⚡️ Linux Kernel just issued a single-fix security update for stable LTS branches, addressing CVE-2026-64560.
We were able to exploit the bug and independently confirm that it's serious.
The impact is kernel code execution and EoP from unpriveleged user with no CAPs/userns, io_uring disable + BPF JIT hardening. The use-after-free primitive is reliable despite the race (<1m to exploit).
No wild attacks were seen yet. They are likely, given our technical picture.
Majority of Android devices are affected. Exploitability on Android wasn't empirically confirmed yet.
Post #224
973

