{
  "platform": "FOSSWire",
  "service": "Autonomous FOSS & Linux Kernel CVE Threat Radar",
  "domain": "https://fosswire.org",
  "generated_at": "2026-10-11T11:46:00.533444+00:00",
  "metrics": {
    "total": 33,
    "critical": 5,
    "high": 4,
    "medium": 24,
    "subsystems_monitored": 4
  },
  "advisories": [
    {
      "cve_id": "ADV-FOSS-3932",
      "title": "Why TLP should not replace your internal information classification, (Sat, Oct 10th)",
      "title_tr": "Why TLP should not replace your internal information classification, (Sat, Oct 10th)",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether information may be shared further (and if so, how far)..",
      "summary": "The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether information may be shared further (and if so, how far).",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-10T09:11:34+00:00",
      "source": "SANS Internet Storm Center",
      "slug": "why-tlp-should-not-replace-your-internal-information-classif",
      "url": "/news/why-tlp-should-not-replace-your-internal-information-classif.html",
      "impact_score": 9.4
    },
    {
      "cve_id": "ADV-FOSS-6705",
      "title": "Stable Channel Update for ChromeOS / ChromeOS Flex",
      "title_tr": "Stable Channel Update for ChromeOS / ChromeOS Flex",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "The Stable channel is being updated to OS version 16805.33.0 (Browser version 154.0.8037.151) for most ChromeOS devices.",
      "summary": "The Stable channel is being updated to OS version 16805.33.0 (Browser version 154.0.8037.151) for most ChromeOS devices. If you find new issues, please let us know one of the following ways File a bug Visit our ChromeOS communities General: Chromebook Help Community Beta Specific: ChromeOS Beta Help Community Report an...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T23:46:54.569000+00:00",
      "source": "Google Chromium Engineering Releases",
      "slug": "stable-channel-update-for-chromeos-chromeos-flex",
      "url": "/news/stable-channel-update-for-chromeos-chromeos-flex.html",
      "impact_score": 8.8
    },
    {
      "cve_id": "ADV-FOSS-1879",
      "title": "Friday Squid Blogging: I Caught a Squid",
      "title_tr": "Friday Squid Blogging: I Caught a Squid",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA.",
      "summary": "On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA. We caught many cod (none of which we could keep), and a bunch of hake and mackerel (all of which we could keep). And…I caught a squid! Near as I can tell, it’s a longfin squid, sometimes called a Boston squid ( Doryteuthis (Amerigo) pealeii ). T...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T20:25:01+00:00",
      "source": "Bruce Schneier Security Affairs",
      "slug": "friday-squid-blogging-i-caught-a-squid",
      "url": "/news/friday-squid-blogging-i-caught-a-squid.html",
      "impact_score": 8.8
    },
    {
      "cve_id": "ADV-FOSS-9698",
      "title": "[$] Adding kernel control-flow-integrity checking to GCC",
      "title_tr": "[$] Adding kernel control-flow-integrity checking to GCC",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "While many developers are struggling to keep up with the flood of vulnerability reports, others are still focused on preventing those reports from happening in the first place.",
      "summary": "While many developers are struggling to keep up with the flood of vulnerability reports, others are still focused on preventing those reports from happening in the first place. Control-flow integrity (CFI) is the term for preventing (or at least detecting) exploits that divert the flow of control from its intended path...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T17:06:12+00:00",
      "source": "Linux Weekly News (LWN.net)",
      "slug": "adding-kernel-control-flow-integrity-checking-to-gcc",
      "url": "/news/adding-kernel-control-flow-integrity-checking-to-gcc.html",
      "impact_score": 7.7
    },
    {
      "cve_id": "ADV-FOSS-8150",
      "title": "USN-8911-1: Linux kernel (OEM) vulnerabilities",
      "title_tr": "USN-8911-1: Linux kernel (OEM) vulnerabilities",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Several security issues were discovered in the Linux kernel.",
