kimmo.cloud


These pages track how the distros and operating systems I have deployed are responding to specific vulnerabilities — which releases are patched, which are still exposed, and when the fixes shipped. Each tracker is updated twice daily with information from vendor advisories and other sources. Updates are continued until every tracked release has a fix.

Linux Kernel

CVE-2026-68138
Linux kernel net/sched use-after-free: concurrent tc flower filters with a police action race the unserialized global qdisc rate-table list and refcount on an unlocked classifier path, freeing a rate table still in use. An unprivileged local user (via user namespaces) or a container holding CAP_NET_ADMIN escalates to root, and a working exploit is public.
CVE-2026-64564 — SCTPhantom
Linux kernel SCTP use-after-free: a crafted ASCONF chunk carrying an out-of-order DEL-IP frees the association's own cached transport, then a wildcard DEL-IP reuses the dangling pointer. Triggerable by a remote SCTP peer, and demonstrated as local privilege escalation and container-to-host escape.
CVE-2026-64561 — Zapscape
Linux kernel KVM/x86 shadow-MMU flaw: the page-fault handler could populate an invalidated shadow root, corrupting page-table bookkeeping. A malicious guest with nested virtualization can escape to root on the host, and where /dev/kvm is world-accessible an unprivileged local user can trigger it too.

Applications

CVE-2026-42533 — nginx map/regex capture clobbering
nginx two-pass script-engine heap buffer overflow: a map regex match between two capture references clobbers the PCRE captures, so the sizing and writing passes disagree — giving an unauthenticated attacker both an overflow and a heap-pointer leak, and with them pre-authentication remote code execution.

Recently Archived

CVE-2026-64531 — OVSwrap
Linux kernel Open vSwitch datapath integer overflow: an oversized nested action stream wraps the 16-bit nla_len, letting an unprivileged local user escalate to root on hosts running the OVS datapath with conntrack.
CVE-2026-43499 — GhostLock
Linux kernel rtmutex/futex requeue-PI stack use-after-free in remove_waiter(), giving any unprivileged local user root — and an unprivileged container an escape to the host.
CVE-2026-53359 — Januscape
Linux kernel KVM/x86 shadow-MMU use-after-free enabling a guest-to-host escape to root on Intel and AMD; also a local crash or privilege escalation where /dev/kvm is world-accessible.

All archived trackers