Skip to main content
← CVE Tracker

Vendor

Linux

81 articles

Advertisement

HIGH
Vulnerabilities

Linux Kernel Januscape Flaw: VM Escape on KVM Hypervisors

Analysis of the 16-year-old Januscape flaw affecting Linux KVM hypervisors, enabling VM escape and potential host code execution on Intel and AMD systems.

Runtime Rebel Intel
4 min read · Jul 7, 2026
CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw
HIGH
Vulnerabilities

CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw

A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.

Runtime Rebel Intel
5 min read · Jul 6, 2026
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
HIGH
Vulnerabilities

CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android

Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.

Runtime Rebel Intel
4 min read · Jul 3, 2026
HIGH
Vulnerabilities

DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation

DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.

Runtime Rebel Intel
5 min read · Jun 29, 2026
CVE-2026-46331: Linux pedit COW Exploit Grants Root Access
HIGH
Vulnerabilities

CVE-2026-46331: Linux pedit COW Exploit Grants Root Access

A critical Linux kernel flaw, 'pedit COW' (CVE-2026-46331), allows local unprivileged users to gain root access via an out-of-bounds write. Public exploits exist.

Runtime Rebel Intel
4 min read · Jun 26, 2026
INFO
Supply Chain

Linux Foundation's Project Akrites: Bolstering Open Source Security

Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.

Runtime Rebel Intel
4 min read · Jun 26, 2026
CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access
HIGH
Vulnerabilities

CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access

DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.

Runtime Rebel Intel
4 min read · Jun 26, 2026
HIGH
Vulnerabilities

CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide

Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.

Runtime Rebel Intel
4 min read · Jun 24, 2026
MEDIUM
Threat Intel

Linux Process Name Masquerading: Analyzing T1036 Obfuscation

Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.

Runtime Rebel Intel
4 min read · Jun 24, 2026
HIGH
Threat Intel

Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments

Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.

Runtime Rebel Intel
3 min read · Jun 16, 2026
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
HIGH
Supply Chain

400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer

Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.

Runtime Rebel Intel
4 min read · Jun 12, 2026
MEDIUM
Supply Chain

AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers

Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.

Runtime Rebel Intel
4 min read · Jun 12, 2026
CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape
HIGH
Vulnerabilities

CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape

A one-character use-after-free vulnerability in the Linux kernel nf_tables subsystem allows local root access and container escapes. Patch immediately.

Runtime Rebel Intel
4 min read · Jun 8, 2026
HIGH
Vulnerabilities

Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626

CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.

Runtime Rebel Intel
4 min read · Jun 3, 2026
INFO
Threat Intel

Microsoft Coreutils for Windows: Security and Memory Safety Analysis

Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.

Runtime Rebel Intel
3 min read · Jun 3, 2026
HIGH
Vulnerabilities

CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595

CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.

Runtime Rebel Intel
3 min read · Jun 2, 2026
PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap
HIGH
Threat Intel

PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap

An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.

Runtime Rebel Intel
3 min read · Jun 1, 2026
HIGH
Vulnerabilities

CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems

The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.

Runtime Rebel Intel
4 min read · May 30, 2026
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
HIGH
Threat Intel

Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap

Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.

Runtime Rebel Intel
3 min read · May 25, 2026
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
HIGH
Supply Chain

Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware

Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.

Runtime Rebel Intel
3 min read · May 23, 2026
INFO
Threat Intel

Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps

Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.

Runtime Rebel Intel
5 min read · May 21, 2026
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
HIGH
Threat Intel

Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis

Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.

Runtime Rebel Intel
4 min read · May 21, 2026
Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy
HIGH
Threat Intel

Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy

Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.

Runtime Rebel Intel
3 min read · May 21, 2026
INFO
Threat Intel

Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools

Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.

Runtime Rebel Intel
4 min read · May 21, 2026