home / selinux

Selinux

2026.08.31A Newline to Root: CVE-2026-19624An unprivileged D-Bus call writes a root-parsed VPN config value. One newline, root code execution, confinement escape.2026.08.12Confined Root Is Still RootA compromised root daemon can’t change its own SELinux domain. It doesn’t need to - it recruits something already unconfined.2026.07.20Measuring the Blast Radius of a Root DaemonThe real confinement of a root daemon is the intersection of SELinux policy, systemd sandboxing, Linux capabilities, and DAC.