Tag
CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog
2 CVEsCISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.
Memory Corruption in Linux Kernel I2C Subsystem (CVE-2026-25278)
1 TTP 1 CVEA race condition vulnerability in the Linux kernel I2C subsystem allows local attackers to trigger memory corruption, potentially leading to system crashes or privilege escalation.
Local Privilege Escalation Vulnerability in Windows 11 Secure Kernel Mode
1 TTPA vulnerability in the Secure Kernel Mode of Microsoft Windows 11 allows a local attacker to perform privilege escalation on the affected system.
CVE-2026-57842: Kernel Use-After-Free in NetBSD COMPAT_NETBSD32 Layer
1 TTP 1 CVEA use-after-free and double-free vulnerability in the NetBSD kernel's COMPAT_NETBSD32 layer allows local users to trigger memory corruption or kernel panics via crafted recvmsg system calls.
Remote Code Execution Vulnerability in SAP Extended Passport Processing
2 TTPsA critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.
Local Privilege Escalation in util-linux via Race Condition
1 TTP 1 CVEA vulnerability in util-linux allows unprivileged local users to perform arbitrary bind mounts and change file ownership or permissions by exploiting a race condition in SUID mount(8) handling of fstab entries.
Local Privilege Escalation in Ubuntu Kernel via OverlayFS
1 TTP 2 CVEsPublicly available proof-of-concept exploits targeting CVE-2023-2640 and CVE-2023-32629 allow unprivileged users to gain root access on Ubuntu systems by bypassing permission checks in the overlayfs subsystem.
Detection of Tainted Kernel Module Loading on Linux
1 rule 2 TTPsThe loading of tainted Linux kernel modules may indicate the presence of rootkits or malicious persistence mechanisms used to bypass security controls and intercept system calls.
Kernel Denial of Service Vulnerability in vmxnet3 Driver
1 CVECVE-2026-68299 is a kernel-level denial of service vulnerability in the vmxnet3 virtual network driver caused by a BUG_ON condition when processing malformed Geneve-encapsulated packets.
Microchip WILC1000 Wi-Fi Driver Vulnerability
1 CVECVE-2026-68196 is a memory corruption vulnerability in the Microchip WILC1000 Linux kernel driver caused by insufficient validation of the association response length prior to header subtraction.
Vulnerability in Linux Kernel fscrypt Subsystem
1 CVECVE-2026-68147 addresses a memory management vulnerability in the Linux kernel fscrypt subsystem within the fscrypt_get_devices function, where improper dynamic allocation could lead to memory corruption or exhaustion.
Intel i915 Driver Speculation Barrier Vulnerability
1 CVECVE-2026-68269 describes a missing speculation barrier in the Intel i915 graphics driver that could enable transient execution side-channel attacks by allowing unauthorized speculative memory access.
Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver
1 CVEA potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.
NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver
1 CVEA NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.
Vulnerability in Linux Kernel RADOS Block Device Module
1 CVECVE-2026-68131 identifies a flaw in the Linux kernel rbd module where failure to reset result codes to zero during object map updates may lead to improper status reporting.
Missing Superblock Check in fscrypt find_or_insert_direct_key
1 CVEA vulnerability in the Linux kernel fscrypt subsystem exists due to a missing superblock check in the find_or_insert_direct_key function, potentially impacting filesystem integrity.
Path Resolution Vulnerability in Linux ksmbd Kernel Module
1 CVECVE-2026-68083 describes a path resolution vulnerability in the ksmbd_vfs_kern_path_create function within the Linux kernel ksmbd module that may allow unauthorized file system operations.
Vulnerability in AMD Display Driver for Linux Kernel
1 TTP 1 CVEA memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.
Linux Kernel cfg80211 Wireless Subsystem Vulnerability
1 CVECVE-2026-68412 identifies an error handling flaw in the cfg80211_wext_siwscan function of the Linux kernel wireless subsystem, potentially leading to instability during wireless scanning operations.
Linux Kernel binfmt_misc Privilege Escalation Vulnerability
CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.
KVM Shadow VMCS Memory Handling Vulnerability
1 TTP 1 CVEA vulnerability in the Linux kernel KVM module allows a guest user to trigger memory corruption via improper shadow VMCS handling after a VMCLEAR operation.
Vulnerability in Linux KVM MMU Page Management
1 TTP 1 CVECVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.
Linux Kernel MPLS NULL Pointer Dereference Vulnerability
2 TTPs 1 CVEA NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.
Exploitation of Linux Kernel GSM 0710 TTY Multiplexor Race Condition
1 rule 1 TTP 5 CVEsAn unprivileged local user can escalate privileges to root by exploiting a race condition in the Linux kernel GSM 0710 tty multiplexor (CVE-2023-6546).
Linux Kernel USB Type-C Wcove Driver Buffer Overflow Vulnerability
1 CVEA buffer overflow vulnerability, identified as CVE-2026-63960, exists in the `wcove_read_rx_buffer()` function within the USB Type-C `wcove` driver in the Linux kernel, potentially leading to memory corruption or system instability upon exploitation.
CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem
1 CVEA vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.
CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel
1 CVEA vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.
Linux Kernel fbdev Use-After-Free Vulnerability (CVE-2026-53401)
1 CVEA high-severity use-after-free vulnerability, CVE-2026-53401, has been identified in the Linux kernel's fbdev subsystem affecting omap2 processors, potentially allowing for privilege escalation or denial of service.
Linux Kernel ip_gre Module Vulnerability CVE-2026-63829
1 CVEA vulnerability identified as CVE-2026-63829 affects the `ip_gre` module in the Linux kernel, involving a security fix to ensure that the `changelink` operation properly requires `CAP_NET_ADMIN` capabilities within the device's network namespace, addressing a potential privilege escalation or security bypass scenario.
CVE-2026-63833: Linux Kernel ntfs3 Privilege Escalation Vulnerability
1 CVEThe Microsoft Security Response Center has published information concerning CVE-2026-63833, a privilege escalation vulnerability in the Linux kernel's `ntfs3` module that allows direct userspace writes to reserved `$LX*` extended attributes.
Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation
2 TTPsA local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.
Public Exploit for Linux Kernel Use-After-Free Vulnerability CVE-2026-43499
1 TTP 2 CVEs 6 IOCsA public exploit has been published for CVE-2026-43499, a Use-After-Free vulnerability in the Linux Kernel, demonstrated to achieve KASLR bypass and potential privilege escalation on Android 15 devices running Linux Kernel 5.15.149, significantly elevating risk for unpatched systems.
CVE-2026-53359: KVM x86 Use-After-Free in Shadow Paging
1 CVE 6 IOCsCVE-2026-53359 is a high-severity use-after-free vulnerability affecting the KVM virtualization component on x86 architectures within the Linux kernel, stemming from an unexpected role in shadow paging, which could lead to host system compromise.
CIFSwitch Linux Kernel Local Privilege Escalation Vulnerability
2 rules 1 TTPThe CIFSwitch vulnerability in the Linux kernel allows an unprivileged user to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges by loading a malicious NSS module.
Multiple Vulnerabilities in Linux Kernel Allow Privilege Escalation and Denial of Service
2 rules 3 TTPsA local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges, cause a denial-of-service condition, disclose sensitive information, or perform an unspecified attack.
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
2 rules 1 TTPA new local privilege escalation vulnerability in the Linux kernel's XFRM ESP-in-TCP subsystem, named "Fragnesia," allows unprivileged local attackers to modify read-only file contents in the kernel page cache and achieve root privileges through a deterministic page-cache corruption.
CVE-2026-35420 - Windows Kernel Heap-Based Buffer Overflow Local Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-35420 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authorized local attacker to elevate privileges.
Linux Kernel: Local Privilege Escalation Vulnerabilities
2 rules 1 TTPA local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges or manipulate files.
Ubuntu Linux Kernel Vulnerabilities Addressed in Security Notices
2 rulesUbuntu released security notices between May 4 and 10, 2026, addressing vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10, requiring timely updates.
CVE-2026-31718 ksmbd Use-After-Free Vulnerability
2 rules 1 TTP 1 CVECVE-2026-31718 is a use-after-free vulnerability in the ksmbd kernel module, specifically in the __ksmbd_close_fd() function, which can be triggered via the durable scavenger mechanism, potentially leading to arbitrary code execution.
CVE-2026-31431 'Copy Fail' Linux Kernel Privilege Escalation
2 rules 1 TTP 1 CVEThe 'Copy Fail' vulnerability (CVE-2026-31431) in the Linux kernel allows a local attacker to escalate privileges to root, potentially leading to container breakout and lateral movement in cloud environments.
Multiple Vulnerabilities in Red Hat Linux Kernel
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in the Red Hat Linux kernel allow for arbitrary code execution, privilege escalation, and remote denial of service.
CVE-2026-26179 Windows Kernel Double Free Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-26179 is a double free vulnerability in the Windows Kernel, allowing a locally authenticated attacker to elevate privileges on the system.
Out-of-Cancel Vulnerability Class in Linux Workqueue Cancellation APIs
2 rules 1 TTPThe 'Out-of-Cancel' vulnerability class stems from flaws in Linux workqueue cancellation APIs, potentially leading to exploitable conditions within the kernel.
Untrusted Driver Loaded by Windows Kernel
3 rules 1 TTP 4 IOCsAn untrusted driver loaded by the Windows kernel may indicate an attempt to bypass code signing policies and execute unsigned or self-signed kernel code, potentially leading to defense evasion.
Linux Kernel Instrumentation Discovery via Kprobes and Tracefs
2 rules 1 TTPAdversaries may attempt to discover kernel instrumentation tools like Kprobes and Tracefs on Linux systems to understand the security landscape and potential detection mechanisms.
Linux BPF Program Tampering for Defense Evasion
2 rules 1 TTPAttackers can manipulate or tamper with Berkeley Packet Filter (BPF) programs on Linux systems to evade detection or analysis by security tools that rely on BPF for monitoring and security enforcement.