home.social

#kernelsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kernelsecurity, aggregated by home.social.

fetched live
  1. Linux kernel CVEs surged to 440 advisories in just 24 hours, with many flaws found by AI. Most are already patched, so update your kernel promptly.

    #Linux #CVE #KernelSecurity #AI #CyberSecurity

    securityonline.info/linux-kern

  2. Linux kernel CVEs surged to 440 advisories in just 24 hours, with many flaws found by AI. Most are already patched, so update your kernel promptly.

    #Linux #CVE #KernelSecurity #AI #CyberSecurity

    securityonline.info/linux-kern

  3. The new whitepaper wraps up our deep‑dive into a kernel info‑leak bug. It outlines the discovery steps, reproduces the flaw across Linux, BSD and macOS, and quantifies the risk of arbitrary memory disclosure.

    🔑 Key insight: the leak stems from unchecked metadata in the process‑scheduler, allowing a local attacker to read kernel space without privilege escalation.

    #KernelSecurity #InfoLeak #OpenSource #SysAdmin #PrivacyFirst

    🔗 j00ru.vexillium.org/2018/07/wr

    t.me/GlobalWFeed

  4. 🔐 New Linux kernel vulnerability disclosed: CVE-2026-46300 “Fragnesia”
    A new local privilege escalation flaw affecting Linux XFRM/IPsec components has been identified, related to the same vulnerability class as Dirty Frag and Copy Fail.
    We’ve published a brief impact assessment and mitigation guidance for RELIANOID environments.

    relianoid.com/resources/knowle

  5. Gentoo's recent "vulnerabilities" read like a bad soap opera: "Copy Fail," "Dirty Frag," and "Fragnesia"—because nothing says secure like a kernel with amnesia. 😂🔑 Maybe next they'll discover "Oopsie-Daisy" and "Whoops-a-Doodle." 🤷‍♂️🐧
    gentoo.org/news/2026/05/19/cop #Gentoo #Vulnerabilities #SoapOpera #KernelSecurity #TechHumor #LinuxFun #HackerNews #ngated

  6. Gentoo's recent "vulnerabilities" read like a bad soap opera: "Copy Fail," "Dirty Frag," and "Fragnesia"—because nothing says secure like a kernel with amnesia. 😂🔑 Maybe next they'll discover "Oopsie-Daisy" and "Whoops-a-Doodle." 🤷‍♂️🐧
    gentoo.org/news/2026/05/19/cop #Gentoo #Vulnerabilities #SoapOpera #KernelSecurity #TechHumor #LinuxFun #HackerNews #ngated

  7. 🔐 “Copy Fail” and “Dirty Frag” are the latest Linux kernel vulnerabilities putting enterprise infrastructures under pressure.

    Our latest article explores how kernel-level flaws are reshaping security priorities across cloud, Kubernetes, containers, and production Linux environments.


    relianoid.com/blog/linux-kerne

  8. Copy Fail (CVE-2026-31431) is a 4-byte write into the Linux page cache that hands root to any local user in seconds. No race, no ASLR bypass, a 2017 "in-place is faster" optimization in algif_aead, exploitable in 2026 with 732 bytes of Python.
    The boundaries that hold are the ones that don't share a kernel: Firecracker, V8 isolates, gVisor. Shared-kernel containers, you have homework.
    #LinuxSecurity #KernelSecurity #DevOps

    open.substack.com/pub/doriandi

  9. LWN.net is *thrilled* to announce that #AI is now flooding the kernel security list with *riveting* #reports at an unprecedented rate. 🎉 Who needs #quality when you can have *quantity*, right? 👏 Apparently, robots are the new unpaid interns, churning out security tattle faster than humans can hit "unsubscribe." 🤖📈
    lwn.net/Articles/1065620/ #LWNnet #KernelSecurity #Quantity #Over #UnpaidInterns #HackerNews #ngated

  10. LWN.net is *thrilled* to announce that #AI is now flooding the kernel security list with *riveting* #reports at an unprecedented rate. 🎉 Who needs #quality when you can have *quantity*, right? 👏 Apparently, robots are the new unpaid interns, churning out security tattle faster than humans can hit "unsubscribe." 🤖📈
    lwn.net/Articles/1065620/ #LWNnet #KernelSecurity #Quantity #Over #UnpaidInterns #HackerNews #ngated

  11. Got tricked into writing a blog post better explaining the linux kernel's audit system and setting it up in Nix

    It's a moving work of art and you should read it; it will look great on your wedding day:
    https://blog.xvrqt.com/nix-audit.html

    #nix #nixos #linux #kernelsecurity

  12. Got tricked into writing a blog post better explaining the linux kernel's audit system and setting it up in Nix

    It's a moving work of art and you should read it; it will look great on your wedding day:
    https://blog.xvrqt.com/nix-audit.html

    #nix #nixos #linux #kernelsecurity

  13. Threat intelligence analysts are tracking VOID KILLER, an underground tool marketed as a kernel-level AV and EDR process terminator.

