CISA Adds One Known Exploited Vulnerability to Catalog
This CVE is actively exploited and added to CISA's KEV catalog, requiring immediate patching of affected Linux systems.
CTI Status
Stand:
Letzter Pipeline-Run:
This CVE is actively exploited and added to CISA's KEV catalog, requiring immediate patching of affected Linux systems.
This alert describes a specific active exploit (CopyFail) with root access capabilities, not just a patch reminder, and highlights that many systems remain unpatched.
Public PoC and Metasploit module for a Linux kernel cryptographic API logic flaw enabling local privilege escalation on AMD64/AARCH64 systems.
The BRICKSTORM malware exploits vCenter SSO to establish persistence and evade detection, requiring MFA and real-time alerting on SSO account actions.
This vulnerability allows a non-privileged user to corrupt kernel memory via GPU system calls, which could be exploited in multi-tenant virtualization environments like VMware ESXi to break isolation.
This is a newly disclosed Linux kernel vulnerability with a TOCTOU race condition in the packet socket subsystem that could allow local privilege escalation.
This CVE describes a newly discovered vulnerability in the Linux kernel's SMB client that allows a malicious server to corrupt memory via a crafted DACL, going beyond a simple patch reminder by detailing the specific flaw in ACL validation.
An unauthenticated remote attacker can exhaust the max_connections pool by triggering memory allocation failures via crafted TCP connections, causing permanent denial of service until module reload.
This vulnerability describes a specific slab-out-of-bounds read in io_uring that can be triggered by passing large sqe->len values, potentially leading to memory corruption or information disclosure.
This is a newly disclosed use-after-free vulnerability in the Linux kernel's BPF sockmap subsystem that could allow local privilege escalation or denial of service.
This is a newly disclosed vulnerability with no active exploitation reported yet, but it poses a high risk of kernel panic for systems using AF_ALG crypto operations.