» Tag
privilege-escalation
10 postsRefluXFS: XFS reflink race lets Linux users escalate to root (CVE-2026-64600)
Qualys details RefluXFS (CVE-2026-64600), an XFS reflink race enabling local privilege escalation to root on default RHEL, Rocky, and Fedora Server installs.
Four Long-Standing Linux Kernel Local Root Flaws Disclosed
Four decade-old Linux kernel local root flaws — DirtyAH6, TUNderflow, PPPoEject, DiagSpill — are now public, with PoCs and stable-tree fixes released.
AI Agent XBOW Finds and Exploits a Linux Kernel Bug (CVE-2026-72018)
XBOW's AI security agent found and exploited a Linux kernel bug (CVE-2026-72018) via SMC-D, achieving full root privilege escalation.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comCVE-2025-39964: The $113,337 AF_ALG Linux Privilege Escalation Bug
CVE-2025-39964: a race condition in Linux AF_ALG enables root privilege escalation and Docker container escape, earning $113,337 via kernelCTF.
Linux Kernel UDP Corking Flaw Enables Local Privilege Escalation
Two Linux kernel CVEs (2026-53362, 2026-53366) expose a heap OOB write via UDP MSG_SPLICE_PAGES corking, enabling local privilege escalation.
MongoDB BSON Symbol Type Bypasses Authorization Check (CVE-2026-18690)
MongoDB CVE-2026-18690: a BSON symbol-typed collection name bypasses authorization checks, letting limited users reach protected system collections.
AWS EKS Privilege Escalation: Pod Metadata to Cluster-Admin
How a compromised EKS pod can escalate to cluster-admin via EC2 metadata and node tokens, plus a persistent aws-auth backdoor technique.
OVSwrap (CVE-2026-64531): AI-Assisted Discovery of a Linux Kernel LPE
OVSwrap (CVE-2026-64531): an AI-assisted discovery of a Linux kernel Open vSwitch LPE caused by a 16-bit nested action length wraparound.
RustyTux: Linux Kernel Local Privilege Escalation Exploit
RustyTux exploits a Linux kernel race condition for local privilege escalation.
Windows Privilege Abuse: The Shortcut to SYSTEM Access
Exploring how Windows privileges like SeImpersonatePrivilege are weaponized into SYSTEM access via Potato attacks, and why architectural defenses matter.