      "summary": "Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - USB core drivers; - GFS2 file system; - OCFS...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T11:58:11+00:00",
      "source": "Ubuntu Security &amp; Release Notices",
      "slug": "usn-8911-1-linux-kernel-oem-vulnerabilities",
      "url": "/news/usn-8911-1-linux-kernel-oem-vulnerabilities.html",
      "impact_score": 8.7
    },
    {
      "cve_id": "CVE-2023-20585",
      "title": "USN-8887-3: Linux kernel vulnerabilities",
      "title_tr": "USN-8887-3: Linux kernel vulnerabilities",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers.",
      "summary": "It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585) Se...",
      "mitigation": "Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.",
      "published_at": "2026-10-09T08:38:46+00:00",
      "source": "Ubuntu Security &amp; Release Notices",
      "slug": "usn-8887-3-linux-kernel-vulnerabilities",
      "url": "/news/usn-8887-3-linux-kernel-vulnerabilities.html",
      "impact_score": 8.5
    },
    {
      "cve_id": "CVE-2022-3114",
      "title": "USN-8875-2: Linux kernel (NVIDIA) vulnerabilities",
      "title_tr": "USN-8875-2: Linux kernel (NVIDIA) vulnerabilities",
      "severity": "HIGH",
      "subsystem": "Linux Kernel Core",
      "threat_model": "It was discovered that the i.MX clock driver in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference.",
      "summary": "It was discovered that the i.MX clock driver in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-3114) Several security issues were d...",
      "mitigation": "Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.",
      "published_at": "2026-10-09T08:38:43+00:00",
      "source": "Ubuntu Security &amp; Release Notices",
      "slug": "usn-8875-2-linux-kernel-nvidia-vulnerabilities",
      "url": "/news/usn-8875-2-linux-kernel-nvidia-vulnerabilities.html",
      "impact_score": 8.6
    },
    {
      "cve_id": "ADV-FOSS-8124",
      "title": "ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)",
      "title_tr": "ISC Stormcast For Friday, October 9th, 2026 https://isc.sans.edu/podcastdetail/10130, (Fri, Oct 9th)",
      "severity": "HIGH",
      "subsystem": "Linux Kernel Core",
      "threat_model": "A security advisory reported by SANS Internet Storm Center exposes critical vulnerability vectors.",
      "summary": "A security advisory reported by SANS Internet Storm Center exposes critical vulnerability vectors. This assessment examines attack surface boundaries, privilege escalation paths, and defense-in-depth mitigations.",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T07:52:03+00:00",
      "source": "SANS Internet Storm Center",
      "slug": "isc-stormcast-for-friday-october-9th-2026-httpsiscsansedupod",
      "url": "/news/isc-stormcast-for-friday-october-9th-2026-httpsiscsansedupod.html",
      "impact_score": 8.1
    },
    {
      "cve_id": "CVE-2026-107314",
      "title": "PostgreSQL Official News 2026-10-07: PostgreSQL JDBC 42.7.14 Security update for multiple CVE&#x27;s",
      "title_tr": "PostgreSQL Official News 2026-10-07: PostgreSQL JDBC 42.7.14 Security update for multiple CVE&#x27;s",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "greSQL JDBC team has released a security release for 2 CVE's CVE-2026-107314 and the GitHub Security Advisory GHSA-rhp9-mr79-r74h and CVE-2026-107315 and the GitHub Security Advisory GHSA-f64h-wr5q-3qf3 See the release notes for details",
      "summary": "greSQL JDBC team has released a security release for 2 CVE's CVE-2026-107314 and the GitHub Security Advisory GHSA-rhp9-mr79-r74h and CVE-2026-107315 and the GitHub Security Advisory GHSA-f64h-wr5q-3qf3 See the release notes for details",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-09T00:00:00+00:00",
      "source": "PostgreSQL Official News",
      "slug": "postgresql-official-news-2026-10-07-postgresql-jdbc-42714-se",
      "url": "/news/postgresql-official-news-2026-10-07-postgresql-jdbc-42714-se.html",
      "impact_score": 9.9
    },
    {
      "cve_id": "ADV-FOSS-2556",
      "title": "How Technology Empowers—and Imperils—Dictators",
