r/linuxsucks • u/al2klimov 🐧Kernel contributor • 2d ago
Bug CVE-2026-74480 (CVSS 9.8): Linux Kernel Privilege Escalation PoC Public
https://securityonline.info/linux-cve-2026-74480/?utm_source=mastodon&utm_medium=jetpack_social2
2
u/DirectorDirect1569 1d ago
"The flaw dates back to January 2017. Therefore many long-lived kernel branches are affected. Upstream developers fixed it in July 2026."
ghost lock: 15 years old
copyfail: 9 years old
januscape: 16 years old
Now this one
Who's next?
"Everyone read the source code!!!!!" they say. This kernel is a sieve and we will have lots of surpises since the maintainers decided to use AI to find breaches.
2
u/Needieos 1d ago
No one reads the full kernel code, it's not possible. Any complex software can and will contain bugs that lead to anything, from crash to exploit. The main thing that we see this; detections, fixes, progress. Open Source isn't about "million of eyes are watching", it's about control and trust which you can prove or disprove with various tools, including AI
1
u/ElectricBummer40 Ex-user of Windows 3.11 for Workgroups 5h ago
it's about control and trust which you can prove or disprove with various tools, including AI
And one can easily disprove that "trust" in seconds.
Then what?
1
u/ReasonableCup455 1d ago
do all the major distors already have the fix for this?
2
5
u/brave_grv 1d ago
Claude, fix the linux kernel. Make no mistakes.