Vulnerabilities
Researchers Flag 11 Old Microsoft-Signed Linux UEFI Shims That Could Bypass Secure Boot
Eleven old Microsoft-signed shims land as bypasses of Secure Boot — Linux-boot defender review this week.
This tag is the central repository for intelligence regarding the open-source ecosystem powering cloud infrastructure and enterprise desktops. We track the unique security architecture of the Linux kernel and its distributions (Ubuntu, Fedora, Debian, Rocky), focusing on low-level memory safety and userspace daemon vulnerabilities.
Vulnerabilities
Eleven old Microsoft-signed shims land as bypasses of Secure Boot — Linux-boot defender review this week.
Linux
Another long-standing Linux finding lands with defender-team implications across distributions and container platforms.
Vulnerabilities
A significant Google bounty award draws attention to a Linux virtualization finding — defender review continues this week.
Linux
A long-standing KVM finding lands with cloud-provider implications — defender posture review this week.
Linux
Researchers detailed pedit COW, CVE-2026-46331, a Linux kernel privilege-escalation flaw in the act_pedit traffic-control action — a second Linux disclosure in the same weekend as DirtyClone, with distribution patch tracking continuing.
Linux
Another Linux kernel research disclosure — distribution patch tracking work for the week. JFrog published a working exploit for DirtyClone, a local privilege escalation to root in the kernel networking stack, fixed upstream in late May.
Vulnerabilities
A lifecycle deadline that requires defender coordination with hardware vendors, as Microsoft's 2011-era Secure Boot certificates begin expiring across Windows and Linux environments.
Vulnerabilities
A dormant TOCTOU race in PackageKit — the daemon almost every Linux distro ships — lets any local user poison a transaction and install a root-owned package with no password. It hid for 12 years, and a public exploit is already out.