[Autonomous Security Intelligence]

Linux Kernel & FOSS CVE Threat Radar

Real-time telemetry and architectural threat modeling covering the Linux kernel, eBPF, io_uring, WireGuard network isolation, hardware vulnerabilities, and upstream security disclosures.

36 Active Events
7 Critical
4 High Severity
25 Medium
4 Subsystems
ADV-FOSS-2502 CRITICAL Linux Kernel Core
2026-10-10 • Phoronix Benchmarks & Drivers

Rolling Release Distros Superior To LTS Distros In The Patch-Heavy GenAI Era?

Architectural Threat Model

As some interesting food for thought and weekend forum discussions, this week at the Linux Plumbers Conference in Prague, Qualcomm engineer Khem Raj questioned the relevance of.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-6624 MEDIUM Linux Kernel Core
2026-10-10 • SANS Internet Storm Center

Why TLP should not replace your internal information classification, (Sat, Oct 10th)

Architectural Threat Model

The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether information may be shared further (and if so, how far)..

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-7814 MEDIUM Linux Kernel Core
2026-10-09 • Google Chromium Engineering Releases

Stable Channel Update for ChromeOS / ChromeOS Flex

Architectural Threat Model

The Stable channel is being updated to OS version 16805.33.0 (Browser version 154.0.8037.151) for most ChromeOS devices.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-9456 MEDIUM Linux Kernel Core
2026-10-09 • Bruce Schneier Security Affairs

Friday Squid Blogging: I Caught a Squid

Architectural Threat Model

On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-5201 MEDIUM Linux Kernel Core
2026-10-09 • Linux Weekly News (LWN.net)

[$] Adding kernel control-flow-integrity checking to GCC

Architectural Threat Model

While many developers are struggling to keep up with the flood of vulnerability reports, others are still focused on preventing those reports from happening in the first place.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

CVE-2023-20585 MEDIUM Linux Kernel Core
2026-10-09 • Ubuntu Security & Release Notices

USN-8887-3: Linux kernel vulnerabilities

Architectural Threat Model

It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers.

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

CVE-2022-3114 HIGH Linux Kernel Core
2026-10-09 • Ubuntu Security & Release Notices

USN-8875-2: Linux kernel (NVIDIA) vulnerabilities

Architectural Threat Model

It was discovered that the i.MX clock driver in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference.

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

CVE-2026-107314 MEDIUM Linux Kernel Core
2026-10-09 • PostgreSQL Official News

PostgreSQL Official News 2026-10-07: PostgreSQL JDBC 42.7.14 Security update for multiple CVE's

Architectural Threat Model

greSQL JDBC team has released a security release for 2 CVE's CVE-2026-107314 and the GitHub Security Advisory GHSA-rhp9-mr79-r74h and CVE-2026-107315 and the GitHub Security Advisory GHSA-f64h-wr5q-3qf3 See the release notes for details

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-3319 MEDIUM Linux Kernel Core
2026-10-08 • Bruce Schneier Security Affairs

Apple’s Verified Photography System

Architectural Threat Model

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-7629 CRITICAL Hardware & Microcode
2026-10-08 • Dolphin GameCube & Wii Emulator Blog

Dolphin Progress Report: Release 2609

Architectural Threat Model

Welcome to Dolphin 2609's accompanying Progress Report!

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

ADV-FOSS-4119 CRITICAL Linux Kernel Core
2026-10-06 • OpenSSF Supply Chain Security

What’s in the SOSS? Podcast #75 – S3E27 From Upstream to Downstream: Managing Open Source Risk in a Changing Regulatory Era with Vincent Danen

Architectural Threat Model

Summary In this episode of What’s in the SOSS’ “Big Thoughts, Open Sources,” host CRob sits down with Vincent Danen, Vice President of Product Security at Red Hat, for a deep dive into the evolving landscape of open source vulnerability disclosure.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-9279 MEDIUM Linux Kernel Core
2026-10-06 • Google Project Zero Research

How to fix a bug in a fix

Architectural Threat Model

Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-4682 CRITICAL Linux Kernel Core
2026-10-03 • Kernel.org Releases

Kernel.org 6.18.55: longterm

Architectural Threat Model

Version: 6.18.55 (longterm) Released: 2026-10-03 Source: linux-6.18.55.tar.xz PGP Signature: linux-6.18.55.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.18.55

