<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:webfeeds="http://webfeeds.org/rss/1.0" version="2.0">
  <channel>
    <title>LinuxSecurity - Security Features</title>
    <link>https://linuxsecurity.com/</link>
    <description>The central voice for Linux and Open Source security news.</description>
    <language>en-us</language>
    <copyright>1999-2026 Guardian Digital, Inc. All rights reserved</copyright>
    <managingEditor>dave@linuxsecurity.com (Dave Wreski)</managingEditor>
    <pubDate>Tue, 06 Oct 2026 16:40:31 +0000</pubDate>
    <lastBuildDate>Tue, 06 Oct 2026 16:40:31 +0000</lastBuildDate>
    <generator>generate_indexes-linuxsecurity-v451-validation-scope-fix.php</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <atom:link href="https://linuxsecurity.com/static-content/linuxsecurity_features.xml" rel="self" type="application/rss+xml" />
    <ttl>20</ttl>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/top-6-vulnerability-scanning-tools</guid>
      <link>https://linuxsecurity.com/features/top-6-vulnerability-scanning-tools</link>
      <title>Top Linux Vulnerability Scanners in 2026: A Guide to Open-Source Security Tools</title>
      <description>Computer systems, software, applications, and Linux servers are all vulnerable to network security threats. Failure to identify these cybersecurity vulnerabilities, often through modern vulnerability scanning tools, can leave companies exposed</description>
      <pubDate>Tue, 14 Apr 2026 16:00:44 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-kernel-vulnerability-binderfs-device-creation</guid>
      <link>https://linuxsecurity.com/features/linux-kernel-vulnerability-binderfs-device-creation</link>
      <title>Linux Kernel Vulnerability Fixed in Binder Device Creation</title>
      <description>Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.</description>
      <pubDate>Tue, 06 Oct 2026 03:10:16 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-ipsec-queue-bug-device-use-after-free</guid>
      <link>https://linuxsecurity.com/features/linux-ipsec-queue-bug-device-use-after-free</link>
      <title>Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race</title>
      <description>Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.</description>
      <pubDate>Fri, 02 Oct 2026 00:00:21 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-fastrpc-shared-buffer-cleanup-race</guid>
      <link>https://linuxsecurity.com/features/linux-fastrpc-shared-buffer-cleanup-race</link>
      <title>Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race</title>
      <description>Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.</description>
      <pubDate>Thu, 01 Oct 2026 23:45:20 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-qnx6-filesystem-memory-safety-fixes</guid>
      <link>https://linuxsecurity.com/features/linux-qnx6-filesystem-memory-safety-fixes</link>
      <title>Proposed Linux QNX6 Fixes Address Filesystem Memory Errors</title>
      <description>Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.</description>
      <pubDate>Thu, 01 Oct 2026 23:35:49 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/flatpak-vulnerability-linux-host-files-processes</guid>
      <link>https://linuxsecurity.com/features/flatpak-vulnerability-linux-host-files-processes</link>
      <title>Flatpak Vulnerability Fixes Protect Linux Host Files and Processes</title>
      <description>Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.</description>
      <pubDate>Thu, 01 Oct 2026 01:15:32 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-device-driver-rtc-provider-use-after-free</guid>
      <link>https://linuxsecurity.com/features/linux-device-driver-rtc-provider-use-after-free</link>
      <title>Linux Device Driver Fix Prevents Clock Lookups From Reading Freed Memory</title>
      <description>A Linux device driver fix closes a use-after-free risk in the AC100 real-time clock (RTC) driver.</description>
      <pubDate>Thu, 01 Oct 2026 01:15:45 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-storage-nvmem-double-free-setup</guid>
      <link>https://linuxsecurity.com/features/linux-storage-nvmem-double-free-setup</link>
      <title>Linux Storage Fix Stops Cleanup From Freeing the Same Object Twice</title>
      <description>A Linux flash-storage fix prevents a double free, in which the kernel releases the same object twice during device setup.</description>
