news.mlab.sh
Back to the feed
threat-intel

Linux kernel team publishes 432 CVEs in two days

Medium
Summary

The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exploits targeting extensions and potential zero-day attacks against on-premise systems. The release underscores the continuous effort required to maintain a secure Linux environment.

The Linux kernel team has recently released a large batch of security vulnerabilities, totaling 432 CVEs over a short period. This indicates an active effort to address security concerns within the kernel. Specifically, vulnerabilities were found in extensions, leading to exploits targeting vulnerable Joomla websites. These flaws in iCagenda and Balbooa Forms extensions could impact a million sites utilizing the CMS that powers them. Furthermore, a zero-day attack is now targeting on-premise SharePoint, despite Microsoft’s patching efforts. The release also includes a new X11 server, implemented directly in assembly, joining existing servers like yserver, Phoenix, and XLibre. Finally, the Linux kernel team released Debian versions 13.6 and 12.15.

Read the full article at The Register