Collected every two hours from specialised publications — each link leads to the original article.
An update that fixes one vulnerability is now available.
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mu…
SUSE released a security update for kubevirt and related containers, addressing 16 vulnerabilities including risks of denial of service and privilege escalatio…
Ubuntu 16.04 LTS received security updates for the linux-aws-hwe kernel to correct several vulnerabilities that could allow local attackers to escalate privile…
Ubuntu Security Notice USN-8529-2 reveals multiple vulnerability fixes in the Linux kernel affecting Ubuntu 16.04 LTS, with local attackers potentially escalat…
Fedora has released an update for fuse-overlayfs to version 1.17, addressing a privilege escalation vulnerability related to SUID/SGID bit preservation on file…
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an …
An update for the moby-engine in Fedora 43 has been released, addressing upstream security vulnerabilities and introducing version 29.6.2, making Docker contai…
Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security restrictions or t…
Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any art…
Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in denial of service. For the oldstable dis…
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service or the execution of …
Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware cap…
Important: container-tools:rhel8 security update
Cybersecurity researchers have called attention to a "massive campaign" that has systematically targeted cloud native environments to set up malicious infrastr…
Multiple vulnerabilities were discovered in containerd, an open-source container runtime, used by e.g. Docker or Kubernetes. CVE-2024-25621 Overly broad defaul…
Two security vulnerabilities were discovered in the Containerd container runtime, which may result in denial of service or local privilege escalation. For the …
It was discovered that LXD, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability if unprivileged users are al…
It was discovered that Incus, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability unprivileged users are all…
A path traversal flaw in the Rust async-tar library has people looking harder at archive extraction security on Linux. Researchers are calling it TARmageddon, …
Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NV…
Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NV…