      <pubDate>Thu, 01 Oct 2026 01:00:51 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/superh-linux-page-fault-double-mmap-lock-unlock</guid>
      <link>https://linuxsecurity.com/features/superh-linux-page-fault-double-mmap-lock-unlock</link>
      <title>Linux Memory Fault Bug Can Release a Lock Twice on SuperH</title>
      <description>A proposed Linux patch addresses a double unlock in the SuperH architecture’s page-fault handling.</description>
      <pubDate>Wed, 30 Sep 2026 00:15:45 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-kernel-security-boundaries-review</guid>
      <link>https://linuxsecurity.com/features/linux-kernel-security-boundaries-review</link>
      <title>How to Review Linux Security Boundaries: Three Kernel Examples</title>
      <description>A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.</description>
      <pubDate>Tue, 29 Sep 2026 23:35:22 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/crun-container-images-host-microvm-settings</guid>
      <link>https://linuxsecurity.com/features/crun-container-images-host-microvm-settings</link>
      <title>crun Blocks Container Images From Choosing Host MicroVM Settings</title>
      <description>crun has tightened the boundary between container-controlled configuration and host-controlled microVM behavior.</description>
      <pubDate>Tue, 29 Sep 2026 03:45:14 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-ebpf-interpreter-races-program-execution</guid>
      <link>https://linuxsecurity.com/features/linux-ebpf-interpreter-races-program-execution</link>
      <title>Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch</title>
      <description>Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a program.</description>
      <pubDate>Mon, 28 Sep 2026 23:45:51 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-gpu-reset-multi-container-mapping</guid>
      <link>https://linuxsecurity.com/features/linux-gpu-reset-multi-container-mapping</link>
      <title>Linux GPU Security Fix Prevents Stale Mappings Across Containers</title>
      <description>A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.</description>
      <pubDate>Mon, 28 Sep 2026 22:45:46 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/runc-1-5-2-linux-cgroup-v2-memory-corruption</guid>
      <link>https://linuxsecurity.com/features/runc-1-5-2-linux-cgroup-v2-memory-corruption</link>
      <title>runc 1.5.2 Shields Containers From a Linux cgroup v2 Memory-Corruption Bug</title>
      <description>runc 1.5.2 adds a workaround for a Linux cgroup v2 memory-corruption bug that can make the privileged container runtime crash unpredictably.</description>
      <pubDate>Mon, 28 Sep 2026 22:25:24 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-kvm-pkvm-stacks-nested-mmu-lifetime</guid>
      <link>https://linuxsecurity.com/features/linux-kvm-pkvm-stacks-nested-mmu-lifetime</link>
      <title>Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines</title>
      <description>A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hypervisor stacks and the lifetime of memory-management state used by nested virtual machines.</description>
      <pubDate>Mon, 28 Sep 2026 22:00:34 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ext4-corrupted-inline-data-bounds-check</guid>
      <link>https://linuxsecurity.com/features/ext4-corrupted-inline-data-bounds-check</link>
      <title>Linux ext4 Patch Blocks an Out-of-Bounds Read From Damaged Metadata</title>
      <description>Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.</description>
      <pubDate>Fri, 25 Sep 2026 20:35:36 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-ext4-inline-directory-conversion-race</guid>
      <link>https://linuxsecurity.com/features/linux-ext4-inline-directory-conversion-race</link>
      <title>Why an Unlocked ext4 Buffer Can Restore Stale Directory Data</title>
      <description>A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.</description>
      <pubDate>Fri, 25 Sep 2026 20:15:38 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-usb-ip-timer-device-teardown</guid>
      <link>https://linuxsecurity.com/features/linux-usb-ip-timer-device-teardown</link>
      <title>USB/IP Teardown Race Can Rearm a Freed Linux Kernel Timer</title>
      <description>A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.</description>
      <pubDate>Fri, 25 Sep 2026 20:15:47 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-io-uring-sqpoll-freed-ring-state</guid>
