freenode

← freenode

tarpit

Security & Cryptography desk

Security & Cryptography4h ago

Critical Expat UTF-16 fix, Octavia RCE, and glibc loader flaws posted same week

oss-security carried a high-severity libexpat release, an OpenStack Amphora root RCE path, and two glibc dynamic-loader issues affecting AT_SECURE programs.

Security & Cryptography26h ago

HAWK exits and McEliece parameters buckle under fresh attacks

An AI-assisted lattice reduction forces HAWK out of the NIST signature round while quasipolynomial results leave Classic McEliece's proposed sizes without defenders.

Security & Cryptography6d ago

KVM/arm64 nested virt flaw allows guest escape to host

CVE-2026-89775 leaves a freed host page writable to the guest when nested virtualization is enabled, enabling cloud breakout and local root on some setups.

Security & Cryptography6d ago

Unbound 1.26.1 patches critical DNSKEY RCE and eight other flaws

NLnet Labs ships a security release fixing a heap overflow that can yield remote code execution, plus high-severity DNSSEC and CNAME issues.

Security & Cryptography6d ago

ISC patches 14 BIND 9 flaws, including remote crashes and DoS

Fixes span use-after-free bugs, DNSSEC validation errors, amplification paths, and unauthenticated crashes across recursive and authoritative roles.

Security & Cryptography7d ago

ZooKeeper ACL bypass lets anyone delete empty znodes

CVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.

Security & Cryptography7d ago

ZooKeeper critical bug leaks ACL-restricted paths on reconnect

CVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.

Security & Cryptography8d ago

CPython tarfile filters allow escape via hard link to symlink

CVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.

Security & Cryptography8d ago

Incomplete Emacs CVE-2024-53920 fix still allows code execution

Untrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.

Security & Cryptography9d ago

Canonical-signed GRUB 2.14 bypasses Secure Boot lockdown via serial MMIO

A local attacker who controls boot configuration can clear GRUB's file-verifier list and load unsigned modules while lockdown still reports enabled.

Security & Cryptography12d ago

Critical WebGL bug lets Chrome run code outside sandbox

CVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.

Security & Cryptography12d ago

Camel K critical flaw lets tenants run code as the operator

CVE-2026-80351 turns tenant-controlled Maven repositories into arbitrary code execution inside the Camel K operator pod.

Security & Cryptography13d ago

Tor 0.4.9.12 patches high-severity UAFs and drops TAP keys

The security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.

Security & Cryptography14d ago

Xen Tapdisk flaws let guests run code as root in dom0

Two out-of-bounds bugs in the userspace block backend give a malicious VM a direct path to host compromise.

Security & Cryptography17d ago

util-linux 2.42.3 fixes mount races and nsenter leaks

Four new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.

Security & Cryptography17d ago

libxml2 2.15.4 patches eight XML parsing memory flaws

The release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.

Security & Cryptography19d ago

OpenStack Glance SSRF flaws expose internal URLs and image data

Three related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.

Security & Cryptography19d ago

Linux XFS flaw lets local users overwrite files for root

CVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.

Security & Cryptography21d ago

FreeRDP 3.31.0 plugs five server bugs, pre-auth RCE chain

GNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.

Security & Cryptography24d ago

Four U-Boot filesystem overflows risk pre-boot code execution

Integer overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.

Security & Cryptography24d ago

Vault Secrets Operator leaks privileged token to tenants

CVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.

Security & Cryptography26d ago

Vim patches out-of-bounds write in bundled libvterm resize handling

Before 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.

Security & Cryptography27d ago

Tomcat rewrite [N] flag bug can bypass access controls

An off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.

Security & Cryptography27d ago

Tomcat security constraint bypass fixed as CVE-2026-65182

Path ordering could let requests slip past more restrictive access rules on shorter prefixes.

Security & Cryptography28d ago

OpenRGB root daemon allows trivial remote compromise

Flaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.

Security & Cryptography32d ago

Classic McEliece team: new attack still slower than known methods

Preliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.

Security & Cryptography32d ago

Emacs TRAMP zero-click flaw runs local shell commands

Crafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.

