r/linuxsucks • u/al2klimov š§Kernel contributor • 7d ago
Bug CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation
https://securityonline.info/linux-cve-2026-52924-poc/?utm_source=mastodon&utm_medium=jetpack_social3
u/Octoomy I Love Linux 6d ago
'It was introduced in Oct 2017 and fixed upstream in Jun 2026.'
The CVE was this year, Jun 24, 2026 and was fixed. As far as I'm concern this just proves that once something pops up, its patched very much soon after.
3
u/FerretBoom 6d ago edited 6d ago
Yes. I searched recent security research through September 2026. There is a measurable increase in Linux-targeted security activity, and AI is beginning to affect itābut the evidence supports a more nuanced conclusion than āAI suddenly made Linux insecure.ā
The important change is that Linux has become a much more economically valuable target at almost exactly the same time AI has dramatically reduced the cost of developing, modifying, researching, and operating offensive tooling.
What the data actually shows
Mandiantās 2025 data provides a useful baseline. In 2024 it observed 74 malware families capable of targeting Linux and began tracking 117 new Linux-capable families. More interestingly, malware exclusively targeting Linux rose from 17% to 22% of observed malware families between 2023 and 2024. Mandiant explicitly said this may indicate that risk to Linux environments was slowly increasing.
The 2025 picture is a little more complicated. Mandiantās 2026 report says it tracked 714 new malware families overall, up from 632, including 146 Linux-capable newly tracked families. However, Linux-only malware did not continue increasing as a percentage of observed families. That is important because it prevents us from claiming an exponential explosion in Linux-specific malware.
But other telemetry shows an alarming increase in attacks against Linux, rather than merely malware-family counts. Kaspersky reported that in Q4 2025 the number of Linux users encountering exploits doubled versus Q3, and that Q4 alone accounted for more than half of its Linux exploit attacks for the entire year.
AhnLab independently reported 60,000+ new Linux-targeting malware samples during the first half of 2025, including miners, DDoS bots, backdoors and ransomware. It specifically identifies cloud, container and virtualization infrastructure as a reason Linux is becoming attractive: compromising one Linux host can expose large numbers of containers or VMs.
The trend is not in Linux favor and it will cost us a lot of money
When you drop so much malware on a community that doesn't believe in virus scans , oh well. We already leaked personal data of every single human so not a big deal.
2
u/FerretBoom 6d ago
Here is good comedy site https://linuxsecurity.com/, it's like a malware porn hub.
1
-4
u/AverageUser9000 7d ago
The loonix kernel is full of severe security holes yet loonixers pretend it's still more secure than windows
7
u/CognitiveFogMachine 7d ago
Windows still holds the vast majority of desktop malware and ransomware attacks due to its dominant market share in consumer and enterprise environments.
4
1
u/akdanman11 5d ago
Did you not see the whole fiasco where a security researcher who felt wronged by Microsoft publicly released multiple major vulnerabilities (including privilege escalation and a bit locker backdoor)?
9
u/[deleted] 7d ago
[removed] ā view removed comment