Safeguard
Tag

linux

Safeguard articles tagged "linux" — guides, analysis, and best practices for software supply chain and application security.

40 articles

Vulnerability Analysis

CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

CVE-2026-31431 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-01.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability

CVE-2022-0492 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-02.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2022-0995 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-53362: Linux Kernel Unspecified Vulnerability

CVE-2026-53362 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-27.

Sep 17, 20263 min read
Vulnerability Analysis

A Sudo Bug Let Local Users Reach Root Without Ever Appearing in Sudoers

CVE-2025-32463 let any local user leverage sudo's --chroot option to run commands as root, bypassing the sudoers access-control model entirely.

Sep 16, 20265 min read
Vulnerability Analysis

Three Linux Kernel Privilege Escalation Bugs, Three Unrelated Subsystems, One Shared Trust Boundary

A netfilter heap overflow, an ELF-loading integer overflow, and a crypto API resource-transfer bug all reached CISA's KEV within a year — each a fresh failure of the same local privilege boundary.

Sep 16, 20265 min read
Vulnerability Analysis

Shellshock (CVE-2014-6271) Explained: RCE Hiding in Bash Environment Variables

CVE-2014-6271, Shellshock, let attackers run commands by smuggling code into environment variables that Bash parsed as function definitions. Reachable over HTTP, DHCP, and SSH. Here is how.

Jul 5, 20265 min read
Vulnerability Analysis

Baron Samedit (CVE-2021-3156) Explained: The Sudo Root Overflow

CVE-2021-3156, Baron Samedit, is a heap overflow in sudo that gives any local user root and hid in plain sight for nearly a decade. Here is the root cause, a one-line test, and the patched version.

Jul 4, 20266 min read
Vulnerability Analysis

PwnKit (CVE-2021-4034) Explained: Root From a 12-Year-Old Polkit Bug

CVE-2021-4034, aka PwnKit, is a memory-corruption flaw in polkit's pkexec that gives any local user reliable root on nearly every Linux distribution. Here is how it works and how to close it.

Jul 1, 20265 min read
Vulnerability Management

The CUPS RCE chain: a postmortem of CVE-2024-47176 and friends

The September 2024 CUPS chain (CVE-2024-47176, 47076, 47175, 47177) turned a printer browsing daemon into a remote code execution vector and exposed how badly long-tail Linux daemons get patched.

May 12, 20266 min read
Vulnerability Management

regreSSHion revisited: defending against CVE-2024-6387 in 2026

How the regreSSHion race condition in OpenSSH sshd reintroduced an unauthenticated RCE on glibc Linux, what the patch trajectory looked like, and the supply chain habits it should change.

May 12, 20266 min read
DevSecOps

Reproducible Builds Debian: The Long View

Debian's Reproducible Builds project has been at it for over a decade. Here's what they've learned, what still isn't reproducible, and why it matters.

Mar 18, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.