      <link>https://linuxsecurity.com/features/linux-io-uring-sqpoll-freed-ring-state</link>
      <title>Why an io_uring Queue Handoff Can Become a Use-After-Free</title>
      <description>A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.</description>
      <pubDate>Fri, 25 Sep 2026 21:00:49 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ebpf-security-trampoline-race-freed-programs</guid>
      <link>https://linuxsecurity.com/features/ebpf-security-trampoline-race-freed-programs</link>
      <title>A Linux eBPF Trampoline Can Outlive the Program It Calls</title>
      <description>A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.</description>
      <pubDate>Fri, 25 Sep 2026 19:45:34 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-cgroup-namespace-race-freed-root-object</guid>
      <link>https://linuxsecurity.com/features/linux-cgroup-namespace-race-freed-root-object</link>
      <title>Linux Cgroup Namespace Race Could Expose a Freed Root Object</title>
      <description>A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.</description>
      <pubDate>Thu, 24 Sep 2026 22:30:48 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-ipe-dm-verity-freed-policy-data</guid>
      <link>https://linuxsecurity.com/features/linux-ipe-dm-verity-freed-policy-data</link>
      <title>Linux Integrity Checks Could Read Freed dm-verity Policy Data</title>
      <description>Linux integrity checks depend on more than a correct policy or a trusted hash. The kernel must also keep that security state alive for the entire decision. A new patch series reports two places where Integrity Policy Enforcement could continue reading after policy or dm-verity data had been freed. Integrity Policy Enforcement, usually shortened to IPE, is a Linux Security Module that can allow or deny access according to integrity properties. dm-verity supplies read-only block-device verifica...</description>
      <pubDate>Thu, 24 Sep 2026 22:15:11 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-dvb-usb-driver-disconnect-use-after-free</guid>
      <link>https://linuxsecurity.com/features/linux-dvb-usb-driver-disconnect-use-after-free</link>
      <title>Linux Device Driver Race Leaves Open Files Using Freed Memory</title>
      <description>A Linux device driver can keep an open file alive while freeing the hardware state that file still needs.</description>
      <pubDate>Thu, 24 Sep 2026 22:15:39 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-hid-flaw-could-leak-kernel-memory-through-input-events</guid>
      <link>https://linuxsecurity.com/features/linux-hid-flaw-could-leak-kernel-memory-through-input-events</link>
      <title>Linux HID Flaw Could Leak Kernel Memory Through Input Events</title>
      <description>A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.</description>
      <pubDate>Wed, 23 Sep 2026 19:30:07 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-damon-page-table-bug-could-corrupt-arm64-system-memory</guid>
      <link>https://linuxsecurity.com/features/linux-damon-page-table-bug-could-corrupt-arm64-system-memory</link>
      <title>Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory</title>
      <description>Linux DAMON, the kernel's Data Access Monitor, samples memory use to show which pages a workload touches.</description>
      <pubDate>Wed, 23 Sep 2026 19:25:32 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ph4ntxm-linux-disposable-identity</guid>
      <link>https://linuxsecurity.com/features/ph4ntxm-linux-disposable-identity</link>
      <title>PH4NTXM Linux Builds a Disposable Identity at Every Boot</title>
      <description>A live Linux distribution runs from removable media, usually a USB drive, without requiring a permanent installation.</description>
      <pubDate>Wed, 23 Sep 2026 00:25:57 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/crun-gpu-renderer-container-isolation</guid>
      <link>https://linuxsecurity.com/features/crun-gpu-renderer-container-isolation</link>
      <title>crun Tightens GPU Security for Containers Running in MicroVMs</title>
      <description>The crun container runtime has changed how GPU-enabled workloads launch a key graphics helper.</description>
      <pubDate>Tue, 22 Sep 2026 05:15:44 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-dma-teardown-use-after-free</guid>
      <link>https://linuxsecurity.com/features/linux-dma-teardown-use-after-free</link>
      <title>Linux Fixes Two Memory Safety Bugs in DMA Cleanup</title>
