linux
Safeguard articles tagged "linux" — guides, analysis, and best practices for software supply chain and application security.
40 articles
CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CVE-2026-31431 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-01.
CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability
CVE-2022-0492 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-02.
CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2022-0995 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2026-53362: Linux Kernel Unspecified Vulnerability
CVE-2026-53362 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-27.
A Sudo Bug Let Local Users Reach Root Without Ever Appearing in Sudoers
CVE-2025-32463 let any local user leverage sudo's --chroot option to run commands as root, bypassing the sudoers access-control model entirely.
Three Linux Kernel Privilege Escalation Bugs, Three Unrelated Subsystems, One Shared Trust Boundary
A netfilter heap overflow, an ELF-loading integer overflow, and a crypto API resource-transfer bug all reached CISA's KEV within a year — each a fresh failure of the same local privilege boundary.
Shellshock (CVE-2014-6271) Explained: RCE Hiding in Bash Environment Variables
CVE-2014-6271, Shellshock, let attackers run commands by smuggling code into environment variables that Bash parsed as function definitions. Reachable over HTTP, DHCP, and SSH. Here is how.
Baron Samedit (CVE-2021-3156) Explained: The Sudo Root Overflow
CVE-2021-3156, Baron Samedit, is a heap overflow in sudo that gives any local user root and hid in plain sight for nearly a decade. Here is the root cause, a one-line test, and the patched version.
PwnKit (CVE-2021-4034) Explained: Root From a 12-Year-Old Polkit Bug
CVE-2021-4034, aka PwnKit, is a memory-corruption flaw in polkit's pkexec that gives any local user reliable root on nearly every Linux distribution. Here is how it works and how to close it.
The CUPS RCE chain: a postmortem of CVE-2024-47176 and friends
The September 2024 CUPS chain (CVE-2024-47176, 47076, 47175, 47177) turned a printer browsing daemon into a remote code execution vector and exposed how badly long-tail Linux daemons get patched.
regreSSHion revisited: defending against CVE-2024-6387 in 2026
How the regreSSHion race condition in OpenSSH sshd reintroduced an unauthenticated RCE on glibc Linux, what the patch trajectory looked like, and the supply chain habits it should change.
Reproducible Builds Debian: The Long View
Debian's Reproducible Builds project has been at it for over a decade. Here's what they've learned, what still isn't reproducible, and why it matters.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.