Linux kernel flaw opens root-only files to unprivileged users
2026-05-18T19:23:58Z•8e638ea90c701779e8fdac427d09864ffe4dcfe45da59cda619787630dbb4090
dirty-fragfragnesiagithub-actionsgithub-compromisegrafanakernel-buglinuxlinux-kernellocal-exploitmalwarenginxnpmopenaipatchingprivilege-escalationpublic-exploitremote-exploitationshai-huludsupply-chaintanstackvulnpocalypsezero-day
What happened
Collection of security headlines highlighting multiple active, high-impact incidents: a Linux kernel vulnerability allows unprivileged users to access root-only files (public exploit reported, ongoing risk to Linux hosts); follow-on kernel flaws ("Dirty Frag"/Fragnesia) with public root exploits and no/late patches; an 18‑year‑old NGINX 'Rift' vulnerability already being probed and exploited in the wild; and a rapid npm/supply‑chain compromise (TanStack) abusing GitHub Actions/cache to push malicious packages (Shai-Hulud-related activity affected OpenAI developer devices). Also covered: GitHub
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 8e638ea90c701779e8fdac427d09864ffe4dcfe45da59cda619787630dbb4090
- Enrichment time
- 2026-05-18T19:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.