      <description>Linux developers have fixed two memory-safety bugs in the subsystem that lets hardware move data without constant help from the CPU.</description>
      <pubDate>Tue, 22 Sep 2026 04:45:18 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-input-kernel-stack-data-leak</guid>
      <link>https://linuxsecurity.com/features/linux-input-kernel-stack-data-leak</link>
      <title>Linux Fixes Input Bugs That Could Leak Kernel Memory</title>
      <description>Linux developers have fixed two input-system bugs that could expose small pieces of leftover kernel memory to a local program.</description>
      <pubDate>Tue, 22 Sep 2026 04:35:31 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/selinux-nested-overlayfs-mprotect-checks</guid>
      <link>https://linuxsecurity.com/features/selinux-nested-overlayfs-mprotect-checks</link>
      <title>Linux Fix SELinux Overlays Important Security Contexts 401610</title>
      <description>Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.</description>
      <pubDate>Mon, 21 Sep 2026 23:00:37 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-security-roundup-september-18-2026</guid>
      <link>https://linuxsecurity.com/features/linux-security-roundup-september-18-2026</link>
      <title>Linux Security Roundup: Patch BIND, Browsers, and Cloud Kernels First</title>
      <description>Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.</description>
      <pubDate>Fri, 18 Sep 2026 21:00:22 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>linuxsecurity-com-must-read-articles</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-packet-metadata-stale-header-offsets</guid>
      <link>https://linuxsecurity.com/features/linux-packet-metadata-stale-header-offsets</link>
      <title>Linux Packet Metadata Could Point to Headers That No Longer Exist</title>
      <description>Linux packet metadata could keep pointing to network headers after the underlying packet had been rebuilt without them.</description>
      <pubDate>Fri, 18 Sep 2026 20:15:46 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-ebpf-security-flaw-out-of-bounds-access</guid>
      <link>https://linuxsecurity.com/features/linux-ebpf-security-flaw-out-of-bounds-access</link>
      <title>Linux eBPF Security Flaw Could Approve an Out-of-Bounds Memory Access</title>
      <description>A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.</description>
      <pubDate>Fri, 18 Sep 2026 20:00:06 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/powerpc-kvm-nested-guest-use-after-free</guid>
      <link>https://linuxsecurity.com/features/powerpc-kvm-nested-guest-use-after-free</link>
      <title>How a PowerPC Guest Could Trigger a KVM Use-After-Free</title>
      <description>A PowerPC KVM use-after-free could leave the Linux host kernel accessing a nested-guest object after another virtual CPU caused that object to be removed and freed. The upstream Linux correction adds a missing reference that keeps the object alive while KVM invalidates cached address translations.</description>
      <pubDate>Thu, 17 Sep 2026 20:45:39 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-path-validation-symlink-race</guid>
      <link>https://linuxsecurity.com/features/linux-path-validation-symlink-race</link>
      <title>How a TOCTOU Race Condition Breaks Linux Path Validation</title>
      <description>A Linux path can be valid when a program checks it and point somewhere else when the program uses it. That gap creates a time-of-check to time-of-use, or TOCTOU race condition, whenever an untrusted process can change part of the directory tree between two separate lookups.</description>
      <pubDate>Thu, 17 Sep 2026 07:58:18 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-file-permissions-root-trust-boundary</guid>
      <link>https://linuxsecurity.com/features/linux-file-permissions-root-trust-boundary</link>
      <title>How Linux File Permissions Become a Root Trust Boundary</title>
      <description>Linux file permissions are usually introduced as a way to decide who may read, write, or execute a file. On a production server, they do something more important: they help decide which lower-privilege users can influence work later performed by root or another privileged service.</description>
      <pubDate>Thu, 17 Sep 2026 01:15:41 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/malicious-container-image-crun-linux-host</guid>
      <link>https://linuxsecurity.com/features/malicious-container-image-crun-linux-host</link>
      <title>Container Security Failure Could Let a Malicious Image Reach the Linux Host</title>
      <description>Container security can fail before a workload fully enters its root filesystem, the private file tree the container is meant to see.</description>
      <pubDate>Wed, 16 Sep 2026 10:31:07 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-smb-ownership-input-trust-boundaries</guid>
      <link>https://linuxsecurity.com/features/linux-smb-ownership-input-trust-boundaries</link>
      <title>Linux SMB Security Fixes Restore Ownership and Input-Trust Boundaries</title>
      <description>SMB, or Server Message Block, lets Linux systems access files shared over a network.</description>
      <pubDate>Wed, 16 Sep 2026 10:22:20 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-huge-page-reclaim-data-loss</guid>
      <link>https://linuxsecurity.com/features/linux-huge-page-reclaim-data-loss</link>
      <title>How Transparent Huge Pages Could Lose Rewritten Data During Reclaim</title>
      <description>Transparent huge pages let Linux manage memory in larger blocks for better performance.</description>
      <pubDate>Wed, 16 Sep 2026 10:16:05 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/sleepable-ebpf-btf-metadata-lifetime</guid>
      <link>https://linuxsecurity.com/features/sleepable-ebpf-btf-metadata-lifetime</link>
      <title>Why eBPF Security Depends on Matching Metadata Lifetimes</title>
      <description>eBPF lets verified programs run inside the Linux kernel. Linux eBPF security depends on supporting data remaining available for as long as those programs can use it.</description>
      <pubDate>Wed, 16 Sep 2026 10:07:46 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-encryption-strategy</guid>
      <link>https://linuxsecurity.com/features/linux-encryption-strategy</link>
      <title>Effective Encryption Strategies to Safeguard Your Online Identity</title>
      <description>In today’s world, almost every part of our lives is directly or indirectly linked to the Internet. As cyberattacks in network security grow more advanced, our sensitive data faces more risk. Knowing how to protect your online identity is now a necessity.</description>
      <pubDate>Mon, 27 Feb 2023 17:00:13 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-virtualization-vhost-memory-exhaustion</guid>
      <link>https://linuxsecurity.com/features/linux-virtualization-vhost-memory-exhaustion</link>
      <title>Linux Virtualization Fix Limits a Host Memory Exhaustion Path</title>
      <description>Linux virtualization lets a physical host run guest virtual machines. A fix in vhost, the Linux component that helps those guests exchange data with virtual devices, limits memory consumed by repeated requests for a missing memory mapping.</description>
      <pubDate>Fri, 11 Sep 2026 23:10:32 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-tls-traffic-confidential-vm-attestation</guid>
      <link>https://linuxsecurity.com/features/linux-tls-traffic-confidential-vm-attestation</link>
      <title>Linux Can Hold TLS Traffic Until a Confidential VM Proves Its State</title>
      <description>Confidential computing can protect a virtual machine’s memory from the host that runs it. A remote client still needs to check that its connection reaches the protected machine. Transport Layer Security, or TLS, encrypts the connection and checks the service’s identity, but does not by itself verify the machine’s software environment.</description>
      <pubDate>Fri, 11 Sep 2026 22:15:29 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-close-file-descriptors-filesystem-stall</guid>
      <link>https://linuxsecurity.com/features/linux-close-file-descriptors-filesystem-stall</link>
      <title>Why Linux Must Close File Descriptors Before a Filesystem Can Stall</title>
      <description>A file descriptor is the numbered handle a running program uses to access an open file or similar resource. Linux can mark it to close automatically when the program replaces itself through exec(). That cleanup can involve waiting for a filesystem, which makes its timing important.</description>
      <pubDate>Thu, 10 Sep 2026 19:30:12 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-sandbox-freed-parent-directory</guid>
      <link>https://linuxsecurity.com/features/linux-sandbox-freed-parent-directory</link>
      <title>Linux Sandbox Bug Could Read a Freed Parent Directory</title>
