The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week a Linux kernel vulnerability, tracked as , to its Known Exploited Vulnerabilities Catalog.
According to , FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the and address the vulnerabilities in their infrastructure.
The is a Linux Kernel privilege escalation vulnerability. The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
In September, researchers from AT&T Alien Labs discovered a new piece of stealthy Linux malware, dubbed Shikitega, that targets endpoints and IoT devices. The Shikitega infection chain leverages two Linux vulnerabilities for privilege escalation, the CVE-2021-3493 and CVE-2021-4034 (aka PwnKit).
US CISA also added to the catalog a recently disclosed vulnerability, tracked as CVE-2022-41352, that affects Zimbra Collaboration (ZCS).
CISA orders federal agencies to address both vulnerabilities by November 10, 2022.
Follow me on Twitter: and
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Linux)
[adrotate banner=”5″]
[adrotate banner=”13″]