A logic gap in the Linux kernel’s kTLS receive path lets a zero-length record on the rx_list slip past type checks, corrupting zero-copy and queuing assumptions for later records.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Linux Kernel Out-of-Bounds Write Vulnerability
A bridge firewall rule feature in ebtables’ SNAT target can be tricked into writing an ARP address rewrite straight into unprepared kernel memory, corrupting it.
Linux Kernel Race Condition Vulnerability
A local, low-privileged process can race concurrent writes to the same AF_ALG crypto socket, corrupting kernel state with confidentiality, integrity and availability impact.
Acronis Backup Incorrect Default Permissions Vulnerability
A permissions flaw in Acronis Backup’s cPanel/WHM plugin and Plesk extension lets a local user, such as a hosting customer, escalate to root or admin-level control on shared servers.
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
An unauthenticated attacker can bypass login on Cisco ISE and ISE-PIC’s web management interface and gain access to the device outright, with no patch yet available.
Google Pixel Improper Authorization Vulnerability
A logic flaw in the Pixel cellular modem lets someone with radio-level proximity bypass permission checks and escalate privileges without any user interaction, and it’s already being exploited.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.