Security & Cryptography32d ago

Ceph auth flaws force keyring rotation across OpenStack

Four CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.

Security & Cryptography34d ago

Ceph patches CephX auth bypass and Monitor key-store leak

Tentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.

Security & Cryptography36d ago

OpenZFS on Linux full-disclosed for zpool and userns escapes

Researcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.

Security & Cryptography41d ago

Apache Airflow 3.3.1 patches three DAG-author RCE bugs in the scheduler and API server

Three important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.

Security & Cryptography42d ago

Flatpak 1.18.1 plugs sandbox escapes and local root escalations

The stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.

Security & Cryptography42d ago

OpenStack Designate bugs allow cross-tenant DNS zone collisions

Two flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.

Security & Cryptography47d ago

Zapscape: KVM/x86 use-after-free lets guests escape to host

CVE-2026-64561 corrupts host shadow pages from untrusted guests when nested virtualization is exposed, especially on multi-tenant clouds.

Security & Cryptography47d ago

PowerDNS patches high-severity DNS packet resource exhaustion bug

CVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.

Security & Cryptography47d ago

Linux SCTP bug lets local users hit root and escape containers

A use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.

Security & Cryptography48d ago

Bouncy Castle Java 1.85 closes 32 CVEs in core crypto paths

The July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.

Security & Cryptography48d ago

X.Org patches libXfont2 font client flaws that can escalate privileges

Version 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.

Security & Cryptography49d ago

AI cryptanalysis forces HAWK out and hardens the SSH ML-DSA fight

An Anthropic lattice break that halved HAWK’s dimension, and an IETF call for ML-DSA drafts that immediately invoked machine-assisted attacks, have turned AI from a future worry into a live input on which post-quantum algorithms survive standardization.

Security & Cryptography49d ago

Django patches high-severity spatial lookup file-write flaw

Staff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.

Security & Cryptography50d ago

Apache NiFi auth flaw let read-only users override parameter checks

CVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.

Security & Cryptography50d ago

NIST leans toward seed-only keys for HQC in draft FIPS 207

The agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.

Security & Cryptography51d ago

Lean 4 kernel bug lets metaprograms forge proofs of False

A nested inductive projection flaw accepted axiom-free proofs of 0 = 1 until a late July nightly fix.

Security & Cryptography53d ago

GNOME cuts vuln embargo to 30 days, stops AI-ban forwards

Longtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.

Security & Cryptography53d ago

PHP security releases fix SQL injection and out-of-bounds write

Four branches ship fixes for PostgreSQL injection, Phar crashes, libgd, and a BCMath flaw limited to newer lines.

Security & Cryptography54d ago

Researcher discloses 33 flaws in stagnant cJSON library

Memory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.

Security & Cryptography54d ago

Apache Traffic Server patches 38 flaws, some CVSS 10

Versions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.

Security & Cryptography56d ago

Xen ships batch of fixes for guest escapes spanning grant tables, pygrub, and more

Six advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.

Security & Cryptography56d ago

Resolver stacks buckle together under DNSSEC and transport CVEs

Same-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.

Security & Cryptography60d ago

OpenStack Ironic Python Agent allows root command execution via NTP config

Unsanitized ntp_server values let project managers run arbitrary commands during ramdisk startup.

Security & Cryptography60d ago

Knot Resolver 6.3.0 DoQ overflow allows unauthenticated RCE

A single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.

Security & Cryptography62d ago

IETF TLS list: structural CoI question over Security AD meets moderation warning

A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.

Security & Cryptography62d ago

Linux UDP corking bugs yield local root on kernels since 6.1

Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.

Security & Cryptography62d ago

Linux XFS privilege escalation, BIND and Unbound DNS flaws, and Exim local bugs land together

A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.

Security & Cryptography62d ago

TLS chairs refuse to release the weighting behind a contested ML-KEM consensus call

After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.

Security & Cryptography62d ago

Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door

While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.

Security & Cryptography62d ago

TLS chairs call rough consensus to advance pure ML-KEM over sustained objection

Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.

Security & Cryptography63d ago

libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws

Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.

Security & Cryptography63d ago

snapd 2.76.1 patches LPE and two sandbox flaws

Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.