<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Linux</title><description>Actively exploited vulnerabilities affecting Linux products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/linux.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2022-0492 — Linux Kernel Improper Authentication Vulnerability</title><link>https://wildfortech.com/security#CVE-2022-0492</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2022-0492</guid><description>This Linux kernel flaw allows an unprivileged local user to escalate their privileges to root by abusing the cgroups v1 release_agent feature, which lacks proper authentication checks. In practice, this means any user with local access to an affected system — including container workloads — could potentially gain full system control. It is especially concerning in multi-tenant or containerized environments where privilege boundaries are critical security assumptions.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item><item><title>CVE-2026-31431 — Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-31431</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-31431</guid><description>This Linux Kernel flaw involves incorrect resource transfer between security boundaries, a class of bug that attackers can exploit to gain elevated privileges on a compromised system. In practice, a local user or process with limited rights could leverage this vulnerability to escalate to root or kernel-level access, potentially taking full control of the affected host. Any Linux system running a vulnerable kernel version is at risk, making this particularly urgent for servers, cloud instances, and embedded Linux devices.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item><item><title>CVE-2018-14634 — Linux Kernel Integer Overflow Vulnerability</title><link>https://wildfortech.com/security#CVE-2018-14634</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2018-14634</guid><description>This Linux kernel flaw in the create_elf_tables() function allows a local, unprivileged user to trigger an integer overflow and escalate their privileges to root or other elevated levels. The attack vector requires access to a SUID or otherwise privileged binary, which are common on most Linux systems. Successful exploitation gives an attacker full control of the affected host, making this a serious risk in any multi-user or shared Linux environment.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item><item><title>CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-22555</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-22555</guid><description>This Linux kernel vulnerability allows a local attacker to write data beyond the bounds of a heap memory buffer, exploitable through user namespaces. A successful attack can escalate privileges — potentially giving an unprivileged user root-level access — or crash the system via memory corruption. Because user namespaces are widely enabled on modern Linux distributions, this vulnerability is broadly relevant to servers, containers, and desktop systems running affected kernel versions.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item><item><title>CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-38352</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-38352</guid><description>This Linux kernel vulnerability involves a race condition where an attacker can exploit the gap between when a resource is checked and when it is actually used. Because it affects the kernel itself, successful exploitation can compromise the entire system — impacting confidentiality (data exposure), integrity (data or system tampering), and availability (denial of service or crashes). Any system running a vulnerable kernel version is potentially at risk, making this a high-priority concern for Linux-based infrastructure.</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item><item><title>CVE-2023-0386 — Linux Kernel Improper Ownership Management Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-0386</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-0386</guid><description>This Linux kernel flaw in the OverlayFS subsystem lets a local, unprivileged user escalate to root-level privileges. By copying a setuid file with special capabilities from a nosuid-mounted filesystem into another mount, the attacker exploits a UID mapping bug to gain capabilities they should never have. This is particularly dangerous on shared systems, containers, and cloud environments where local access by untrusted users is common — a foothold becomes full system compromise.</description><pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate><category>Linux</category><category>Kernel</category></item></channel></rss>