A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as ...
A Linux kernel race condition disclosed July 3 lets any unprivileged local user become root on desktops, servers, and Android devices running kernel v6.4 or later — and the researcher who found it ...
A monthly overview of things you need to know as an architect or aspiring architect. Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with ...
Phoronix Linux 7.2's merge window closed out a cleanup campaign on Friday that most kernel developers had stopped expecting to see end: the complete removal of strncpy(), a C string-copy function that ...
There’s a line in a [Weird Al] (no relation) song that says, “I upgrade my system at least twice a day…” I know how that is. I primarily use a rolling distro, OpenSuse Tumbleweed, and if I’m having a ...
Most Linux users have no idea their systems load thousands of kernel modules by default, even though only a small fraction are actually needed during normal operation. The rest sit quietly in the ...
After three critical Linux kernel vulnerabilities, Copy Fail, Dirty Frag, and Fragnesia, were reported in just two weeks, the Linux community began looking for ways to address the problem. One ...
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. Named ...
Experts say until the distros release patches, CSOs have to beware of unauthorized privilege escalation; Kubernetes container escape is also a risk. CSOs must ensure their Linux-based systems block ...
Linux kernel 7.0 is out, but the new version number should not be mistaken for a major turning point in the kernel’s development. As Linus Torvalds has done before, the move from 6.19 to 7.0 is ...
VoidLink is a sophisticated, cloud-native Linux malware framework that leverages a rare hybrid architecture to maintain deep stealth on compromised systems. First documented by Check Point Research in ...