Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day

Researchers exploited CVE-2025-38001—a previously unknown Use-After-Free (UAF) vulnerability in the Linux HFSC queuing discipline—to compromise all Google kernelCTF instances (LTS, COS, and mitigation) as well as fully patched Debian 12 systems.  Their work netted an estimated $82,000 in cumulative bounties and underscores the continuing importance of in-depth code auditing beyond automated fuzzing. Key Takeaways1. NETEM’s […]

The post Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: