Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

15 / 28 results
Active filter:vendor: linux✕ clear
18-year-old Linux SCTP flaw enables local root and container escapecriticalbug_reportVulnerability
bug_reportVulnerability

18-year-old Linux SCTP flaw enables local root and container escape

Linux kernel versions since 2.6.25 (2008) through 7.1.5, 6.18.41, 6.12.100, and 6.6.147. Affects systems with SCTP networking enabled. Confirmed vulnerable: Debian 13, Ubuntu 24.04, Rocky Linux 9, RHEL 9, OpenCloudOS.

Linux7 Aug · 09:10 UTC
Zapscape KVM flaw allows L1 guest escape to host with nested virtualizationhighbug_reportVulnerability
bug_reportVulnerability

Zapscape KVM flaw allows L1 guest escape to host with nested virtualization

Linux kernel KVM/x86 shadow MMU in versions 5.9 through 7.1.5. Fixed in stable releases 6.6.148, 6.12.101, 6.18.42, 7.1.6, and 7.2-rc5. Affects systems running KVM hosts with nested virtualization exposed to untrusted guests.

CVE-2026-645616 Aug · 15:58 UTC
Linux kernel Open vSwitch flaw grants local root; public exploit availablehighbug_reportVulnerability
bug_reportVulnerability

Linux kernel Open vSwitch flaw grants local root; public exploit available

Linux kernel Open vSwitch datapath. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Affects default configurations of AlmaLinux 9/10, Alpine 3.22-3.24, Amazon Linux 2023, Arch, CentOS Stream 9/10, Debian 12/13, Fedora…

CVE-2026-645315 Aug · 09:43 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
Linux kernel use-after-free in traffic-control allows local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux kernel use-after-free in traffic-control allows local root escalation

Linux kernel versions 4.14 through 7.0.x. Fixed in 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, and mainline 7.1-rc7. CentOS Stream 9 exploit demonstrated.

CVE-2026-5326428 Jul · 06:04 UTC
Linux XFS race condition CVE-2026-64600 enables local root escalationhighbug_reportVulnerability
bug_reportVulnerability

Linux XFS race condition CVE-2026-64600 enables local root escalation

Linux kernel v4.11 and later (since February 2017) with XFS filesystem and reflink enabled (default on RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, CloudLinux).

CVE-2026-6460023 Jul · 09:40 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-434998 Jul · 04:16 UTC
16-year-old Linux kernel flaw enables VM escape on Intel and AMD hostshighbug_reportVulnerability
bug_reportVulnerability

16-year-old Linux kernel flaw enables VM escape on Intel and AMD hosts

Linux kernel (specific versions not disclosed); affects virtualization environments on Intel and AMD processors. VM escape vulnerability impacts hypervisors relying on affected kernel versions.

Linux7 Jul · 10:06 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-533596 Jul · 15:37 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-462423 Jul · 17:40 UTC
Linux kernel traffic-control flaw grants local root via public exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel traffic-control flaw grants local root via public exploit

Linux kernel traffic-control subsystem (act_pedit module). All distributions running vulnerable kernel versions are affected. Specific patched versions not provided; assume unpatched kernels prior to June 16, 2026 vendor advisories are vulnerable.

CVE-2026-4633126 Jun · 11:57 UTC
DirtyClone Linux kernel flaw enables local privilege escalation to roothighbug_reportVulnerability
bug_reportVulnerability

DirtyClone Linux kernel flaw enables local privilege escalation to root

Linux kernel (specific vulnerable versions not disclosed). Affects systems where local users can trigger network packet cloning operations. Part of the DirtyFrag vulnerability family.

CVE-2026-4350326 Jun · 09:51 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux12 Jun · 16:17 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-231118 Jun · 18:17 UTC
CIFSwitch: Linux kernel CIFS flaw enables local privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

CIFSwitch: Linux kernel CIFS flaw enables local privilege escalation

Linux kernel CIFS implementation across multiple distributions. Specific affected kernel versions not yet disclosed. Requires local access to exploit.

Linux30 May · 12:16 UTC