Kernel Security
The latest Kernel Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-60708: Critical Hyper-V DoS Vulnerability in Storvsp.sys Driver
Microsoft has confirmed a critical denial-of-service vulnerability in the Storvsp.sys storage Virtualization Service Provider (VSP) driver, tracked as CVE-2025-60708, that enables locally...
EDR-Redir V2 Exploits Windows Bind Links to Blind Security Tools
A new proof-of-concept tool called EDR-Redir V2 is demonstrating how attackers can exploit Windows' bind link facility and cloud filter stack to create sophisticated filesystem redirections that...
CVE-2025-40051: Linux Kernel vhost vringh Patch Fixes Critical Memory Corruption Vulnerability
The Linux kernel development team has addressed a significant security vulnerability designated CVE-2025-40051, which affects the vhost/vringh subsystem and could lead to memory corruption, privilege...
Linux Kernel Patch Fixes CVE-2025-40060 CoreSight TRBE Crash Risk
A critical vulnerability in the Linux kernel's CoreSight Trace Buffer Extension (TRBE) driver has been addressed with CVE-2025-40060, a security patch that prevents potential kernel panics caused by...
Linux KSM Madvise Bug CVE-2025-40040: Critical Security Patch Analysis
A critical vulnerability in the Linux kernel's Kernel Samepage Merging (KSM) subsystem has been patched, addressing CVE-2025-40040, a subtle but dangerous flag-dropping bug that could lead to...
CVE-2025-40055: OCFS2 Double Free Vulnerability and Linux Kernel Security
A critical security vulnerability in the Linux kernel's OCFS2 filesystem has been addressed through a seemingly simple code fix that highlights the persistent challenges of memory management in...
Linux Kernel CVE-2025-40042: Race Condition in kprobe Initialization Threatens System Stability
A critical vulnerability in the Linux kernel, identified as CVE-2025-40042, exposes systems to potential kernel crashes through a race condition in kprobe initialization that can trigger NULL-pointer...
CVE-2025-40013: Critical Qualcomm Audio Driver Vulnerability Explained
A significant security vulnerability designated as CVE-2025-40013 has been identified in the Qualcomm ASoC (Audio System on Chip) audioreach driver, representing a critical kernel-level security flaw...
Microsoft Flags Graphics Bug That Lets Attackers Grab System Control—Here’s Your Patching Plan
Microsoft’s latest security update addresses a race condition in the Windows graphics component that could allow an attacker with local access to escalate privileges to SYSTEM level. The...
Windows Hyper-V Race Condition Flaw (CVE-2025-54092) Enables Attackers to Seize Host Control
Microsoft has disclosed a dangerous race condition vulnerability in Windows Hyper-V that could allow a local attacker to seize SYSTEM-level privileges on the host. Tracked as CVE-2025-54092, the flaw...
Windows HTTP.sys Out-of-Bounds Read Enables Remote DoS — Patch Urgently
A newly referenced vulnerability in the Windows HTTP protocol stack exposes internet-facing servers to remote denial-of-service attacks, forcing administrators to take immediate action even as public...
CVE-2025-55236: Windows Graphics Kernel Race Condition Allows Attackers to Escalate to SYSTEM — Patch Now
Microsoft has published advisory CVE-2025-55236, a time-of-check/time-of-use (TOCTOU) race condition in the Windows Graphics Kernel that hands local, authenticated attackers a path to elevate...