Category: Blog

PinTheft — the sixth vulnerability of the Copy Fail class, providing root rights in Linux

Details have emerged about the sixth vulnerability (1, 2-3, 4, 5) that allows an unprivileged local user to gain root privileges by overwriting data in page caches. The vulnerability has been given the code name PinTheft. A prototype exploit is available. The CVE identifier has not yet been assigned. A patch has been released as of May 5, and on May 11 it was accepted into the netdev branch, but not included in […]

IncidentRelay — an open system for organizing duty rosters and alert routing

The IncidentRelay project has been released, developing an open system for organizing on-call duties, routing notifications, and incident management, which can be run on a self-hosted server. The project is aimed at SRE, DevOps, and infrastructure teams that require a locally deployable alternative to SaaS services for on-call management, applying escalation policies, and responding to incidents. The project code is written in Python and is distributed under the MIT license. […]

A vulnerability ssh-keysign-pwn has been closed in Linux, allowing local users to read root files.

A vulnerability in the Linux kernel, unofficially named ssh-keysign-pwn, has been fixed. This issue allows a local unprivileged user to read files that should only be accessible by the root, including private SSH host keys and, in some scenarios, /etc/shadow. At the time of publication, a separate CVE for the problem had not yet been assigned. Despite the name, it does not refer to a bug in OpenSSH as a network server […]

Release of ForgeZero 1.9.0, a build tool for C and assembler.

The ForgeZero 1.9.0 (fz) release has been published, a console build tool for projects in C, C++, and assembler languages (NASM, GAS, FASM). The tool does not require the creation of a Makefile or other configuration files for basic use. The project code is written in Go and is distributed under the MIT license. ForgeZero identifies the file type and automatically selects the necessary backend. Each code file […]

In Exim 4.99.3, a vulnerability allowing remote code execution when using GnuTLS has been resolved.

The developers of the Exim mail server have released a patch for Exim 4.99.3, addressing a vulnerability in certain configurations of the mail agent. The issue goes by the internal identifier EXIM-Security-2026-05-01.1; it is also referred to in the official notification as CVE-TBD. The vulnerability is classified as Remote Use-After-Free and manifests when parsing the body of a message BDAT while working in TLS with GnuTLS. BDAT is used in the SMTP CHUNKING extension for transmitting the body […]

DirtyDecrypt — another Copy Fail class vulnerability that grants root rights in Linux.

A vulnerability has been discovered in the Linux kernel, similar to the Copy Fail, Dirty Frag, and Fragnesia vulnerabilities, allowing a non-privileged user to gain root privileges by overwriting data in the page cache. The vulnerability has been assigned the code name DirtyDecrypt (also referred to as DirtyCBC). A prototype exploit is available. The CVE identifier is not mentioned in the exploit note, only that researchers identified the issue on May 9, […]

The compromise of a GitHub token belonging to Grafana Labs has led to the leakage of proprietary code.

Grafana Labs, which develops the eponymous open monitoring and data visualization platform, disclosed details about a GitHub access token that fell into the hands of attackers. The attackers used the token to download code for the company's proprietary products from private repositories and attempted to extort money by threatening to disclose the acquired codebase. Grafana Labs representatives refused to pay. According to the company, the attackers did not gain access […]

A new local privilege escalation vulnerability named Fragnesia has been revealed in Linux, allowing a local user to gain root access.

Another local privilege escalation vulnerability has been revealed in the Linux kernel, named Fragnesia with CVE identifier CVE-2026-46300. This issue pertains to the same class of page cache attacks as the recently discussed Copy Fail and Dirty Frag, but it is not a rehash of an old error: it is a distinct defect in the XFRM ESP-in-TCP code. Researcher William Bowling discovered the vulnerability […]

Malware has been found in the Linux builds of the Cemu emulator.

For six days—from May 6 to May 12, 2026—the official Linux builds of the popular Wii U emulator Cemu version 2.6 were compromised. Instead of the clean program, users downloaded malware that stole passwords, SSH keys, GitHub tokens, and credentials for cloud services. The attackers succeeded in replacing binary files in the official project repository on GitHub. […]

ModuleJail for blocking unused Linux kernel modules

Jasper Nuyens, founder of Linux Belgium, who created a layer for using Linux in Tesla's automotive information system, proposed a simple way to reduce the attack surface of the Linux kernel to lower the likelihood of compromise amid a surge in the detection of dangerous vulnerabilities using AI. Many vulnerabilities are typically found in specific kernel modules available for autoloading, but […]

Release of Memtest86+ Memory Testing System 8.10

The release of the Memtest86+ memory testing program 8.10 is now available. The program is not tied to any operating system and can be launched directly from the BIOS/UEFI firmware or bootloader for a comprehensive memory check. In case of issues, the built-in Memtest86+ faulty memory map can be used in the Linux kernel to exclude problematic areas using the memmap option. […]

New Versions of Debian 12.14 and 13.5

The fifth corrective update for Debian 13 has been formed, which includes accumulated package updates and installer fixes. The release includes 144 updates addressing stability issues and 103 updates fixing vulnerabilities. Notable changes in Debian 13.5 include updates to the latest stable versions of packages apache2, openssl, and systemd. The dav4tbsync package has been removed, whose functionality […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster