Kernel-Security

4 posts

/openbsd-pap-empty-password-bypass/openbsd-pap-empty-password-bypass.png
OpenBSD Let Attackers Log In With an Empty Password for 27 Years

June 17, 2026

A 27-year-old flaw in OpenBSD let attackers bypass its PPP login with nothing more than an empty username and an empty password. Hand a vulnerable system a …

/ssh-keysign-pwn-cve-2026-46333/featured-image.png
ssh-keysign-pwn Lets Any Linux User Steal SSH Keys and Password Hashes Without Root

May 16, 2026

ssh-keysign-pwn is a newly disclosed Linux kernel vulnerability that gives any unprivileged local user direct access to the SSH host private keys of a server …

/dirty-frag-linux-root/featured-image.gif
Dirty Frag Gives Root Access on Every Major Linux Distribution

May 8, 2026

A new Linux zero-day called Dirty Frag gives any local user full root access on every major Linux distribution, and right now no distribution has a patched …

/copy-fail-linux-kernel-cve-2026-31431/featured-image.png
Copy Fail CVE-2026-31431: Nine Years of Root Access Hidden in the Linux Kernel

April 30, 2026

Since 2017, every major Linux distribution has been shipping a flaw that hands root access to any local user. The exploit is a 732-byte Python script that uses …