Google has increased the rewards for identifying vulnerabilities in the Linux and Kubernetes kernels.

Google has announced the expansion of its initiative to provide monetary rewards for identifying security issues in the Linux kernel, the Kubernetes container orchestration platform, the GKE (Google Kubernetes Engine), and the competition environment for vulnerability discovery kCTF (Kubernetes Capture the Flag).

The reward program has introduced additional bonus payments of $20,000 for 0-day vulnerabilities, for exploits that do not require enabling user namespaces, and for demonstrating new exploitation methods. The base payment for demonstrating a working exploit in kCTF is $31,337 (the base payment is made to the participant who first demonstrates a working exploit, but bonus payments can also apply to subsequent exploits for the same vulnerability).

In total, considering bonuses, the maximum reward for a 1-day exploit (issues identified based on analysis of bug fixes in the codebase that are not explicitly marked as vulnerabilities) can reach up to $71,337 (was $31,337), while for a 0-day (issues for which there is no patch yet) it can be $91,337 (was $50,337). The payment program will be in effect until December 31, 2022.

It is noted that in the past three months, Google processed 9 reports containing information about vulnerabilities, for which $175,000 was paid. Participating researchers prepared five exploits for 0-day vulnerabilities and two for 1-day vulnerabilities. Information has been publicly disclosed for three already patched vulnerabilities in the Linux kernel (CVE-2021-4154 in cgroup-v1, CVE-2021-22600 in af_packet, and CVE-2022-0185 in VFS) (these issues had previously been identified through Syzkaller, and fixes were added for two of the issues in the kernel).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster