USN-7001-1: Linux kernel critical security update
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.
A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.
A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.
Researchers used AI to examine over 3,700 dream and waking-life reports and identified recurring ways memories, people and places recombine. The findi...
The government has separated digital transformation from procurement and given AI a Cabinet-level role. That fragmentation risks inconsistent strategy...
Beta releases @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 were tampered with to include a module that decrypts a...
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences