buildOne report1 publisher Researcher Asim Manizada published working local-root exploits for four Linux kernel bugs on 18 September 2026. On hosts where containers or exposed services share one kernel, any compromised service can now become a lost node.
Reality
- Evidence55
- Adoption30
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Intel, AMD and Arm say their IBPB barrier can block Branch Target Reuse, a Spectre v2 variant hitting all three, if JIT software calls it. Each kernel, browser and runtime that rewrites JIT code now has to add that call itself.
Perspective Coverage
3 publishers
- Builder
- Builder 42%
- Operator
- Operator 51%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption40
- Hype gap+15
- Incentives30
- Confidence70
buildOne report1 publisher Copy Fail, tracked as CVE-2026-31431, lets any unprivileged local user write a chosen four bytes into the page cache of any readable file. Because it fires every time the right syscalls run in order, timing-based mitigations do not apply.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives42
- Confidence30
buildOne report1 publisher CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Canonical is merging two update cycles so that an Ubuntu kernel ships every week. Getting a CVE fix faster than that means running release candidates its certification testing has not yet cleared.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence60
buildOne report1 publisher A dev.to write-up argues that Landlock's unprivileged self-confinement retires the profile-maintenance tax that AppArmor and SELinux impose, though the rules it describes are still paths, so somebody has to enumerate them.
Reality
- Evidence24
- Adoption20
- Hype gap+45
- Incentives62
- Confidence28
The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.
Perspective Coverage
6 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence74
- Adoption68
- Hype gap−8
- Incentives38
- Confidence76
A researcher posting to oss-security reports that all four proof-of-concept exploits gave an unprivileged local user root code execution on the test targets, against kernel code that has been in the tree for between 10 and 21 years.
Publishers:scour.ing
Reality
- Evidence66
- Adoption35
- Hype gap−10
- Incentives28
- Confidence62
Fixes are in for four Linux local-root bugs found in code more than a decade old. Turning off unprivileged user namespaces closes three of them. The fourth stays open.
Publishers:heyitsas.im
Reality
- Evidence58
- Adoption32
- Hype gap+12
- Incentives55
- Confidence55
buildOne report1 publisher Landlock has been in mainline since kernel 5.13 and needs no policy file and no administrator to confine a process to named paths. The dev.to walkthrough explaining it leaves the enforcing syscall inside a comment.
Reality
- Evidence30
- Adoption35
- Hype gap+45
- Incentives30
- Confidence45
The fixes are already upstream, so the work now is confirming your distribution shipped them before someone with a low-privileged shell on a shared host uses the published code to reach root.
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives35
- Confidence60
CVE-2026-31431 escalates a locally authenticated user or a compromised container workload to root through the Linux kernel's algif_aead interface. ABB has fixed it in Edgenius 3.2.4.1 for the bE100 gateway.
Reality
- Evidence72
- Adoption30
- Hype gap0
- Incentives60
- Confidence66
A two-week, $1m escape challenge against Vercel's Firecracker sandbox produced 1,285 reports. The most valuable one hit the Linux kernel networking stack that many clouds use to isolate tenants, and its CVEs are pending.
Reality
- Evidence45
- Adoption35
- Hype gap+25
- Incentives80
- Confidence45
CSAIL researchers timed an interrupt to land inside the gap AMD's saferet defense leaves open, then pulled the root password file off a current Linux kernel. AMD has shipped a mitigation. Intel's picture is messier.
Reality
- Evidence38
- Adoption30
- Hype gap+26
- Incentives55
- Confidence44
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
Reality
- Evidence48
- Adoption44
- Hype gap+30
- Incentives66
- Confidence45