Articles from April 2026
Browse all Windows news articles published in April 2026
Microsoft Flags Linux Kernel Panic Bug CVE-2026-31507 in WSL — Update Now
Microsoft’s Security Response Center has published an advisory for CVE-2026-31507, a Linux kernel vulnerability that can crash a system with a repeated tee operation on SMC network data. The bug...
CVE-2026-31485: A Tiny Linux Kernel Bug with Big Consequences for Embedded Systems
A routine software teardown should never crash a system. But a newly published Linux kernel vulnerability (CVE-2026-31485) shows how a subtle race condition in a widely used SPI driver can do exactly...
Phantom Subvolumes Haunt Btrfs: How a Late Flag Exposes Linux Systems to Deletion Failures and Aborts
Linux maintainers have published CVE-2026-31519, a flaw in the Btrfs filesystem that can turn perfectly healthy subvolumes into ghostly entries—visible to ls but absent to stat, resistant to...
Microsoft Flags Linux Kernel Flaw That Leaves Btrfs Subvolumes Stuck in a Half‑Present State
{ "title": "Microsoft Flags Linux Kernel Flaw That Leaves Btrfs Subvolumes Stuck in a Half‑Present State", "content": "On April 22, 2026, Microsoft’s Security Response Center published a...
Linux ext4 Filesystem Teardown Bug Can Crash Systems—Here’s the Fix
A use-after-free vulnerability in Linux’s ext4 filesystem can trigger during unmount, potentially causing kernel crashes or instability on systems from laptops to cloud servers. Tracked as...
Linux Kernel Squashes ext4 Use-After-Free Bug That Can Crash WSL and VMs
Linux kernel maintainers have released patches for CVE-2026-31446, a use-after-free vulnerability in the ext4 filesystem’s sysfs teardown path that can trigger system crashes during unmount or...
Linux ext4 vulnerability exposes systems to memory data leaks via crafted filesystems
Linux administrators received a fresh reminder this week that ext4’s maturity does not make it immune to memory-safety bugs. CVE-2026-31449 is a slab-out-of-bounds read in the Linux kernel’s ext4...
CVE-2026-31510: Linux Bluetooth Stack Fix Prevents Null Pointer Dereference in L2CAP
Linux has published another Bluetooth kernel fix that looks small on the surface but matters for anyone tracking availability and stability risks in the network stack. CVE-2026-31510 covers a...
CVE-2026-31449: Ext4 Bounds Check Fix Prevents Slab Out-of-Bounds Reads in Linux Kernel
A newly disclosed vulnerability in the Linux kernel's Ext4 filesystem, tracked as CVE-2026-31449, has been patched to prevent slab out-of-bounds (OOB) reads. The flaw, which carries a moderate...
Linux Bluetooth L2CAP NULL Pointer Bug Lets Attackers Crash Kernel Remotely
A newly published CVE record, CVE-2026-31510, details a critical NULL pointer dereference vulnerability in the Linux kernel's Bluetooth L2CAP implementation. The bug resides in the...
CVE-2026-31489: Linux Kernel's meson-spicc Driver Double-Put Bug Poses Stability Risk
A newly published Linux kernel vulnerability, CVE-2026-31489, has drawn attention for a classic reference-counting mistake in the Amlogic Meson SPI controller driver (meson-spicc). The bug, which...
Linux Kernel Patch CVE-2026-31431 Defaults to Safer Crypto Mode, Fixes Data Leak Bug
The Linux kernel has released a security fix addressing CVE-2026-31431, a vulnerability in the algif_aead cryptographic subsystem. The patch, which modifies the AF_ALG interface for AEAD ciphers,...