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.</description><pubDate>Sat, 30 May 2026 16:26:59 GMT</pubDate><category>CVE-2024-52336</category><category>Linux Kernel</category><category>CIFSwitch</category><category>Qualys</category><category>Privilege Escalation</category></item><item><title>CVE-2026-46333: Nine-Year-Old Linux Kernel Privilege Escalation Flaw</title><link>https://runtimerebel.com/blog/cve-2026-46333-nine-year-old-linux-kernel-privilege-escalation-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46333-nine-year-old-linux-kernel-privilege-escalation-flaw</guid><description>A long-standing Linux kernel flaw, CVE-2026-46333, allows local users to achieve root access and disclose sensitive data on major Linux distributions.</description><pubDate>Thu, 21 May 2026 09:15:05 GMT</pubDate><category>CVE-2026-46333</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Local Exploit</category><category>Root Access</category></item><item><title>CVE-2026-31635: DirtyDecrypt Linux Kernel LPE PoC Released</title><link>https://runtimerebel.com/blog/cve-2026-31635-dirtydecrypt-linux-kernel-lpe-poc-released</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-31635-dirtydecrypt-linux-kernel-lpe-poc-released</guid><description>Exploit code for DirtyDecrypt (CVE-2026-31635) has been released, allowing local privilege escalation via vulnerabilities in the Linux kernel crypto API.</description><pubDate>Tue, 19 May 2026 17:03:37 GMT</pubDate><category>CVE-2026-31635</category><category>Linux Kernel</category><category>Dirtydecrypt</category><category>Privilege Escalation</category><category>DirtyCBC</category></item><item><title>DirtyDecrypt: How Attackers Exploit Linux Kernel rxgk for Root Access</title><link>https://runtimerebel.com/blog/dirtydecrypt-how-attackers-exploit-linux-kernel-rxgk-for-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/dirtydecrypt-how-attackers-exploit-linux-kernel-rxgk-for-root-access</guid><description>Learn about DirtyDecrypt, a local privilege escalation vulnerability in the Linux rxgk module. Discover how to detect and mitigate this root access threat.</description><pubDate>Mon, 18 May 2026 09:20:23 GMT</pubDate><category>Linux Kernel</category><category>Rxgk</category><category>Privilege Escalation</category><category>Dirtydecrypt</category><category>Exploit Poc</category></item><item><title>CVE-2026-46300: Fragnesia Flaw Enables Linux Root Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-46300-fragnesia-flaw-enables-linux-root-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46300-fragnesia-flaw-enables-linux-root-privilege-escalation</guid><description>Security researchers identify Fragnesia (CVE-2026-46300), a Linux kernel vulnerability allowing local attackers to gain root access via packet fragmentation.</description><pubDate>Thu, 14 May 2026 20:37:48 GMT</pubDate><category>CVE-2026-46300</category><category>Linux Kernel</category><category>Fragnesia</category><category>Privilege Escalation</category></item><item><title>CVE-2026-46300: Linux Fragnesia Kernel Privilege Escalation Analysis</title><link>https://runtimerebel.com/blog/cve-2026-46300-linux-fragnesia-kernel-privilege-escalation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46300-linux-fragnesia-kernel-privilege-escalation-analysis</guid><description>Critical analysis of the Fragnesia Linux kernel vulnerability (CVE-2026-46300), enabling local root access via IP fragmentation flaws. Includes mitigation steps.</description><pubDate>Thu, 14 May 2026 09:04:30 GMT</pubDate><category>CVE-2026-46300</category><category>Linux Kernel</category><category>Fragnesia</category><category>Privilege Escalation</category></item><item><title>CVE-2026-46300: Fragnesia Linux Kernel LPE Grants Root Access</title><link>https://runtimerebel.com/blog/cve-2026-46300-fragnesia-linux-kernel-lpe-grants-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46300-fragnesia-linux-kernel-lpe-grants-root-access</guid><description>A technical analysis of CVE-2026-46300, a Linux kernel LPE vulnerability dubbed Fragnesia that enables root access via XFRM page cache corruption.</description><pubDate>Thu, 14 May 2026 09:03:13 GMT</pubDate><category>CVE-2026-46300</category><category>Linux Kernel</category><category>Fragnesia</category><category>LPE</category></item><item><title>CVE-2026-31431: Analyzing the Copy.Fail Linux Kernel LPE</title><link>https://runtimerebel.com/blog/cve-2026-31431-analyzing-the-copy-fail-linux-kernel-lpe</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-31431-analyzing-the-copy-fail-linux-kernel-lpe</guid><description>Technical analysis of CVE-2026-31431 (Copy.Fail), a critical Linux kernel vulnerability enabling local privilege escalation via page cache corruption.</description><pubDate>Tue, 12 May 2026 12:50:25 GMT</pubDate><category>CVE-2026-31431</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Theori</category></item><item><title>CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels</title><link>https://runtimerebel.com/blog/cve-2024-1086-dirty-frag-local-privilege-escalation-in-linux-kernels</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-1086-dirty-frag-local-privilege-escalation-in-linux-kernels</guid><description>Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.</description><pubDate>Mon, 11 May 2026 17:02:08 GMT</pubDate><category>CVE-2024-1086</category><category>Dirty Frag</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Netfilter</category></item><item><title>CVE-2026-43284: &apos;Dirty Frag&apos; Linux Vulnerability Exploited — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-43284-dirty-frag-linux-vulnerability-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-43284-dirty-frag-linux-vulnerability-exploited-patch-now</guid><description>Analysis of the &apos;Dirty Frag&apos; (Copy Fail 2) Linux kernel vulnerabilities CVE-2026-43284 and CVE-2026-43500, which enable potential remote code execution.</description><pubDate>Mon, 11 May 2026 09:18:43 GMT</pubDate><category>CVE-2026-43284</category><category>CVE-2026-43500</category><category>Linux Kernel</category><category>Dirty Frag</category><category>Zero-Day</category></item><item><title>&quot;Dirty Frag&quot; Linux Kernel LPE: Unpatched Root Access Risk</title><link>https://runtimerebel.com/blog/dirty-frag-linux-kernel-lpe-unpatched-root-access-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/dirty-frag-linux-kernel-lpe-unpatched-root-access-risk</guid><description>An unpatched Linux kernel vulnerability dubbed Dirty Frag allows local privilege escalation to root, building on the exploitation patterns of CVE-2026-31431.</description><pubDate>Fri, 08 May 2026 08:37:55 GMT</pubDate><category>Linux Kernel</category><category>Dirty Frag</category><category>CVE-2026-31431</category><category>Privilege Escalation</category><category>Root Access</category></item><item><title>CVE-2024-1086: Copy Fail Linux Privilege Escalation Under Exploitation</title><link>https://runtimerebel.com/blog/cve-2024-1086-copy-fail-linux-privilege-escalation-under-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-1086-copy-fail-linux-privilege-escalation-under-exploitation</guid><description>CISA adds CVE-2024-1086 (Copy Fail) to its KEV catalog after Microsoft observes exploitation of this Linux Netfilter privilege escalation vulnerability.</description><pubDate>Mon, 04 May 2026 12:43:34 GMT</pubDate><category>CVE-2024-1086</category><category>Netfilter</category><category>Linux Kernel</category><category>CISA KEV</category><category>Privilege Escalation</category></item><item><title>CVE-2026-31431: Linux Kernel Resource Transfer Vulnerability Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-31431-linux-kernel-resource-transfer-vulnerability-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-31431-linux-kernel-resource-transfer-vulnerability-actively-exploited</guid><description>CISA adds CVE-2026-31431, a Linux Kernel incorrect resource transfer vulnerability, to its KEV catalog due to active exploitation. Prioritize remediation.</description><pubDate>Fri, 01 May 2026 20:24:29 GMT</pubDate><category>CVE-2026-31431</category><category>Linux Kernel</category><category>Resource Transfer</category><category>CISA KEV</category><category>Active Exploitation</category><category>BOD 22 01</category></item><item><title>CrackArmor: Nine Linux AppArmor Flaws Enable Root Escalation</title><link>https://runtimerebel.com/blog/crackarmor-nine-linux-apparmor-flaws-enable-root-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/crackarmor-nine-linux-apparmor-flaws-enable-root-escalation</guid><description>Qualys researchers reveal nine CrackArmor vulnerabilities in the Linux AppArmor module, allowing unprivileged users to bypass container isolation and gain root.</description><pubDate>Fri, 13 Mar 2026 12:19:33 GMT</pubDate><category>Linux Kernel</category><category>AppArmor</category><category>CrackArmor</category><category>Privilege Escalation</category><category>Container Security</category><category>Qualys</category></item></channel></rss>