      "title_tr": "How Technology Empowers—and Imperils—Dictators",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs .",
      "summary": "This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs . Two weeks after Moscow’s full-scale invasion of Ukraine in March 2022, the Russian TV Channel One editor Marina Ovsyannikova burst onto the set of the evening newscast. She held up a hand-drawn sign behind the anchor’s head that rea...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-08T11:08:05+00:00",
      "source": "Bruce Schneier Security Affairs",
      "slug": "how-technology-empowersand-imperilsdictators",
      "url": "/news/how-technology-empowersand-imperilsdictators.html",
      "impact_score": 8.4
    },
    {
      "cve_id": "ADV-FOSS-9800",
      "title": "Apple’s Verified Photography System",
      "title_tr": "Apple’s Verified Photography System",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer.",
      "summary": "Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone. Other industry solutions require a photographer or institution to vouc...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-08T05:44:43+00:00",
      "source": "Bruce Schneier Security Affairs",
      "slug": "apples-verified-photography-system",
      "url": "/news/apples-verified-photography-system.html",
      "impact_score": 8.3
    },
    {
      "cve_id": "ADV-FOSS-2514",
      "title": "Dolphin Progress Report: Release 2609",
      "title_tr": "Dolphin Progress Report: Release 2609",
      "severity": "CRITICAL",
      "subsystem": "Hardware & Microcode",
      "threat_model": "Welcome to Dolphin 2609's accompanying Progress Report!",
      "summary": "Welcome to Dolphin 2609's accompanying Progress Report! Like everyone else, we've been doing our best to weather the Techpocalypse brought on by AI, but it's really come after us in the past few months. Our website has been up and down repeatedly lately, as our defenses are barely holding out under the endless bombardm...",
      "mitigation": "Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.",
      "published_at": "2026-10-08T02:39:22.834000+00:00",
      "source": "Dolphin GameCube &amp; Wii Emulator Blog",
      "slug": "dolphin-progress-report-release-2609",
      "url": "/news/dolphin-progress-report-release-2609.html",
      "impact_score": 7.9
    },
    {
      "cve_id": "ADV-FOSS-3020",
      "title": "What’s in the SOSS? Podcast #75 – S3E27 From Upstream to Downstream: Managing Open Source Risk in a Changing Regulatory Era with Vincent Danen",
      "title_tr": "What’s in the SOSS? Podcast #75 – S3E27 From Upstream to Downstream: Managing Open Source Risk in a Changing Regulatory Era with Vincent Danen",
      "severity": "CRITICAL",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Summary In this episode of What’s in the SOSS’ “Big Thoughts, Open Sources,” host CRob sits down with Vincent Danen, Vice President of Product Security at Red Hat, for a deep dive into the evolving landscape of open source vulnerability disclosure.",
      "summary": "Summary In this episode of What’s in the SOSS’ “Big Thoughts, Open Sources,” host CRob sits down with Vincent Danen, Vice President of Product Security at Red Hat, for a deep dive into the evolving landscape of open source vulnerability disclosure. Drawing on over two decades of open source security experience, Vincent...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-06T15:31:13+00:00",
      "source": "OpenSSF Supply Chain Security",
      "slug": "whats-in-the-soss-podcast-75-s3e27-from-upstream-to-downstre",
      "url": "/news/whats-in-the-soss-podcast-75-s3e27-from-upstream-to-downstre.html",
      "impact_score": 7.8
    },
    {
      "cve_id": "ADV-FOSS-4721",
      "title": "How to fix a bug in a fix",
      "title_tr": "How to fix a bug in a fix",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure.",
      "summary": "Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their ...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-06T07:00:00+00:00",
      "source": "Google Project Zero Research",
      "slug": "how-to-fix-a-bug-in-a-fix",
      "url": "/news/how-to-fix-a-bug-in-a-fix.html",
      "impact_score": 8.2
