Linux
Curated coverage and analysis in this editorial area.

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available
ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Tengu: The Botnet That Turns Reboot Into a Forensic Trap
Discovered by Nozomi Networks Labs, the Mirai variant Tengu abuses the hardware watchdog timer on embedded Linux devices to force an a…

X.Org Server: Critical Glamor Font Bug Allows Root Privilege Escalation
CVE-2026-55999 in the Glamor Font component of X.Org Server and Xwayland lets any local user with an X connection escalate to root. Pa…

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016
Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8
An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete
CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017
A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

Atomic Arch: 1,500 AUR Packages Hijacked, Targeting Developers and CI
The Atomic Arch operation hijacked over 1,500 Arch User Repository packages via orphaned-package ownership transfers to deliver a Rust…

X.Org Server: GLX Use-After-Free Bug Enables Local Root Escalation on Linux
A use-after-free vulnerability in the CommonMakeCurrent function allows a local attacker to escalate privileges to root. The flaw was…