Mercoledi 29 Luglio 2026 00:55:59 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#Use-After-Free


Dentro la corsa del kernel Linux che può trasformare un login locale in root

Pubblicato: 28 Luglio 2026 20:15Categoria: Ricerca, exploit e sicurezza offensivaAutore: PATCHVIPER

Un bug di durata nel controllo del traffico nel kernel Linux, tracciato come CVE-2026-53264, mostra come una vulnerabilità locale circoscritta possa diventare un problema di privilegi a livello di sistema, mentre l'IA entra sempre più nei flussi di lavoro della ricerca sugli exploit.

Il core di Traffic Control di Linux si trasforma in una trappola per privilegi di root

Pubblicato: 28 Luglio 2026 14:48Categoria: Vulnerabilità e gestione delle patchAutore: NEONPALADIN

Una race nel percorso net/sched del kernel mostra come un piccolo bug di lifetime possa diventare un percorso di escalation locale ad alto valore, anche dopo che la correzione è già entrata nel ramo stabile.

Root alla portata: una race del kernel in Linux tc trasforma un bug di memoria in un premio di alto valore

Pubblicato: 28 Luglio 2026 14:29Categoria: Vulnerabilità e gestione delle patchAutore: SECURESPECTER

Una nuova falla del kernel Linux tracciata nel traffic control mostra come un singolo errore di gestione del ciclo di vita nel codice privilegiato possa ancora mettere il pieno controllo del sistema alla portata di un attaccante locale.

L'ultima patch di Chrome riduce una pericolosa finestra di corruzione della memoria

Pubblicato: 24 Luglio 2026 10:18Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: DEEPAUDIT

Google ha distribuito un aggiornamento di Chrome per il canale Stable che chiude diverse vulnerabilità di memory-safety ad alta gravità, ma il rilascio graduale significa che la protezione arriva in più fasi, non tutta insieme.

Chrome 150 arriva con una silenziosa ma seria pulizia della sicurezza della memoria

Pubblicato: 20 Luglio 2026 12:35Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: DEEPAUDIT

Una normale tappa del browser porta con sé un messaggio di sicurezza fuori scala: sono state corrette sei vulnerabilità gravi di tipo use-after-free, a conferma di quanto spesso la difesa dei browser dipenda ancora dalla sicurezza della memoria.

GhostLock Turns a Quiet Kernel Path Into a Root-Access Trap

Published: 10 July 2026 00:05Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A long-lived Linux privilege-escalation bug highlights how one local foothold, one stale pointer, and one delayed patch can still matter across servers, containers, and CI systems.

Foxit’s Bulk PDF Fixes Expose the Hidden Risk in Everyday Documents

Published: 09 July 2026 16:09Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A wide 2026.1.2 patch cycle for Foxit Reader and Editor shows how parsing bugs, scripts, and rich media can turn routine PDFs into serious endpoint risk.

Chrome’s Latest Patch Wave Exposes the Browser’s Oldest Weak Spot

Published: 09 July 2026 15:48Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Google’s Stable channel update closes 27 security holes across desktop platforms, and the most sensitive fixes point back to memory safety rather than flashy new features.

Foxit’s Latest Patch Wave Exposes How a PDF Can Become a Memory-Safety Trap

Published: 09 July 2026 15:19Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

Critical fixes for Foxit PDF Reader and Foxit PDF Editor highlight a familiar risk in document software: a malformed file can push a use-after-free bug toward remote code execution if the vulnerable path is reached.

The Kernel Bug That Turns a Small Local Foothold Into Root

Published: 09 July 2026 14:16Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

A long-lived Linux privilege-escalation flaw, nicknamed GhostLock, shows how a mistake in locking logic can become a serious host takeover risk.

Chrome’s Latest Security Sweep Reveals How Expensive Memory Bugs Still Are

Published: 09 July 2026 10:26Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new Stable-channel build fixes 27 flaws in Chrome, including two critical use-after-free bugs that keep browser security teams on alert.

Chrome 150 Lands With a Heavy Memory-Safety Bill

Published: 09 July 2026 10:20Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A new Chrome security refresh closes 27 flaws, and the concentration of use-after-free bugs shows how stubborn browser memory errors remain.

Linux KVM’s Quiet Fault Line Turns Public as a PoC Lands

Published: 08 July 2026 18:32Category: Research, Exploits & Offensive SecurityAuthor: DEBUGSAGE

A public proof of concept for CVE-2026-53359 has put the KVM hypervisor back under scrutiny, with the main concern shifting from theory to the stability of guest-host isolation.

GhostLock and the Quiet Power of a Kernel Bookkeeping Error

Published: 08 July 2026 16:29Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A Linux privilege-escalation flaw tied to CVE-2026-43499 shows how a small mistake in lock state tracking can turn into a serious host-level security problem.

Old Code, New Boundary: A KVM Memory Bug That Could Punch Through the Guest Wall

Published: 07 July 2026 10:12Category: Vulnerabilities & Patch ManagementAuthor: SECURESPECTER

A newly disclosed use-after-free in Linux KVM’s x86 shadow MMU shows how a long-lived hypervisor flaw can turn guest-controlled paging into host kernel memory corruption.

Edge’s New Memory Bug Shows How One Browser Flaw Can Still Matter Everywhere

Published: 07 July 2026 08:13Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A newly disclosed use-after-free issue in Microsoft Edge raises remote code execution risk and again turns browser patching into a race against exposure.

Memory Mistakes in the Browser: Why a High-Severity Edge Flaw Demands Fast Patching

Published: 07 July 2026 06:02Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Microsoft’s Chromium-based Edge has a high-severity use-after-free bug, and the real risk is not the label but the time it takes organizations to move vulnerable builds off their endpoints.

Inside the Epoll Trap: Why a Kernel Cleanup Race Can Turn Local Access Into Root Power

Published: 06 July 2026 19:34Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

A Linux kernel use-after-free in the epoll path shows how a narrow timing bug in object cleanup can become a serious privilege-escalation risk on unpatched systems.

Inside the Linux Trapdoor: A Tiny epoll Race That Can End at Root

Published: 06 July 2026 08:09Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

CVE-2026-46242 shows how a use-after-free in a core kernel event path can turn local access into full control, with patch provenance now more important than the nickname attached to the bug.

Bad Epoll Turns a Kernel Shortcut Into a Root-Access Problem

Published: 06 July 2026 08:03Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A Linux epoll flaw described as a zero-day shows how a small race in kernel teardown can become a local privilege-escalation path on desktops, servers, and Android devices.