You are here

LinuxSecurity.com

Subscribe to Feed LinuxSecurity.com
The central voice for Linux and Open Source security news.
Përditësimi: 11 min 18 sek më parë

Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines

Mar, 29/09/2026 - 12:00pd
A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hypervisor stacks and the lifetime of memory-management state used by nested virtual machines.

Managed Detection and Response for Manufacturing: How to Evaluate Providers

Hën, 28/09/2026 - 11:20md
Manufacturing security tends to fail at the seam between information technology and operational technology. 

Why an io_uring Queue Handoff Can Become a Use-After-Free

Pre, 25/09/2026 - 11:00md
A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.

Linux Patch Management For Enterprises: A Complete Guide

Pre, 25/09/2026 - 10:55md
Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own set of software packages, dependencies and updates.

Linux ext4 Patch Blocks an Out-of-Bounds Read From Damaged Metadata

Pre, 25/09/2026 - 10:35md
Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.

USB/IP Teardown Race Can Rearm a Freed Linux Kernel Timer

Pre, 25/09/2026 - 10:15md
A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.

Why an Unlocked ext4 Buffer Can Restore Stale Directory Data

Pre, 25/09/2026 - 10:15md
A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.

A Linux eBPF Trampoline Can Outlive the Program It Calls

Pre, 25/09/2026 - 9:45md
A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.

Faqet