Fetching from the wire…
Security2026-04-30 · source-backed
A privilege escalation in the kernel's algif_aead module (CVSS 7.8) lets any unprivileged local user get root. Deterministic exploit. No race conditions, no kernel offsets. The flaw traces to a 2017 commit enabling page-cache pages in writable scatterlists. Patches haven't shipped from any major distro yet. Disable the algif_aead module now: echo "install algif_aead /bin/true" >> /etc/modprobe.d/disable-algif-aead.conf. Check back daily for vendor patches.
Each link below shares sources, entities, or timing with this story.
Claude Code supports Linux / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code supports Linux); both cover CVE, CVSS; overlapping topics (check, cvss).
Linked by a graph relationship (Claude Code supports Linux); both cover CVE, CVSS; overlapping topics (check, cvss).
OpenHands uses Python / Shared entity: Check / What happened next
Linked by a graph relationship (OpenHands uses Python); both cover Check; picks up the Check thread on 2026-05-19.
JAI uses Linux / Shared entity: Linux / Earlier coverage
Linked by a graph relationship (JAI uses Linux); both cover Linux; earlier Linux coverage from 2026-03-28.
Claude Code supports Linux / Shared entities / What happened next
Linked by a graph relationship (Claude Code supports Linux); both cover CVE, CVSS; picks up the CVE thread on 2026-08-09.
Linked by a graph relationship (Claude Code supports Linux); both cover Check, Linux; picks up the Check thread on 2026-08-07.
Linked by a graph relationship (Claude Code supports Linux); both cover CVE, CVSS; picks up the CVE thread on 2026-05-24.
Linked by a graph relationship (Claude Code supports Linux); both cover Check, CVSS; picks up the Check thread on 2026-05-20.