    },
    {
      "cve_id": "ADV-FOSS-5689",
      "title": "Kernel.org 6.18.55: longterm",
      "title_tr": "Kernel.org 6.18.55: longterm",
      "severity": "CRITICAL",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Version: 6.18.55 (longterm) Released: 2026-10-03 Source: linux-6.18.55.tar.xz PGP Signature: linux-6.18.55.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.18.55",
      "summary": "Version: 6.18.55 (longterm) Released: 2026-10-03 Source: linux-6.18.55.tar.xz PGP Signature: linux-6.18.55.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.18.55",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-03T10:41:11+00:00",
      "source": "Kernel.org Releases",
      "slug": "kernelorg-61855-longterm",
      "url": "/news/kernelorg-61855-longterm.html",
      "impact_score": 9.6
    },
    {
      "cve_id": "ADV-FOSS-4944",
      "title": "Summary of reading: July - September 2026",
      "title_tr": "Summary of reading: July - September 2026",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "\"Wuthering Heights\" by Emily Brontë - good writing, but the protagonists are quite something.",
      "summary": "\"Wuthering Heights\" by Emily Brontë - good writing, but the protagonists are quite something. There's barely a likable character in the whole story - they are all either crazy, evil, stupid or a combination of these. It's also remarkable to consider how small the world of some people in those times was (pre-Victorian E...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-10-01T19:38:41+00:00",
      "source": "Eli Bendersky Systems Programming",
      "slug": "summary-of-reading-july-september-2026",
      "url": "/news/summary-of-reading-july-september-2026.html",
      "impact_score": 9.6
    },
    {
      "cve_id": "ADV-FOSS-2664",
      "title": "OpenSSF Newsletter – September 2026",
      "title_tr": "OpenSSF Newsletter – September 2026",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "September brings a commitment to sustainable package registries, practical Cyber Resilience Act (CRA) guidance, new community security work, and three conversations on AI, regulation, and dependency risk.",
      "summary": "September brings a commitment to sustainable package registries, practical Cyber Resilience Act (CRA) guidance, new community security work, and three conversations on AI, regulation, and dependency risk. Join us in Prague for OpenSSF Community Day Europe on October 6. TL;DR Sustainable Package Registries → OpenSSF’s G...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-30T11:25:38+00:00",
      "source": "OpenSSF Supply Chain Security",
      "slug": "openssf-newsletter-september-2026",
      "url": "/news/openssf-newsletter-september-2026.html",
      "impact_score": 9.6
    },
    {
      "cve_id": "CVE-2026-94603",
      "title": "Podman Container Engine v6.1.3 Release",
      "title_tr": "Podman Container Engine v6.1.3 Release",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Security This release addresses CVE-2026-94603 , where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.",
      "summary": "Security This release addresses CVE-2026-94603 , where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created. Breaking Changes Removed support for checkpoin...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-29T15:34:46+00:00",
      "source": "Podman Container Engine",
      "slug": "podman-container-engine-v613-release",
      "url": "/news/podman-container-engine-v613-release.html",
      "impact_score": 9.6
    },
    {
      "cve_id": "CVE-2026-97024",
      "title": "Flatpak Sandboxed Applications 1.19.2 Release",
      "title_tr": "Flatpak Sandboxed Applications 1.19.2 Release",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "This is a development prerelease from the 1.19.x series.",
      "summary": "This is a development prerelease from the 1.19.x series. The first stable release from this branch will be 1.20.0. Changes in 1.19.2 Bug fixes: Use bubblewrap from our PPA in the CI pipeline for creating releases Changes in 1.19.1 Security fixes: Prevent privileged overwrite of arbitrary files with an empty file or a s...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-28T13:26:10+00:00",
