Category: Blog

SCTPhantom — a vulnerability in the Linux kernel that provides root access and container escape.

A vulnerability (CVE-2026-64564) has been identified in the SCTP protocol implementation provided in the Linux kernel, allowing a local user to gain root privileges on the system. Among other issues, this vulnerability allows root access to the main system when an exploit is launched in an isolated container. A prototype of the exploit has been prepared, and its operation has been demonstrated in the Debian 13, Rocky Linux 9, RHEL 9, and Ubuntu 24.04 distributions with kernels 5.14, 6.6, […]

Update of the ClamAV antivirus package 1.4.6 and 1.5.4 addressing 8 vulnerabilities.

Cisco has released new versions of the free antivirus package ClamAV 1.4.6 and 1.5.4, which fix vulnerabilities, some of which may lead to the execution of attacker's code when checking specially crafted content. CVE-2026-20337 — out-of-bounds write during the processing of specially crafted ZIP archive headers. CVE-2026-20345 — buffer overflow on write and read when processing invalid names […]

Proxmox VE has received official support for 64-bit ARM servers

On August 5, 2026, Proxmox Server Solutions released the first officially supported version of Proxmox Virtual Environment for the ARM64 architecture. Until now, the Proxmox VE virtualization server platform was officially released for x86-64, although there were third-party ports and experimental ways to run it on ARM. The ARM64 variant is implemented not as a separate fork or stripped-down edition. Proxmox VE 9.2 for […]

ClamAV 1.5.4 and 1.4.6

On August 7, corrective releases of the free antivirus package ClamAV 1.5.4 and 1.4.6 were published. The main focus of the new versions is security: in the current branch 1.5, eight CVEs are fixed, six of which are also resolved in the supported branch 1.4. Additionally, an issue in clamd has been addressed that could lead to memory content disclosure of the process. In ClamAV 1.5.4, the following vulnerabilities have been fixed: […]

GCC 16.2

On August 7, GCC 16.2 was released — the second stable release of the GCC 16 branch. The new version is primarily corrective in nature: developers explicitly call it a bug-fix release, containing fixes for regressions found in GCC 16.1 compared to previous releases. A total of 102 known bugs have been fixed since the April GCC 16.1. The fixes affect various components of the compiler and supported architectures; no […]

3 TL;DR: Encountering the third discovered buffer overflow of 2026 (according to F5).

Developer Vyacheslav Serbov, known by the pseudonym slvDev, demonstrated fully local text generation on the ESP32-S3 microcontroller. The language model he created contains 28.9 million parameters and produces about 9.9 tokens per second without relying on a server or other external computing resources. The generated short stories are displayed on a connected OLED screen. The esp32-ai project was tested on the ESP32-S3 N16R8 module, which has […]

Announcement of the Dissolution of the Nixpkgs Core Team

The Nixpkgs Core Team announced its dissolution due to member burnout and an accumulated systemic management crisis within the community. The team coordinated work on the Nixpkgs package repository, used in the NixOS distribution, and also performed tasks such as mediating disputes between maintainers and approving new members. Burnout among members was cited as the main reason for the Core Team's self-dissolution […]

TONTOU — an attack on Intel and AMD CPUs that allows bypassing the protection against Spectre v2 vulnerabilities

Researchers from the Massachusetts Institute of Technology identified a technique called TONTOU (Time-of-Neutralization to Time-of-Use), proposing a new way to exploit class Spectre v2 microarchitectural vulnerabilities. This vulnerability allows for the determination of kernel memory contents when executing an exploit in user space. The code to block this vulnerability was included in the Linux kernel on August 5 and is part of releases 7.1.7, 6.18.43, 6.12.102, 6.6.149, […]

Zapscape — a vulnerability in the KVM hypervisor that allows obtaining root access to the host system

Information has been disclosed about vulnerability (CVE-2026-64561) in the KVM hypervisor, which allows root-level access to the host environment when there is root access in the guest system. This issue can also be used for local privilege escalation if there is access to the device /dev/kvm (for example, on RHEL, such access is granted to all users). A prototype exploit is available for download. The issue has been assigned […]

Ban on accepting AI patches in the drivers/staging section of the Linux kernel

Greg Kroah-Hartman, responsible for maintaining the stable and staging branches of the Linux kernel, announced the cessation of patch acceptance in the drivers/staging section that were prepared using AI tools. It is noted that such automatically generated patches contradict the primary idea of using the drivers/staging subsystem as a training ground for new kernel developers. Code in drivers/staging is initially positioned as problematic (TAINT_CRAP) and is intentionally supported […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster