Skip to content

project

Linux kernel

The open-source Unix-like kernel underlying Linux-based operating systems, from Android to servers and embedded devices, maintained via kernel.org.

Known aliases

  • arm64 Linux
  • kernel.org
  • Linux
  • Linux 6.18.7
  • Linux 7.2
  • Linux 7.3
  • Linux kernel 7.2
  • mainline
  • mainline kernel
  • mainline Linux
  • the kernel

Relationships

No evidence-backed relationships are recorded.

Current stories

build5 publishers

Google halts product reports to its open-source bug bounty after a flood of invalid AI submissions

Google stopped taking product vulnerability reports for its open-source bug bounty on October 1 after a flood of invalid AI-generated submissions. Any team that takes outside security reports faces the same imbalance, with reports now cheap to write and as costly as ever to check.

Perspective Coverage

5 publishers
Builder
Builder 37%
Operator
Operator 51%
Investor
Investor 12%

Reality

Evidence78
Adoption55
Hype gap+12
Incentives
Insufficient
Confidence74
security3 publishers

Chipmakers leave the Branch Target Reuse fix to each JIT engine that rewrites code

Intel, AMD and Arm say their IBPB barrier can block Branch Target Reuse, a Spectre v2 variant hitting all three, if JIT software calls it. Each kernel, browser and runtime that rewrites JIT code now has to add that call itself.

Perspective Coverage

3 publishers
Builder
Builder 42%
Operator
Operator 51%
Investor
Investor 7%

Reality

Evidence72
Adoption40
Hype gap+15
Incentives30
Confidence70
security1 publisher

Graz researchers read other users' browsing and keystroke timing through OS file-change alerts

Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60
build1 publisher

systemd's mstack mounts a single-layer stack writable by default

systemd's mstack mounted a single-layer directory writable by default in a dev.to test, and one written line overwrote a read-only file with exit code 0. Anyone shipping a one-layer stack in a unit file has to prove read-only with a test write.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence35
security4 publishers

CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.

Perspective Coverage

4 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence66
build2 publishers

Graz researchers use file-change notifications to infer keystroke timing on Linux, plus other leaks on Android and Windows

Graz University researchers showed unprivileged apps can infer keystroke timing and browsing from file-change notifications on Linux, Android and Windows. The fixes shipped so far are partial, and the keystroke and KDE clickjacking flaws are still present.

Publishers:dev.tolwn.net

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60

Earlier coverage

  1. CVE-2026-89775 leaves a freed host page mapped and writable inside ARM64 KVM guests

    Security · September 22, 2026 · 1 publisher

  2. Canonical puts Ubuntu's one-week kernel fix in the -proposed pocket, ahead of certification testing

    Security · September 23, 2026 · 1 publisher

  3. Landlock moves path enumeration out of the AppArmor profile and into the process itself

    Build · September 21, 2026 · 1 publisher

  4. Red Hat's interim mitigations cover two of the three kernel flaws CISA lists as exploited

    Build · September 22, 2026 · 1 publisher

  5. npm ci OOM-killed a 1.6 GB production box while Cloudflare reported 521 and 522