      "source": "Flatpak Sandboxed Applications",
      "slug": "flatpak-sandboxed-applications-1192-release",
      "url": "/news/flatpak-sandboxed-applications-1192-release.html",
      "impact_score": 7.5
    },
    {
      "cve_id": "CVE-2026-97024",
      "title": "Flatpak Sandboxed Applications: flatpak 1.19.1",
      "title_tr": "Flatpak Sandboxed Applications: flatpak 1.19.1",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "This is a development prerelease from the 1.19.x series.",
      "summary": "This is a development prerelease from the 1.19.x series. The first stable release from this branch will be 1.20.0. Security fixes: Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgvf ; tha...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-28T12:58:23+00:00",
      "source": "Flatpak Sandboxed Applications",
      "slug": "flatpak-sandboxed-applications-flatpak-1191",
      "url": "/news/flatpak-sandboxed-applications-flatpak-1191.html",
      "impact_score": 7.6
    },
    {
      "cve_id": "ADV-FOSS-9802",
      "title": "Don't let TEEs break your MPC",
      "title_tr": "Don't let TEEs break your MPC",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs).",
      "summary": "Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-25T11:00:00+00:00",
      "source": "Trail of Bits Engineering Blog",
      "slug": "dont-let-tees-break-your-mpc",
      "url": "/news/dont-let-tees-break-your-mpc.html",
      "impact_score": 9.5
    },
    {
      "cve_id": "ADV-FOSS-8842",
      "title": "SAML: A fractal of bad design",
      "title_tr": "SAML: A fractal of bad design",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations.",
      "summary": "Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-21T11:00:00+00:00",
      "source": "Trail of Bits Engineering Blog",
      "slug": "saml-a-fractal-of-bad-design",
      "url": "/news/saml-a-fractal-of-bad-design.html",
      "impact_score": 7.6
    },
    {
      "cve_id": "CVE-2026-66804",
      "title": "Windows Exploitation Techniques: Dangling COM Object Registrations",
      "title_tr": "Windows Exploitation Techniques: Dangling COM Object Registrations",
      "severity": "HIGH",
      "subsystem": "Linux Kernel Core",
      "threat_model": "This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804 , that I and 14 others reported.",
      "summary": "This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804 , that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif . The root cause of the bug was a dangling COM object registration for the ...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-21T07:00:00+00:00",
      "source": "Google Project Zero Research",
      "slug": "windows-exploitation-techniques-dangling-com-object-registra",
      "url": "/news/windows-exploitation-techniques-dangling-com-object-registra.html",
      "impact_score": 9.3
    },
    {
      "cve_id": "ADV-FOSS-9987",
      "title": "GIMP GNU Image Manipulation Program: GIMP 3.2.6 Released",
      "title_tr": "GIMP GNU Image Manipulation Program: GIMP 3.2.6 Released",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "We’re happy to announce the release of GIMP 3.2.6 !",
      "summary": "We’re happy to announce the release of GIMP 3.2.6 ! This stable release contains several months worth of patches, bug fixes, security updates, and more from new and longtime contributors. Special thanks to Bruno Lopes , who has taken charge of backporting fixes from our development branch to the 3.2 stable branch. Gene...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-09T22:00:00+00:00",
      "source": "GIMP GNU Image Manipulation Program",
      "slug": "gimp-gnu-image-manipulation-program-gimp-326-released",
      "url": "/news/gimp-gnu-image-manipulation-program-gimp-326-released.html",
      "impact_score": 9.2
    },
    {
      "cve_id": "ADV-FOSS-8256",
      "title": "react-devtools@8.0.0: React DevTools 7.0.1 -> 8.0.0 (#37546)",
      "title_tr": "react-devtools@8.0.0: React DevTools 7.0.1 -> 8.0.0 (#37546)",
      "severity": "MEDIUM",
      "subsystem": "Userspace & System Services",
      "threat_model": "Summary Bump React DevTools from 7.0.1 to 8.0.0 (packages + extension manifests only; no publish).",