      <description>A Linux sandbox restricts which files a program can access. Landlock, a kernel facility that lets programs apply those restrictions to themselves, had a bug in the code checking file locations. A concurrent directory move could leave the check reading memory that had already been released.</description>
      <pubDate>Thu, 10 Sep 2026 19:10:40 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-kernel-testing-maccconc-race-conditions</guid>
      <link>https://linuxsecurity.com/features/linux-kernel-testing-maccconc-race-conditions</link>
      <title>New Linux Kernel Testing Tool Can Force Race Conditions</title>
      <description>Linux kernel testing can miss a bug when it depends on two tasks reaching the same data in an unusual order. These independently running tasks are called threads. A race condition occurs when their timing changes whether the code works correctly, which can make a failure difficult to reproduce. Google Project Zero published MAccConc on Sep 8, 2026 as a prototype that changes the timing itself. Its name is short for Memory Access Concurrency. The tool traces selected Linux kernel memory access...</description>
      <pubDate>Wed, 09 Sep 2026 20:30:32 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-privilege-escalation-rds-cleanup-bug</guid>
      <link>https://linuxsecurity.com/features/linux-privilege-escalation-rds-cleanup-bug</link>
      <title>Linux Privilege Escalation Exploit Uses an RDS Cleanup Bug</title>
      <description>A new Linux privilege escalation exploit shows how a cleanup mistake in Reliable Datagram Sockets, or RDS, can give a local user root access, meaning administrator control of the machine. RDS is a Linux kernel networking subsystem designed for low-latency communication between machines and processes.</description>
      <pubDate>Wed, 09 Sep 2026 20:10:12 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/ipv6-security-route-listing-freed-kernel-memory</guid>
      <link>https://linuxsecurity.com/features/ipv6-security-route-listing-freed-kernel-memory</link>
      <title>IPv6 Security Flaw Lets Route Listing Reach Freed Kernel Memory</title>
      <description>Listing network routes should tell administrators where traffic will go. An IPv6 security report instead shows Linux accessing a freed record used to keep track of that listing. A list of active readers still points to the record after cleanup releases it, so a later route change can reach invalid memory and crash the kernel.</description>
      <pubDate>Wed, 09 Sep 2026 19:45:29 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-multicast-tables-cgroup-memory-limits</guid>
      <link>https://linuxsecurity.com/features/linux-multicast-tables-cgroup-memory-limits</link>
      <title>Linux cgroup Memory Limits Can Miss Kernel Network Use</title>
      <description>A Linux cgroup, or control group, limits how much memory a group of processes can use. Yet its counters can look normal while those processes cause the host kernel, the core of the operating system, to use memory that is not counted against their limit. A networking patch posted on Sep 7, 2026 shows one way this can happen with IPv6 multicast routing, which sends network traffic to a group of recipients. The test creates routing tables inside namespaces: separate views of user identities and ...</description>
      <pubDate>Tue, 08 Sep 2026 19:15:39 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
    <item>
      <guid isPermaLink="true">https://linuxsecurity.com/features/linux-rpc-file-network-namespace-use-after-free</guid>
      <link>https://linuxsecurity.com/features/linux-rpc-file-network-namespace-use-after-free</link>
      <title>Linux NFS Control File Can Reach Freed Kernel Memory</title>
      <description>A program can keep a Linux file open even after the separate networking environment behind it has started shutting down. That environment is called a network namespace. A SUNRPC patch posted on Sep 7, 2026 describes that exact failure in the /proc/net/rpc/use-gss-proxy control used by Linux remote procedure call (RPC) servers, including Network File System (NFS), which lets computers access files over a network.</description>
      <pubDate>Tue, 08 Sep 2026 19:00:17 +0000</pubDate>
      <dc:creator>LinuxSecurity Editors</dc:creator>
      <category>features</category>
      <category>features</category>
      <source url="https://linuxsecurity.com">LinuxSecurity.com</source>
    </item>
  </channel>
</rss>
