The US Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalogue after confirming they are being actively exploited.
- What it is: Three flaws in the Linux kernel, including a race condition and an out-of-bounds write bug, are being used in real-world attacks.
- Who is affected: Businesses running Linux-based servers, network appliances, or infrastructure that has not been patched recently.
- What the risk is: Successful exploitation can lead to memory corruption and privilege escalation, giving an attacker deeper access to an affected system.
- What action is needed: Federal agencies overseas were given until today to remediate. Australian businesses running affected Linux systems should apply vendor patches as a priority.
If you are unsure whether any of your systems run on Linux, we can check for you and confirm patching status as part of your regular support.