Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Linux Kernel

Vulnerabilities in the upstream Linux kernel — local privilege escalations, use-after-frees, race conditions, and the subsystems (epoll, netfilter, io_uring, eBPF) that keep producing them — plus the downstream impact on Android devices and long-lived LTS deployments.

6 CVEs13 articlesRSS
CVEs
CVE-2026-72044
[ HIGH ]EPSS 0.2%patched

ksmbd multichannel session-key stack buffer overflow

ksmbd stack buffer overflow in multichannel session binding: 40 bytes copied into a 16-byte kernel stack buffer. Patched in Linux stable; no CVSS assigned yet.

Linux Kernel / ksmbd (in-kernel SMB3 server, Linux ≥5.15)
CVE-2026-72103
[ MEDIUM ]EPSS 0.2%patched

Linux dm keyring leak causes silent LUKS volume key wipe failure

Refactoring regression in Linux device-mapper causes cryptsetup luksSuspend to silently fail to wipe the LUKS volume key from kernel memory.

Linux Kernel / device-mapper (dm)
CVE-2026-72130
[ HIGH ]EPSS 0.7%patched

Linux kernel NVMe-oF auth heap overflow via short AUTH_RECEIVE buffer

A remote NVMe-oF initiator can supply a short-but-nonzero AUTH_RECEIVE allocation length to trigger a heap write past the allocated buffer on the nvmet target during DH-HMAC-CHAP authentication.

Linux Kernel / Linux kernel (nvmet — NVMe over Fabrics target)
CVE-2026-72135
[ MEDIUM ]EPSS 0.2%patched

Linux kernel TPM character device pread() out-of-bounds read

TPM character devices were registered with seekable file operations, allowing pread() with an arbitrary offset to read past the response buffer in tpm_common_read().

Linux Kernel / Linux kernel (TPM character device — /dev/tpm0, /dev/tpmrm0)
CVE-2026-72157
[ HIGH ]EPSS 0.3%patched

Linux kernel ThunderboltIP frags[] array overflow in tbnet_poll()

The Linux kernel ThunderboltIP driver overflows the skb frags[] array when assembling packets with more than 18 frames, enabling heap corruption by a malicious Thunderbolt peer.

Linux Kernel / Linux kernel (ThunderboltIP / tbnet driver)
CVE-2026-64600
[ HIGH ]CVSS 7.8EPSS 0.5%patched

RefluXFS: Linux Kernel XFS Race Condition Allows Local Root

Nine-year-old XFS race condition in the Linux kernel lets an unprivileged local user gain persistent root access on default RHEL, Fedora Server, and Amazon Linux installs.

Linux Kernel / Linux kernel (XFS filesystem driver)
Articles
~/articles/2026-08-29-openai-agents-cve-2026-53362-linux-kernel-kev
OpenAI Agents Hit Linux Kernel Flaw on Own Systems
● Breaking
linux kernel

OpenAI Agents Hit Linux Kernel Flaw on Own Systems

CISA added CVE-2026-53362, a Linux kernel IPv6 privilege-escalation flaw, to KEV August 27. OpenAI's agents exploited it in-house. Patch deadline: August 30.

read →
~/articles/2026-08-16-august-kernel-drop-enterprise-cves
August Kernel Drop: The Enterprise CVEs Nobody Wrote About
Analysis
linux kernel

August Kernel Drop: The Enterprise CVEs Nobody Wrote About

Thirty-plus kernel CVEs hit NVD on August 15. Three affecting ThunderboltIP, NVMe-oF auth, and TPM matter to enterprise infrastructure and flew under radar.

read →
~/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass
Linux Kernel Patches WiFi Heap Overflow, BPF Bypass
linux kernel

Linux Kernel Patches WiFi Heap Overflow, BPF Bypass

August 15 kernel stable drop fixes a Broadcom WiFi heap overflow triggerable by a rogue AP, a BPF verifier bypass, and 28 other security fixes.

read →
~/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave
Linux CAN Subsystem Gets 14-CVE Race Condition Fix Wave
linux kernel

Linux CAN Subsystem Gets 14-CVE Race Condition Fix Wave

The August 15 Linux stable drop patches 14 CVEs in the CAN broadcast manager and ISO 15765-2 transport: data races and use-after-frees.

read →
~/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103
Linux dm Bug Silently Breaks LUKS Key Wipe
linux kernel

Linux dm Bug Silently Breaks LUKS Key Wipe

Kernel refactoring regression in Linux device-mapper causes cryptsetup luksSuspend to silently fail to wipe the LUKS volume key. Patch is in stable.

read →
~/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044
Linux ksmbd SMB Server: Stack Overflow Fix in Stable
Analysis
linux kernel

Linux ksmbd SMB Server: Stack Overflow Fix in Stable

CVE-2026-72044 patches a ksmbd stack overflow in multichannel session binding. Patched in stable; no CVSS assigned yet, no exploitation confirmed.

read →
~/articles/2026-07-29-linux-cve-2026-53264-ai-exploit-root
AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root
linux kernel

AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root

STAR Labs published a working exploit for CVE-2026-53264 (CVSS 7.8), a use-after-free race in the Linux kernel traffic-control subsystem. AI accelerated discovery and exploit development on CentOS Stream 9.

read →
~/articles/2026-07-28-linux-kernel-tc-cve-2026-53264-lpe
Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)
linux kernel

Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)

STAR Labs published a root exploit for CVE-2026-53264, a use-after-free race in the Linux kernel's traffic-control subsystem. CVSS 7.8. Check your distro advisory.

read →
~/articles/2026-07-23-refluxfs-cve-2026-64600-linux-kernel-lpe-rhel
RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux
linux kernel

RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux

Nine-year-old XFS race condition in the Linux kernel lets an unprivileged local user gain root on default RHEL, Fedora Server, and Amazon Linux.

read →
~/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse
snap-confine LPE Hits Default Ubuntu Desktop Installs
linux kernel

snap-confine LPE Hits Default Ubuntu Desktop Installs

CVE-2026-8933 (CVSS 7.8): snap-confine on Ubuntu Desktop lets any local user escalate to root. Affects 24.04 LTS, 25.10, and 26.04 default installs.

read →
~/articles/2026-07-08-ghostlock-linux-kernel-cve-2026-43499-container-escape
GhostLock: 15-Year Linux Kernel Root/Container Escape
linux kernel

GhostLock: 15-Year Linux Kernel Root/Container Escape

Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

read →
~/articles/2026-07-07-januscape-cve-2026-53359-kvm-guest-host-escape
Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
linux kernel

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape

A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

read →
~/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242
Bad Epoll: Linux Kernel LPE Also Hits Android
linux kernel

Bad Epoll: Linux Kernel LPE Also Hits Android

A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

read →