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-3941 MEDIUM Linux Kernel Core
2026-10-01 • Eli Bendersky Systems Programming

Summary of reading: July - September 2026

Architectural Threat Model

"Wuthering Heights" by Emily Brontë - good writing, but the protagonists are quite something.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-4772 MEDIUM Linux Kernel Core
2026-09-30 • OpenSSF Supply Chain Security

OpenSSF Newsletter – September 2026

Architectural Threat Model

September brings a commitment to sustainable package registries, practical Cyber Resilience Act (CRA) guidance, new community security work, and three conversations on AI, regulation, and dependency risk.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

CVE-2026-94603 MEDIUM Linux Kernel Core
2026-09-29 • Podman Container Engine

Podman Container Engine v6.1.3 Release

Architectural Threat Model

Security This release addresses CVE-2026-94603 , where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-4648 CRITICAL Linux Kernel Core
2026-09-28 • GitHub Security Lab Advisories

How we found 24 Android vulnerabilities using our open source AI security agent

Architectural Threat Model

With the rise of AI in the security space, our team created the GitHub Security Lab Taskflow Agent as a way for security researchers to easily automate, package, and share the AI prompts and workflows that they find effective for their work.

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

ADV-FOSS-2140 MEDIUM Linux Kernel Core
2026-09-25 • Trail of Bits Engineering Blog

Don't let TEEs break your MPC

Architectural Threat Model

Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs).

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-7695 MEDIUM Linux Kernel Core
2026-09-21 • Trail of Bits Engineering Blog

SAML: A fractal of bad design

Architectural Threat Model

Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-3488 MEDIUM Linux Kernel Core
2026-08-28 • GE-Proton Custom (GloriousEggroll)

GE-Proton Custom (GloriousEggroll): GE-Proton11-6 Released

Architectural Threat Model

Wine-Wayland Changes Updated the Wine bleeding-edge base twice and imported/rebased the latest EM11 Wine-Wayland series: 3e5f91e ( 3e5f91e ), 0c63e18 ( 0c63e18 ), 061e2df (.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-2948 MEDIUM Linux Kernel Core
2026-08-22 • Minetest / Luanti Voxel Engine

Minetest / Luanti Voxel Engine: Luanti 5.17.0

Architectural Threat Model

Check the changelog here . Warning This release fixes critical security vulnerabilities affecting both the client and server. We advise everyone to upgrade immediately .

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

ADV-FOSS-8320 MEDIUM Hardware & Microcode
2026-08-05 • Hyprland Wayland Compositor

Hyprland Wayland Compositor v0.56.2 Release

Architectural Threat Model

A standard patch release backporting some fixes from main on top of 0.56.2.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-9630 MEDIUM Linux Kernel Core
2026-02-17 • Python Insider Core Releases

Join the Python Security Response Team!

Architectural Threat Model

Thanks to the work of the Security Developer-in-Residence Seth Larson, the Python Security Response Team (PSRT) now has an approved public governance document (PEP 811).

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-2257 CRITICAL Memory Safety & Runtimes
2025-07-18 • Helix Post-Modern Modal Text Editor Releases

Helix Post-Modern Modal Text Editor 25.07.1 Release

Architectural Threat Model

This is a patch release which lowers the GLIBC requirements of the release artifacts published to GitHub.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.

ADV-FOSS-2070 HIGH Linux Kernel Core
2023-10-26 • Kees Cook (Linux Kernel Security)

Enable MTE on Pixel 8

Architectural Threat Model

The Pixel 8 hardware (Tensor G3) supports the ARM Memory Tagging Extension (MTE), and software support is available both in Android userspace and the Linux kernel.

Mitigation & Upstream Status

Upstream security patch merged into stable mainline branch. System operators are advised to update package packages and verify user namespace configuration.

ADV-FOSS-3466 CRITICAL Linux Kernel Core
2022-06-24 • Kees Cook (Linux Kernel Security)

Kees Cook (Linux Kernel Security): finding binary differences

Architectural Threat Model

As part of the continuing work to replace 1-element arrays in the Linux kernel, it’s very handy to show that a source change has had no executable code difference.

Mitigation & Upstream Status

Vendor and kernel mainline patches published. Backported to active LTS channels.