Security Bulletins

SECURITY ADVISORIES.
CVE & FIX LOG.

Public disclosure records for security mitigations, kernel hardenings, and patch integrations shipped across Cyronix OS releases.

CYR-SEC-2026-001 2026-09-22 · High Severity

Kernel Memory Protection & USB Restricted Mode (Release 1.5.0)

Resolved potential local privilege escalation pathways in kernel memory debugging by removing CONFIG_KALLSYMS_ALL, disabling Magic SysRq, and enforcing Yama LSM ptrace boundaries. Enabled USB restricted mode by default on locked devices to block forensic cable extractions.

Fixed in: CYRONIX OS 1.5.0 / 1.5.1