Aggregator
CVE-2025-69233 | Apache CloudStack up to 4.20.2.0/4.22.0.0 toctou
CVE-2025-71301 | Linux Kernel up to 6.18.15/6.19.5 vmap_locked privilege escalation
CVE-2025-71298 | Linux Kernel up to 6.18.15/6.19.5 drm_gem_shmem_madvise_locked privilege escalation
CVE-2025-71296 | Linux Kernel up to 6.18.15/6.19.5 drm_gem_shmem_purge_locked privilege escalation
CVE-2026-41493 | lsegal yard up to 0.9.41 path traversal
Dirty Frag: Unpatched Linux vulnerability delivers root access
A week after Copy Fail, another Linux local privilege escalation vulnerability dubbed “Dirty Frag” has been revealed, along with a PoC exploit. What is Dirty Frag In effect, Dirty Frag refers to two flaws: A xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284, aka Copy Fail 2.0), now patched in the Linux kernel, affects the modules supporting one of the protocols used for IPsec A RxRPC Page-Cache Write vulnerability (CVE number reserved: CVE-2026-43500), currently unpatched, affects the modules … More →
The post Dirty Frag: Unpatched Linux vulnerability delivers root access appeared first on Help Net Security.
CVE-2026-43302 | Linux Kernel up to 6.19.5 debug_dma_map_sg state issue
CVE-2026-43301 | Linux Kernel up to 6.18.15/6.19.5 kernel/kthread.c pm_runtime_put_sync reference count
CVE-2026-43300 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 jdi_panel_dsi_remove null pointer dereference
CVE-2026-43297 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 media rga_buf_init buffer overflow
CVE-2026-43295 | Linux Kernel up to 6.19.5 rapidio rio_free_net allocation of resources
CVE-2026-43293 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 kernel/kthread.c wave5_vpu_timer_callback race condition
CVE-2026-43292 | Linux Kernel up to 6.12.74/6.18.15/6.19.5 purge_vmap_node infinite loop
CVE-2026-43289 | Linux Kernel up to 6.19.5 kernel/kexec_file.c kexec_load_purgatory privilege escalation
CVE-2026-43304 | Linux Kernel up to 6.19.5 libceph process_auth_done buffer overflow
CVE-2026-43303 | Linux Kernel up to 6.18.15/6.19.5 free_pages_prepare use after free
CVE-2026-43299 | Linux Kernel up to 6.19.5 btrfs fs/btrfs/extent-tree.c denial of service
CVE-2026-43296 | Linux Kernel up to 6.19.5 octeontx2-af deadlock
New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server
A newly discovered malware called ZiChatBot has been found quietly using the REST APIs of a legitimate team chat application called Zulip to receive and carry out commands from its operators. This approach is unusual because the malware never communicates with a private server that security tools could flag or block, making it harder to […]
The post New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server appeared first on Cyber Security News.