    If effective, this approach represents a shift from payload obfuscation toward direct disruption of defensive controls, challenging behavioral and real-time monitoring models.

    This reinforces the importance of layered defenses, telemetry integrity, and kernel-level trust validation.

    Follow TechNadu for objective threat analysis and security research coverage.

    Source: cybersecuritynews.com/hackers-

    #InfoSec #ThreatResearch #EndpointSecurity #KernelSecurity #EDR #CyberRisk

  14. Avances en el curso de #Linux #Hardening! 🚀

    Hoy parametrizamos el núcleo para maximizar su seguridad 🤓

    Grabé algunas opciones para mitigar ataques de DoS, ICMP/Ping Flooding, y Smurf.

    Y para probar los parámetros, nada mejor que armar un lab, realizar los ataques, y ver cómo responde el sistema 🖥️

    Se va poniendo interesante!
    Alguien interesado/a por acá? 🤗

    Los tengo informados!

    #KernelSecurity #DoSMitigation #ICMPFlood #SmurfAttack #NetworkSecurity #CyberSecurity #SysAdmin #DevSecOps

  15. Avances en el curso de #Linux #Hardening! 🚀

    Hoy parametrizamos el núcleo para maximizar su seguridad 🤓

    Grabé algunas opciones para mitigar ataques de DoS, ICMP/Ping Flooding, y Smurf.

    Y para probar los parámetros, nada mejor que armar un lab, realizar los ataques, y ver cómo responde el sistema 🖥️

    Se va poniendo interesante!
    Alguien interesado/a por acá? 🤗

    Los tengo informados!

    #KernelSecurity #DoSMitigation #ICMPFlood #SmurfAttack #NetworkSecurity #CyberSecurity #SysAdmin #DevSecOps

  16. 🥴 Ah, yes, Rust in the kernel, because what we really need is to sprinkle more coding languages into the tech soup 🍲. Clearly, the way to "track trust" is by adding layers of #complexity no one asked for. Kernel security? Just slap some Rust on it, problem solved! 🙄
    lwn.net/Articles/1034603/ #RustInKernel #TechSoup #CodingLanguages #KernelSecurity #HackerNews #ngated

  17. 🥴 Ah, yes, Rust in the kernel, because what we really need is to sprinkle more coding languages into the tech soup 🍲. Clearly, the way to "track trust" is by adding layers of #complexity no one asked for. Kernel security? Just slap some Rust on it, problem solved! 🙄
    lwn.net/Articles/1034603/ #RustInKernel #TechSoup #CodingLanguages #KernelSecurity #HackerNews #ngated

  18. I had the pleasure to contribute to Lukas Maar's #USENIX2024 paper "SLUBStick".
    SLUBStick elevates limited heap vulnerabilities within the #Linux kernel to arbitrary memory read-and-write primitives, leveraging a timing side channel.
    Thanks to Lukas Maar, Martin Unterguggenberger, Mathias Oberhuber and Stefan Mangard for this great opportunity!
    Congratulations to Lukas Maar for driving the paper to acceptance at USENIX Security!

    You can read the full paper here: stefangast.eu/papers/slubstick

    #SLUBStick #Kernel #Linux #KernelSecurity #sidechannel #usenixsecurity #usenixsec

  19. I had the pleasure to contribute to Lukas Maar's #USENIX2024 paper "SLUBStick".
    SLUBStick elevates limited heap vulnerabilities within the #Linux kernel to arbitrary memory read-and-write primitives, leveraging a timing side channel.
    Thanks to Lukas Maar, Martin Unterguggenberger, Mathias Oberhuber and Stefan Mangard for this great opportunity!
    Congratulations to Lukas Maar for driving the paper to acceptance at USENIX Security!

    You can read the full paper here: stefangast.eu/papers/slubstick

    #SLUBStick #Kernel #Linux #KernelSecurity #sidechannel #usenixsecurity #usenixsec