Vulnerability Management, Patch/Configuration Management, Threat Intelligence![Closeup of a mobile phone screen with logo lettering of linux on computer keyboard](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/02/020724_linux.jpg)
CISA: Actively exploited Linux kernel flaw requires immediate remediation
![Closeup of a mobile phone screen with logo lettering of linux on computer keyboard](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/02/020724_linux.jpg)
(Adobe Stock)
Ongoing limited, targeted attacks leveraging the high-severity Linux kernel flaw, tracked as CVE-2024-53104, have prompted the Cybersecurity and Infrastructure Security Agency to urge federal agencies to address vulnerable Linux and Android devices by Feb. 26, BleepingComputer reports. Such a vulnerability — which stems from a USB Video Class driver out-of-bounds write issue that could be exploited for privilege escalation — may have been used by forensic data extraction tools, according to the GrapheneOS development team. Moreover, CISA warned that security flaws impacting the Linux kernel are prime targets for cyberattacks and pose significant risks to federal networks. Such a development comes after the inclusion of high- and critical severity Microsoft .NET Framework and Apache OFBiz flaw in CISA's Known Exploited Vulnerabilities catalog earlier this week, as well as the release of Five Eyes network edge device security guidelines urging manufacturers to improve forensic visibility in network edge devices to enhance attack detection and response.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds