Linux kernel flaw opens root-only files to unprivileged users

https://image.theregister.com/1683625.jpg?imageId=1683625&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs

Another Linux kernel flaw has handed local unprivileged users a way to peek at files they should never be able to read, including root-only secrets such as SSH keys. The bug affects multiple LTS kernel lines from 5.10 upward, although a fix has already landed – and there is now a proposal for reducing the odds of similar surprises in future.

What FOSS analytics vendor Metabase memorably dubbed the strip-mining era of open source security continues. This time, the culprit is CVE-2026-46333, a local kernel vulnerability that lets an unprivileged user read files they should not be able to access, including those normally available only to root. An attacker who already has login access to an affected machine could therefore potentially grab SSH keys, password files, or other confidential credentials, as the KnightLiblog explains.

Despite its...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more

https://www.itvoice.in/wp-content/uploads/2026/05/Copy-of-Redington-2026-05-20T130604.690.jpg

Check Point Embarks on a Mission to Transform Network Security Management with its Agentic Network Security Orchestration Platform, to Replace Decades of Rule-Based Complexity

Check Point Software Technologies Ltd, a pioneer and global leader in cyber security solutions, today launched its Agentic Network Security Orchestration Platform, a purpose-built autonomous agent architecture that executes network security operations across enterprise environments, without requiring constant human intervention. The launch continues the company’s mission to fundamentally transform