      "summary": "Summary Bump React DevTools from 7.0.1 to 8.0.0 (packages + extension manifests only; no publish). scripts/devtools/prepare-release.js only supports minor/patch, so this major bump is manual. Changelog is curated from DevTools commits since 7.0.1 (features vs bugfixes; internal/test-only changes omitted). Test plan Con...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-08T23:08:45+00:00",
      "source": "React GitHub Releases",
      "slug": "react-devtools800-react-devtools-701-800-37546",
      "url": "/news/react-devtools800-react-devtools-701-800-37546.html",
      "impact_score": 8.0
    },
    {
      "cve_id": "ADV-FOSS-7279",
      "title": "Testing race conditions with memory access tracing and stack-based delay injection",
      "title_tr": "Testing race conditions with memory access tracing and stack-based delay injection",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear.",
      "summary": "Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis. Regression tests: After fixing a race c...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-09-08T07:00:00+00:00",
      "source": "Google Project Zero Research",
      "slug": "testing-race-conditions-with-memory-access-tracing-and-stack",
      "url": "/news/testing-race-conditions-with-memory-access-tracing-and-stack.html",
      "impact_score": 8.9
    },
    {
      "cve_id": "ADV-FOSS-5278",
      "title": "GE-Proton Custom (GloriousEggroll): GE-Proton11-6 Released",
      "title_tr": "GE-Proton Custom (GloriousEggroll): GE-Proton11-6 Released",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Wine-Wayland Changes Updated the Wine bleeding-edge base twice and imported/rebased the latest EM11 Wine-Wayland series: 3e5f91e ( 3e5f91e ), 0c63e18 ( 0c63e18 ), 061e2df (.",
      "summary": "Wine-Wayland Changes Updated the Wine bleeding-edge base twice and imported/rebased the latest EM11 Wine-Wayland series: 3e5f91e ( 3e5f91e ), 0c63e18 ( 0c63e18 ), 061e2df ( 061e2df ), 09b1a37 ( 09b1a37 ). Original EM11/Wine authorship remains preserved in each patch. Imported Wine-Wineland’s 58-patch cross-process DMA-...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-08-28T21:39:40+00:00",
      "source": "GE-Proton Custom (GloriousEggroll)",
      "slug": "ge-proton-custom-gloriouseggroll-ge-proton11-6-released",
      "url": "/news/ge-proton-custom-gloriouseggroll-ge-proton11-6-released.html",
      "impact_score": 8.4
    },
    {
      "cve_id": "ADV-FOSS-2501",
      "title": "Minetest / Luanti Voxel Engine: Luanti 5.17.0",
      "title_tr": "Minetest / Luanti Voxel Engine: Luanti 5.17.0",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Check the changelog here . Warning This release fixes critical security vulnerabilities affecting both the client and server. We advise everyone to upgrade immediately .",
      "summary": "Check the changelog here . Warning This release fixes critical security vulnerabilities affecting both the client and server. We advise everyone to upgrade immediately .",
      "mitigation": "Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.",
      "published_at": "2026-08-22T02:18:51+00:00",
      "source": "Minetest / Luanti Voxel Engine",
      "slug": "minetest-luanti-voxel-engine-luanti-5170",
      "url": "/news/minetest-luanti-voxel-engine-luanti-5170.html",
      "impact_score": 9.7
    },
    {
      "cve_id": "ADV-FOSS-8578",
      "title": "Hyprland Wayland Compositor v0.56.2 Release",
      "title_tr": "Hyprland Wayland Compositor v0.56.2 Release",
      "severity": "MEDIUM",
      "subsystem": "Hardware & Microcode",
      "threat_model": "A standard patch release backporting some fixes from main on top of 0.56.2.",
      "summary": "A standard patch release backporting some fixes from main on top of 0.56.2. Fixes backported algo/scrolling: fix unFSing window sticking to the left corner instead of respecting focus_fit_method ( ) config: fix duplicate config value crash ( ) core/fullscreen: allow layout managed fullscreens to not block seeking windo...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-08-05T14:14:25+00:00",
      "source": "Hyprland Wayland Compositor",
      "slug": "hyprland-wayland-compositor-v0562-release",
