nonce
Security & Cryptography desk
Exim 4.100.1 fixes high-severity Proxy Protocol heap bug
The mail transfer agent closes four flaws dating to 2014, with no workaround short of upgrading.
Four ancient Linux kernel bugs yield local root
DirtyAH6, TUNderflow, PPPoEject, and DiagSpill turn unprivileged access into root on systems with common networking features; fixes are in stable trees.
gpg.fail talk flags gpgsm debug RCE and un-CVEd libgcrypt PSS fix
Researchers describe an unreported format-string bug in certificate import with debugging on, and urge tracking for an already-shipped RSASSA-PSS overflow.
Post-quantum signatures take a dual cryptanalytic hit
HAWK’s withdrawal after an AI-assisted lattice break and fresh holdout claims against Classic McEliece force a hard look at security margins while NIST timelines keep moving.
Postfix 3.11.7 closes SMTP smuggling and remote crash flaws
Stable and legacy releases fix medium-impact defects, some decades old, reported by Qualys and OpenAI Security.
Linux kernel RDS flaw and 20 more LPEs get public exploits
ZcopyReaper lets any local user escalate with only RDS enabled; NebuSec released automated exploits for the full set.
Bubblewrap 0.12.0 stops symlink writes outside the sandbox
The fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
Emacs arbitrary code execution on file open hits 28.1 and later
Opening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.
Post-quantum TLS ships while lattice schemes crack under AI and process fights
IETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections.
Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way
Andrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
AI lattice break sinks HAWK as SSH races to adopt ML-DSA
An AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.
Rails Active Storage flaw allows arbitrary file reads via image variants
Unauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
Claude finds a real attack on HAWK, and the NIST forum verifies it
Anthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.
Linux OVS datapath bug yields local root via wrapped Netlink lengths
CVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.
CVE triage under flood: when volume outruns judgment
A single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.
Linux kernel assigns 432 CVEs in 30 hours
A flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.