kernel

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
A race condition vulnerability has been discovered in the Linux Kernel's XFRM subsystem, allowing local attackers to escalate privileges. The flaw stems from improper locking during operations on skb objects, enabling an attacker with existing high-privileged code execution to gain kernel-level code execution. A fix has been released by Linux.

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Nebula Security has revealed GhostLock (CVE-2026-43499), a Linux kernel vulnerability present for 15 years. This flaw allows any logged-in user to achieve root privileges and container escape on unpatched systems, as it is included by default in most Linux distributions.

New Januscape Linux flaw allows VM escape on Intel, AMD devices
A newly identified Linux kernel vulnerability, dubbed Januscape, allows virtual machine escape on Intel and AMD systems. The 16-year-old flaw lets attackers break out of a VM and run code on the host.

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
A recently discovered 16-year-old vulnerability in the Linux kernel's KVM hypervisor, dubbed Januscape, allows attackers to break out of a virtual machine. This flaw affects both Intel and AMD systems and could enable unauthorized code execution on the underlying host system.