» Tag
cve
37 postsLinux Kernel UDP Corking Flaw Enables Local Privilege Escalation
Two Linux kernel CVEs (2026-53362, 2026-53366) expose a heap OOB write via UDP MSG_SPLICE_PAGES corking, enabling local privilege escalation.
AI Uncovers 15-Year-Old Root Vulnerability in Linux Kernel
GhostLock (CVE-2026-43499): AI tool VEGA found a 15-year-old use-after-free root exploit in Linux kernel futex code. What engineers need to patch now.
Januscape: 16-Year-Old UAF in KVM Shadow MMU Crashes Hosts
CVE-2026-53359 (Januscape) is a 16-year-old UAF in KVM's shadow paging code enabling guest-to-host escape; the public PoC reliably panics the host, disrupting all co-located VMs.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comJanuscape: 16-Year-Old Critical Linux KVM Escape, PoC Public
CVE-2026-53359 (Januscape) is a critical Linux KVM guest-to-host escape in the shadow MMU, present since 2010; a public PoC causes host kernel panic.
CVE-2026-64560: Use-After-Free in Linux posix-cpu-timers
CVE-2026-64560 details a Linux kernel posix-cpu-timers use-after-free caused by an exec() race condition, along with its memory-ordering fix.
OVSwrap (CVE-2026-64531): AI-Assisted Discovery of a Linux Kernel LPE
OVSwrap (CVE-2026-64531): an AI-assisted discovery of a Linux kernel Open vSwitch LPE caused by a 16-bit nested action length wraparound.
Cursor Sandbox Escape Shows AI Agents Need Kernel Boundaries
Two critical bugs in Cursor's command sandbox let an attacker-controlled AI agent write outside it and reach RCE. Both are fixed in Cursor 3.0.
pgvector 0.8.7 Update: Security Vulnerability and Its Importance
pgvector 0.8.7 fixes CVE-2026-103484 security vulnerability. Learn about the update and security measures.
Bad Epoll Flaw Grants Root Access on Linux and Android
CVE-2026-46242, dubbed Bad Epoll, lets unprivileged local users gain root via a race-condition bug in the Linux kernel's epoll subsystem; a patch is already out.
Triage Is the Product: AI Agents Audit Ethereum's Protocol Code
Ethereum Foundation's security team runs parallel AI agents against protocol code, surfacing a real CVE—yet the hard part is filtering out false positives.