Foundational security for the Linux kernel. Solving the most difficult memory unsafety problems. Created by @opensrcsec

It's now available to beta testers!
We expect our 7.1 beta to be available for testing within the next two weeks.
2
5
1,248
We expect our 7.1 beta to be available for testing within the next two weeks.
2
10
3,045
If you're just now hearing about GhostLock and looking to fix it, make sure you don't introduce two unpriv-reachable DoSes associated with its fixes. The fix the Linux CNA lists for CVE-2026-43499 introduces a NULL deref, which caused CVE-2026-53166 to be issued. Unfortunately...
1
6
19
3,098
the fix referenced by that CVE introduces a worse DoS (busy loops on all CPUs in the kernel), and has no CVE yet to inform users. We discovered this second DoS early last month through routine inspection. Our recommendation:
1
1
6
990
Apply the initial fix: git.kernel.org/pub/scm/linux… Ignore the fix for CVE-2026-53166 which introduced the worse DoS and was reverted just recently: git.kernel.org/pub/scm/linux… Apply this fix which addressed the same initial DoS issue without introducing another: git.kernel.org/pub/scm/linux…
1
8
797
KERNSEAL makes the linear page cache overflow in cyberstan.co.uk/fuse-readdir… deterministically unexploitable. Serial log below 👇
9
29
2,751
It's now available!
We expect our 7.0 beta to be available for testing within the next two weeks.
4
6
2,024
We expect our 7.0 beta to be available for testing within the next two weeks.
1
8
3,492
Exploits are now appearing targeting pidfd, which is forced into all Linux kernels since 5.10 (2020), no module or initcall to blacklist this time, must patch ASAP!
We've just sent a detailed mail to all customers notifying them of this issue, with split-out fixes available for 5.15, 6.6, and 6.18. We'll share more information on our Knowledge Base as it becomes available.
2
31
113
25,309
Correcting the above: in terms of LTS kernels it's 5.10+, but the 2020 commit came in Linux 5.6 (so would affect for instance some Ubuntu 20.04 kernels as well on 5.8)
1
2
1,272
As mentioned at openwall.com/lists/oss-secur… , distro users can echo 2 > /proc/sys/kernel/yama/ptrace_scope to mitigate. Keep in mind this will break some normal usage, like preventing unprivileged use of strace, gdb, etc entirely.
1
1
846
We don't recommend the '3' setting (which rejects all attach-like ptrace_may_access() requests, regardless of privilege level) as once set, it is locked to that value until reboot.
609
We've just published a Knowledge Base article with more information about the vulnerability, current published/unpublished exploits, and current mitigations. We still recommend patching ASAP.
Exploits are now appearing targeting pidfd, which is forced into all Linux kernels since 5.10 (2020), no module or initcall to blacklist this time, must patch ASAP!
2
3
13
3,989
We've just sent a detailed mail to all customers notifying them of this issue, with split-out fixes available for 5.15, 6.6, and 6.18. We'll share more information on our Knowledge Base as it becomes available.
We've uploaded new patches for 5.15, 6.6, and 6.18 to address an obfuscated upstream Linux logic vulnerability that should exist in all kernel versions: git.kernel.org/pub/scm/linux…
17
19,891
We've uploaded new patches for 5.15, 6.6, and 6.18 to address an obfuscated upstream Linux logic vulnerability that should exist in all kernel versions: git.kernel.org/pub/scm/linux…
1
10
46
8,706
The commit message makes no mention of it, but we believe the goal of exploiting the vulnerability would be to target a suid root binary that drops its privileges while retaining privileged access to a file on exit that via the vuln an unprivileged user could gain access to.
2
7
2,482
We've published a detailed KB article for customers on the two vulnerabilities involved in Dirty Frag and the associated public exploits, feel free to reach out with any questions.
2
5
2,131
Fixes for Dirty Frag (seclists.org/oss-sec/2026/q2…) were already included in our current 6.6 and 6.18 patches from May 4th. No distro builds in CONFIG_AF_RXRPC, so MODHARDEN should be generally effective against unprivileged exploitation.
3
17
67
8,579
The upstream rxrpc vulnerability affects >= 6.5. The second vuln reusing the same "Dirty Frag" naming requires unprivileged userns to exploit as an unprivileged user, disabled in grsecurity since it first existed.
1
1
5
1,584