    Build · September 22, 2026 · 1 publisher

  6. CISA gives agencies one business day to patch three exploited Linux kernel flaws

    Security · September 21, 2026 · 6 publishers

  7. Dirtying all of a 64 GB heap during a fork snapshot costs 16.8 million page faults

    Build · September 21, 2026 · 1 publisher

  8. Four newly disclosed exploits turn Linux kernel bugs aged 10 to 21 years into root

    Science · September 20, 2026 · 1 publisher

  9. Disabling unprivileged user namespaces stops three of four new Linux local-root bugs

    Security · September 20, 2026 · 1 publisher

  10. An unprivileged process can confine itself to a directory list without root

    Build · September 19, 2026 · 1 publisher

  11. Asim Manizada published working local-root exploits for four freshly patched Linux kernel bugs

    Security · September 18, 2026 · 1 publisher

  12. Residential proxy pools are pushing edge defence down to the TCP handshake

    Build · September 19, 2026 · 1 publisher

  13. Fifty openat calls in one second is the whole ransomware rule in talus-process-monitor

    Build · September 18, 2026 · 1 publisher

  14. A dark mute LED traced to one missing line in the kernel's Realtek quirk table

    Build · September 18, 2026 · 1 publisher

  15. Copy Fail gives a compromised Edgenius container root on ABB's bE100 gateway

    Security · September 17, 2026 · 1 publisher

  16. Black Duck's Boris Cipot names Microsoft, Google, Amazon and Cloudflare as Rust adopters in production

    Security · September 16, 2026 · 1 publisher

  17. Vercel's $1m sandbox escape challenge turned up two unfixed Linux kernel networking defects

    Security · September 15, 2026 · 1 publisher

  18. Trail of Bits says 1Password's 26% AI patch score reflects flawed prompts, no-code-execution trials, and grading errors, not true AI performance

    Security · September 15, 2026 · 1 publisher

  19. Auditing WireGuard means reviewing one config file, not a sprawling codebase

    Build · September 15, 2026 · 1 publisher

  20. Debian 13.7 folds 92 already-published advisories into the trixie installer

    Security · September 14, 2026 · 1 publisher

  21. Landlock confines a process from inside, with no root and no global policy

    Build · September 11, 2026 · 1 publisher

  22. fentry moves a mismatched kernel prototype from silent bad data to a load-time failure

    Build · September 7, 2026 · 1 publisher

  23. A UDP socket carries Frag Gap from inside a container into host kernel memory

    Build · September 6, 2026 · 1 publisher

  24. Unauthenticated file exposure puts ownCloud first in CISA's newest KEV batch

    Leadership · September 4, 2026 · 1 publisher

  25. Maintainers shipped 97 fixes against the 23,019 bugs Claude Mythos flagged

    Security · September 3, 2026 · 1 publisher

  26. ExploitGym grades agents on the step from crash input to working exploit

    Build · September 1, 2026 · 1 publisher

  27. MIT's TONTOU attack reaches protected Linux memory through a two-instruction window

    Product · August 28, 2026 · 1 publisher

  28. A fabrication checker cleared an invented CVE because it asked the wrong question

    Build · August 26, 2026 · 1 publisher

  29. Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count

    Security · August 26, 2026 · 1 publisher

  30. Exit code 137 is the kernel collecting on a bet you did not know it placed

    Build · August 23, 2026 · 1 publisher

  31. Buildroot's two-command ARM image, and the directory that will brick your board

    Build · August 23, 2026 · 1 publisher

  32. The kernel's unlikely() macro buys you fall-through, and bills you when you guess wrong

    Build · August 22, 2026 · 1 publisher

  33. A Voodoo 3 driver stops assuming the firmware already ran its video BIOS

    Build · August 22, 2026 · 2 publishers

  34. The rebase tax: where a driver lives is a staffing decision, not a packaging one

    Build · August 22, 2026 · 1 publisher

  35. The LG TV "custom kernel" did not break secure boot. Linux 4.4.3 has nothing behind it

    Security · August 22, 2026 · 1 publisher

  36. Coherent or streaming DMA is not a style choice: three ways ownership gets broken

    Build · August 21, 2026 · 1 publisher

  37. SystemReady's Devicetree band moves the board description into firmware, and the bill lands on updates

    Build · August 19, 2026 · 1 publisher

  38. The kernel's Assisted-by trailer makes AI help a signed line, not a rumour

    Build · August 19, 2026 · 1 publisher

  39. Linux 7.2 ships cache-aware scheduling, and Torvalds calls AI bug reports the new normal

    Product · August 17, 2026 · 1 publisher

  40. The MS-R1 ships KVM but no vhost, so an Android test fleet starts with a kernel build

    Build · August 17, 2026 · 1 publisher