      "url": "/news/hyprland-wayland-compositor-v0562-release.html",
      "impact_score": 8.6
    },
    {
      "cve_id": "ADV-FOSS-8077",
      "title": "Join the Python Security Response Team!",
      "title_tr": "Join the Python Security Response Team!",
      "severity": "MEDIUM",
      "subsystem": "Linux Kernel Core",
      "threat_model": "Thanks to the work of the Security Developer-in-Residence Seth Larson, the Python Security Response Team (PSRT) now has an approved public governance document (PEP 811).",
      "summary": "Thanks to the work of the Security Developer-in-Residence Seth Larson, the Python Security Response Team (PSRT) now has an approved public governance document (PEP 811). Following the new governance structure the PSRT now publishes a public list of members , has documented responsibilities for members and admins , and ...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2026-02-17T07:30:00+00:00",
      "source": "Python Insider Core Releases",
      "slug": "join-the-python-security-response-team",
      "url": "/news/join-the-python-security-response-team.html",
      "impact_score": 9.2
    },
    {
      "cve_id": "ADV-FOSS-2830",
      "title": "Helix Post-Modern Modal Text Editor 25.07.1 Release",
      "title_tr": "Helix Post-Modern Modal Text Editor 25.07.1 Release",
      "severity": "CRITICAL",
      "subsystem": "Memory Safety & Runtimes",
      "threat_model": "This is a patch release which lowers the GLIBC requirements of the release artifacts published to GitHub.",
      "summary": "This is a patch release which lowers the GLIBC requirements of the release artifacts published to GitHub.",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2025-07-18T15:13:54+00:00",
      "source": "Helix Post-Modern Modal Text Editor Releases",
      "slug": "helix-post-modern-modal-text-editor-25071-release",
      "url": "/news/helix-post-modern-modal-text-editor-25071-release.html",
      "impact_score": 9.4
    },
    {
      "cve_id": "ADV-FOSS-2636",
      "title": "Enable MTE on Pixel 8",
      "title_tr": "Enable MTE on Pixel 8",
      "severity": "HIGH",
      "subsystem": "Linux Kernel Core",
      "threat_model": "The Pixel 8 hardware (Tensor G3) supports the ARM Memory Tagging Extension (MTE), and software support is available both in Android userspace and the Linux kernel.",
      "summary": "The Pixel 8 hardware (Tensor G3) supports the ARM Memory Tagging Extension (MTE), and software support is available both in Android userspace and the Linux kernel. This feature is a powerful defense against linear buffer overflows and many types of use-after-free flaws. I’m extremely happy to see this hardware finally ...",
      "mitigation": "Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.",
      "published_at": "2023-10-26T19:19:46+00:00",
      "source": "Kees Cook (Linux Kernel Security)",
      "slug": "enable-mte-on-pixel-8",
      "url": "/news/enable-mte-on-pixel-8.html",
      "impact_score": 9.4
    },
    {
      "cve_id": "ADV-FOSS-9918",
      "title": "Kees Cook (Linux Kernel Security): finding binary differences",
      "title_tr": "Kees Cook (Linux Kernel Security): finding binary differences",
      "severity": "CRITICAL",
      "subsystem": "Linux Kernel Core",
      "threat_model": "As part of the continuing work to replace 1-element arrays in the Linux kernel, it’s very handy to show that a source change has had no executable code difference.",
      "summary": "As part of the continuing work to replace 1-element arrays in the Linux kernel, it’s very handy to show that a source change has had no executable code difference. For example, if you started with this: struct foo { unsigned long flags; u32 length; u32 data[1]; }; void foo_init(int count) { struct foo *instance; size_t...",
      "mitigation": "Vendor and kernel mainline patches published. Backported to active LTS channels.",
      "published_at": "2022-06-24T20:11:48+00:00",
      "source": "Kees Cook (Linux Kernel Security)",
      "slug": "kees-cook-linux-kernel-security-finding-binary-differences",
      "url": "/news/kees-cook-linux-kernel-security-finding-binary-differences.html",
      "impact_score": 8.6
    }
  ]
}