These pages track how the distros and operating systems I have deployed are responding to specific vulnerabilities — which releases are patched, which are still exposed, and when the fixes shipped. Each tracker is updated twice daily with information from vendor advisories and other sources. Updates are continued until every tracked release has a fix.
tc flower filters with a
police action race the unserialized global qdisc rate-table list and refcount on an
unlocked classifier path, freeing a rate table still in use. An unprivileged local user
(via user namespaces) or a container holding CAP_NET_ADMIN escalates to root,
and a working exploit is public.
/dev/kvm is
world-accessible an unprivileged local user can trigger it too.
map regex match between
two capture references clobbers the PCRE captures, so the sizing and writing passes
disagree — giving an unauthenticated attacker both an overflow and a heap-pointer
leak, and with them pre-authentication remote code execution.
nla_len, letting an unprivileged local user escalate to root
on hosts running the OVS datapath with conntrack.
remove_waiter(), giving any unprivileged local user root — and an
unprivileged container an escape to the host.
/dev/kvm is
world-accessible.