Linux has been bitten by a second severe security vulnerability in as many weeks, with CVE-2026-3123 enabling arbitrary code execution in the kernel's network stack. This flaw scored 8.4 out of 10 on the CVSS scale, matching the severity of last week's memory management bug, CVE-2026-3118, which affected 40% of enterprise servers running kernel 6.3. The latest vulnerability exploits a heap overflow in the TCP optimization module, a feature added in kernel 6.2 that now requires an urgent patch for 15 million active Linux instances. Compared to the average critical vulnerability, which takes 14 days to patch, this double blow has forced maintainers to issue an emergency fix within 48 hours. The cascade has slowed patch velocity by 20%, raising alarms across embedded devices and cloud infrastructure. This pair of flaws exposes a trend: as Linux adoption grows 30% annually in IoT, the attack surface expands faster than security resources can keep pace.

Comments on "Linux bitten by second severe vulnerability in as many weeks"
Create a free account or sign in to join the discussion.
Sign in to join the conversation