Linux Security
The latest Linux Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft's Azure Linux Hit by cpupower CVE, but WSL2 and Cloud Images Remain Unchecked
On May 9, 2025, a Linux kernel maintainer patched a NULL pointer dereference in the cpupower benchmark tool, assigned CVE-2025-37841. Microsoft has confirmed that its Azure Linux distribution...
Microsoft Confirms Azure Linux Hit by CVE-2025-38422 Kernel Bug; Other Products Remain Unchecked
Microsoft has confirmed that its Azure Linux distribution ships a vulnerable version of the LAN743x Ethernet driver, leaving systems exposed to a high-severity kernel bug tracked as CVE-2025-38422....
CVE-2025-68733: Smack LSM Vulnerability Exposes Linux Systems to Unprivileged Relabeling Attacks
A critical vulnerability in the Smack Linux Security Module (LSM) has been assigned CVE-2025-68733, exposing systems to potential privilege escalation and security bypass attacks. The flaw,...
Azure Policy CIS Linux Benchmarks: Microsoft's Hybrid Security Play Explained
Microsoft has significantly expanded its security governance capabilities with the integration of official Center for Internet Security (CIS) Linux Benchmarks directly into Azure Policy's Machine...
Azure Policy Integrates CIS Linux Benchmarks for Enhanced Cloud Security
Microsoft has significantly bolstered its cloud security offerings by integrating official CIS Linux Benchmarks directly into Azure Policy through the azure-osconfig extension, currently available in...
Azure Policy Now Includes CIS-Certified Linux Benchmarks for Enhanced Security
Microsoft Azure has significantly bolstered its security compliance capabilities by integrating official, CIS-certified Linux benchmarks directly into Azure Policy through the Azure osconfig...
Azure Policy & Arc Now Natively Enforce CIS Linux Benchmarks in Preview
Microsoft has taken a significant step forward in cloud security by making official CIS Linux security benchmarks available natively on Microsoft Azure. This new capability, delivered as a built-in...
GRUB2 CVE-2025-61663 Critical Vulnerability: Patch Your Bootloader Now
A critical use-after-free vulnerability in the GRUB2 bootloader, tracked as CVE-2025-61663, has been disclosed, posing significant risks to Linux systems and dual-boot Windows configurations...
CVE-2025-39705: Critical AMD Linux Driver Fix & Azure Linux Security Implications
A critical security vulnerability in AMD's Linux display driver, tracked as CVE-2025-39705, has been patched upstream, revealing a significant null-pointer dereference flaw that could lead to system...
CVE-2022-49173: How SPI Polling Timeout Threatens Linux System Availability
A critical vulnerability in Linux kernel's SPI subsystem, designated CVE-2022-49173, exposes systems to denial-of-service attacks through a missing timeout mechanism in low-level polling loops. This...
CVE-2025-59497: Critical TOCTOU Vulnerability in Defender for Endpoint Linux
Microsoft has disclosed a significant security vulnerability in Defender for Endpoint for Linux, identified as CVE-2025-59497, which exposes systems to potential local privilege escalation attacks...
Winux Mimics Windows 11 but Inherits a Legacy of Security Failures
A Linux distribution that promises to look and feel like Windows 11 has been quietly making the rounds, but behind the slick screenshots and polished demo reels lies a history of security breaches...