By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: On dealing with security vulnerabilities in the Linux kernel
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Software > On dealing with security vulnerabilities in the Linux kernel
Software

On dealing with security vulnerabilities in the Linux kernel

News Room
Last updated: 2026/06/24 at 6:14 AM
News Room Published 24 June 2026
Share
On dealing with security vulnerabilities in the Linux kernel
SHARE

  1. On dealing with security vulnerabilities in the Linux kernel

    • Kernel: current or well-worn?

  2. Coordination is undesirable

  3. What are the distributors doing?

At the beginning of the year, security company Theori discovered a security hole in the Linux kernel that would later become known as “Copy Fail.” The vulnerability allowed unprivileged users to gain root privileges. Theori reported it to the kernel developers on March 23, and it was fixed in the current development branch of the kernel on April 1; a few days later, the kernel developers also ported the fixes to version branches 6.18 and 6.19. The Linux team responsible for this assigned a unique number for the vulnerability (CVE-2026-31431) and published a notice about it on April 22nd, which, among other things, referred to the fixes.

One might think that coordinated disclosure had been carried out optimally, but when Theori published Copy Fail and an example exploit in a very public manner on April 29th, many Linux distributions and their users were caught off guard: the kernels distributed by the distributions did not contain the fixes, nor did some of the “long-term” versions offered by the kernel team. Fixes for the latter were submitted on April 30th; Some distributions took significantly longer to deliver updated kernels and were busy putting together workarounds to patch up affected systems.

  • The “Copy Fail” case shows how a gap that was actually fixed became a security problem in the distributions.
  • Kernel developers and distributions don’t talk about how security-relevant individual bug fixes are.
  • The controversial question: Should you continually install new kernels or port bug fixes to old kernels?

As a result, Theori was criticized a lot. Not without good reason (more on that later), but Copy Fail was not an extraordinary failure, the cause of which can be blamed solely on Theori. The fact that there is a general crunch in the disclosure process surrounding kernel vulnerabilities became apparent just a few days after Copy Fail, when the vulnerabilities “Dirty Frag” and “Copy Fail 2” were published. Theori was not involved in either and in these two cases the public announcement was anything but smooth.

That was the excerpt from our heise Plus article “On dealing with security gaps in the Linux kernel”. With a heise Plus subscription you can read the entire article.



Unfortunately, this link is no longer valid.

Links to gifted items will be invalid if they are older than 7 days or have been accessed too often.


You need a heise+ package to read this article. Try it now for a week without obligation – without obligation!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article China’s patience with both China’s patience with both
Next Article Alibaba attacks US over military blacklist Alibaba attacks US over military blacklist
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

9 bad habits that developers can’t get rid of
9 bad habits that developers can’t get rid of
News
AI as a team member: How Claude Tag should now automate work on Slack
AI as a team member: How Claude Tag should now automate work on Slack
Gadget
Alibaba attacks US over military blacklist
Alibaba attacks US over military blacklist
Computing
China’s patience with both
China’s patience with both
Gaming

You Might also Like

Starting from South Korea: Tech and IT stocks have fallen significantly in some cases
Software

Starting from South Korea: Tech and IT stocks have fallen significantly in some cases

3 Min Read
Rail traffic stopped throughout Germany due to radio interference; UPDATE: Running again
Software

Rail traffic stopped throughout Germany due to radio interference; UPDATE: Running again

2 Min Read
VR Games Showcase Summer 2026: “Transformers” are coming to Meta Quest
Software

VR Games Showcase Summer 2026: “Transformers” are coming to Meta Quest

10 Min Read
Allcodube iPlay 70 Max Pro in the test: 13-inch tablet with LTE for just 210 euros
Software

Allcodube iPlay 70 Max Pro in the test: 13-inch tablet with LTE for just 210 euros

11 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?