< ciso
brief />
Tag Banner

All news with #use after free tag

26 articles

Exploit for unpatched Ubuntu kernel container escape

πŸ” A use-after-free bug in the Linux kernel's AF_UNIX socket garbage collector (CVE-2026-80521) can be abused to escape containers and gain host root, DepthFirst reported on September 22. The flaw was fixed upstream on August 6, but Ubuntu has not yet shipped patches for 26.04, 24.04, or 22.04 LTS; DepthFirst released exploit code targeting Ubuntu 26.04. The vulnerability is reachable from containers because AF_UNIX is allowed by default in common Docker and Kubernetes seccomp profiles, and no distro workaround has been published.
read more β†’

Zoom annotation flaws allowed zero-click takeover

πŸ›‘οΈ Researchers found that Zoom's annotation feature could enable zero-click remote code execution between meeting participants. The flaws affected multiple Zoom clients and SDKs and were patched in June and July, before public disclosure, with no reported exploitation at publication. The bugs involve improper parsing of structured drawing objects, leading to buffer overflows, over-reads, and a use-after-free. Patches and CVE references are included in Zoom advisories.
read more β†’

Zapscape KVM vulnerability allows nested VM escape

πŸ”’ Zapscape (CVE-2026-64561) is a Linux KVM/x86 shadow-MMU flaw that can let an attacker with kernel privileges in an L1 guest escape KVM isolation and run code on the host. Disclosed by researcher Hyunwoo Kim, the issue is a stale-root ordering bug causing a use-after-free during page-fault handling when nested virtualization is exposed. The upstream fix has been merged; administrators should update kernels or vendor packages that backport the patch.
read more β†’

Google Chrome fixes 370 vulnerabilities in update

πŸ”’ Google’s Chrome team released version 151 (Windows, Mac and Linux) addressing 370 vulnerabilities, including seven critical flaws. The critical issues include several use after free bugs across Compositing, Views, Skia and Ozone, plus validation flaws in Dawn and ANGLE and a race condition in the Updater. These were reported between 18 May and 14 June 2026. The update also patches 71 high, 170 medium and 122 low severity issues, with researchers awarded $58,500 via the bug bounty.
read more β†’

AI-assisted research reveals Linux net/sched race

πŸ›‘οΈ AI-assisted research uncovered a years-old use-after-free race in the Linux kernel's net/sched code that permits local privilege escalation to root (CVE-2026-53264). The bug arises from mismatched locking where an entry can be freed before an RCU grace period ends, creating a window for the kernel to access freed memory. The flaw was found by Lee Jia Jie of STAR Labs, who used AI to locate and reliably reproduce the race; a patch defers freeing until after the grace period. Distributions should apply upstream fixes via normal security channels.
read more β†’

AI-assisted exploit yields local Linux root escalation

πŸ”’ STAR Labs published a local privilege-escalation exploit for CentOS Stream 9 that abuses a use-after-free race in the kernel traffic-control subsystem (CVE-2026-53264, CVSS 7.8). Researcher Lee Jia Jie says AI aided discovery and exploit development; the exploit requires specific kernel options, unprivileged user namespaces, and a kernel-specific ROP chain. Upstream fixes landed June 1, 2026 and have been backported to multiple stable branches, but distribution coverage remains uneven.
read more β†’

15-Year-Old Linux GhostLock Flaw Enables Root

πŸ›‘οΈ Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free that allows any logged-in user to gain root privileges on unpatched systems. The bug, present in mainstream distributions since 2011, requires only ordinary local threading calls and no network access. Nebula developed a 97% reliable exploit that also escapes containers and received $92,337 from Google's kernelCTF bounty. Patching is urgent, with early fixes having introduced a follow-up crash bug and distributions still rolling out the corrected kernel.
read more β†’

16-year KVM bug allows guest-to-host escape

πŸ›‘οΈ A critical KVM vulnerability, tracked as CVE-2026-53359 and nicknamed Januscape, lets an attacker with root in a guest VM execute code on the Linux host by exploiting a use-after-free in KVM's shadow MMU emulation on x86. Discovered by Hyunwoo Kim and present for 16 years, it affects both Intel and AMD servers and can enable host kernel panic, denial-of-service, or full RCE; some distros also allow local escalation via world-writable /dev/kvm. The Linux kernel was patched on June 16, but distribution rollouts may lag.
read more β†’

Januscape Linux kernel flaw enables VM escape

πŸ›‘οΈ A 16-year-old Linux kernel vulnerability called Januscape (CVE-2026-53359) allows guest-to-host escapes via a use-after-free in the KVM/x86 shadow MMU emulation. Discovered and detailed by researcher Hyunwoo Kim and patched in June 2026, it affects both Intel and AMD architectures and was used in Google's kvmCTF program. Unpatched multi-tenant hosts, especially with world-writable /dev/kvm, risk host takeover or denial-of-service.
read more β†’

Januscape: 16-year KVM flaw allows guest-to-host escape

πŸ›‘οΈ A long-standing use-after-free bug in Linux's KVM shadow MMU, tracked as CVE-2026-53359 and dubbed Januscape, lets a guest VM corrupt host shadow-page state and can reliably panic hosts. The public PoC triggers host crashes; the researcher reported an unreleased exploit that achieves full host code execution on Intel and AMD. Fixes were merged June 19, 2026 and backported to stable kernels on July 4, 2026; hosts with nested virtualization should be patched or have nesting disabled.
read more β†’

Bad Epoll kernel flaw lets local users become root

πŸ›‘οΈ A newly disclosed Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows an ordinary local user to escalate privileges to root and affects Linux desktops, servers, and Android. The flaw is a use-after-free race in the epoll subsystem; the timing window is tiny but an exploit by researcher Jaeyoung Chung widens it and succeeds reliably. A fix is available upstream (commit a6dc643c6931) and distributions should backport it; kernels built on 6.4+ are affected unless patched.
read more β†’

Apple issues urgent iOS, macOS and Safari security updates

πŸ”’ Apple released security updates for iOS, macOS, and Safari to address over three dozen vulnerabilities, including four WebKit flaws discovered with AI tools such as Anthropic Claude and OpenAI Codex Security. The fixes target memory corruption, out-of-bounds write, use-after-free, and other WebKit issues, plus several kernel-level bugs that could leak or corrupt memory. Updates are available for iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, and Apple noted no active exploitation has been reported.
read more β†’

F5 issues patches for two critical NGINX flaws

πŸ›‘οΈ F5 released updates to fix two critical vulnerabilities in NGINX Open Source that can allow remote code execution. CVE-2026-42530 is a use-after-free in the HTTP/3 QUIC module and CVE-2026-42055 is a heap-based buffer overflow affecting proxy and gRPC modules when specific directives are set. Patches are available across NGINX Open Source, NGINX Plus, Gateway Fabric, Instance Manager, WAF, DoS modules and Ingress Controller versions. Mitigations include disabling HTTP/3 for CVE-2026-42530 and adjusting ignore_invalid_headers or large_client_header_buffers settings for CVE-2026-42055.
read more β†’

F5 issues out‑of‑band patches for critical NGINX flaws

πŸ”’ F5 released out-of-band updates to fix multiple NGINX vulnerabilities, including two critical flaws in the ngx_http_v3_module and ngx_http_proxy_v2/_grpc modules that can lead to DoS or code execution. The bugs cause use‑after‑free or heap buffer overflow in worker processes and affect NGINX Plus, Open Source, Gateway Fabric, and Instance Manager. Mitigations include disabling HTTP/3 and adjusting header buffer directives until patches are applied.
read more β†’

Exim BDAT Use-After-Free 'Dead.Letter' Patch Released

πŸ”’ Exim has issued emergency updates to fix CVE-2026-45185, dubbed Dead.Letter, a critical use-after-free in BDAT message body parsing that manifests when TLS is handled via GnuTLS. The flaw is triggered when a client sends a TLS close_notify during an active BDAT transfer and then follows up with a final cleartext byte on the same TCP connection, which can corrupt heap metadata and enable code execution. It affects Exim 4.97 through 4.99.2 built with USE_GNUTLS=yes and is fixed in 4.99.3; there are no mitigations, so administrators should apply the update immediately.
read more β†’

Foxit Reader and LibRaw Vulnerabilities β€” Talos Advisory

πŸ”’ Cisco Talos disclosed a use-after-free flaw in Foxit Reader (TALOS-2026-2365 / CVE-2026-3779) exploitable via malicious PDF JavaScript, and six vulnerabilities in LibRaw including heap-based buffer overflows and integer overflows across multiple CVEs. All issues were patched by vendors following Cisco’s disclosure policy. Administrators should apply vendor updates and deploy Snort rules from Talos to detect exploitation.
read more β†’

CISA Adds CVE-2026-5281 to Known Exploited Vulnerabilities

πŸ”” CISA has added CVE-2026-5281, a Google Dawn use-after-free vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation. The listing invokes BOD 22-01 remediation requirements for Federal Civilian Executive Branch agencies, which must remediate by the specified due date. CISA strongly urges all organizations to prioritize timely remediation and strengthen vulnerability management, as use-after-free flaws are a common and impactful attack vector.
read more β†’

Google Patches Chrome Zero-Day CVE-2026-5281 Exploit

πŸ”’ Google released updates for Chrome to fix 21 vulnerabilities, including a zero-day (CVE-2026-5281) that has been exploited in the wild. Dawn, the WebGPU implementation, contains a use-after-free bug allowing a remote attacker with access to the renderer process to execute arbitrary code via crafted HTML. Users should update to versions 146.0.7680.177/178 on Windows and macOS and 146.0.7680.177 on Linux, and ensure Chromium-based browsers receive vendor patches.
read more β†’

Google fixes fourth Chrome zero-day exploited in 2026

⚠️ Google released emergency updates to fix a fourth actively exploited Chrome zero-day, tracked as CVE-2026-5281. The issue is a use-after-free in Dawn, Chromium's implementation of the WebGPU standard, and can cause crashes, rendering problems, or data corruption. Patches are available on Stable Desktop for Windows, macOS (146.0.7680.177/178), and Linux (146.0.7680.177); rollouts may take days, but updates are immediately available when checking.
read more β†’

Talos Disclosures: Foxit, Epic Games, and MedDream Flaws

πŸ”’ Cisco Talos disclosed multiple vulnerabilities affecting Foxit PDF Editor, the Epic Games Store installer, and MedDream PACS. The issues include installer privilege escalation, two use‑after‑free flaws in Foxit that can be triggered by crafted PDF JavaScript, and 21 reflected XSS vulnerabilities in MedDream. Vendors have issued patches under Cisco’s disclosure policy. Administrators should apply vendor updates and consider IDS/IPS signatures such as Snort to detect attempted exploitation.
read more β†’