Get the latest tech news

Federal Agency Warns (Patched) Critical Linux Vulnerability Being Actively Exploited


"The US Cybersecurity and Infrastructure Security Agency has added a critical security bug in Linux to its list of vulnerabilities known to be actively exploited in the wild," reported Ars Technica on Friday. "The vulnerability, tracked as CVE-2024-1086 and carrying a severity rating of 7.8 out of...

"The US Cybersecurity and Infrastructure Security Agency has added a critical security bug in Linux to its list of vulnerabilities known to be actively exploited in the wild," reported Ars Technica on Friday. It's the result of a use-after-free error, a class of vulnerability that occurs in software written in the C and C++ languages when a process continues to access a memory location after it has been freed or deallocated. A deep-dive write-up of the vulnerability reveals that these exploits provide "a very powerful double-free primitive when the correct code paths are hit."

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Federal agency

Federal agency

Related news:

News photo

Every US federal agency must hire a chief AI officer

News photo

Government Watchdog Hacked US Federal Agency To Stress-Test Its Cloud Security

News photo

A government watchdog hacked a US federal agency to stress-test its cloud security