Linux security briefs
14 published alerts for Linux products and services.
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Race Condition Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39682). Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Linux Toolkit Theming vulnerability
Linux Toolkit Theming vulnerability (CVE-2026-76023) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Unspecified Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53362). Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. CISA remediation due date: 2026-08-30. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0995). Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. CISA remediation due date: 2026-09-09. If you need help checking exposure, call (864) 335-9223.
Linux kernel media/dvb-core in dvbdmx_write() vulnerability
Linux kernel media/dvb-core in dvbdmx_write() vulnerability (CVE-2024-24864) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Improper Authentication Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0492). Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-31431). Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. CISA remediation due date: 2026-05-15. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Integer Overflow Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-14634). Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system. CISA remediation due date: 2026-02-16. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22555). Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-38352). Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. CISA remediation due date: 2025-09-25. If you need help checking exposure, call (864) 335-9223.
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Use-After-Free Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1086). Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.