HomeinetGoogle: It just tripled its reward for Linux kernel bugs

Google: It Just Tripled Its Reward for Linux Kernel Bugs

Google has launched a special quarterly bug bounty, targeting flaws in the Linux kernel with a triple reward for security researchers.

Linux kernel

See also: Google Photos: New button scans for similar images

The new bounty announced this week, is offering up to $31,337 (Leet) to security researchers who can exploit privilege escalation in Google's lab environment in a patched vulnerability, and $50,337 to anyone who can find a previously undisclosed flaw or zero-day, or discover a new exploitation technique.

"We continuously invest in the security of the Linux kernel because so much of the internet and Google, from the devices in our pockets to the services running on Kubernetes in the cloud, depend on its security," said Eduardo Vela from the Google Bug Hunters team.

The Linux kernel now powers most of the leading websites and internet infrastructure, from AWS to Microsoft Azure, Google, Facebook, and Wikipedia.

Google's base bounty for each publicly patched vulnerability is $31,337, with a cap of one exploit per vulnerability. However, the bounty can go up to $50,337 if the bug has not been patched or if the exploit uses a new attack or technique in Google's opinion.

See also: Google Chrome: Emergency update to fix zero-day vulnerabilities

Google

"We hope that the new rewards will encourage the security community to explore new kernel exploitation techniques to achieve privilege escalation and lead to faster fixes for these vulnerabilities," Vela said.

He adds that “the most easily exploited bugs are not available in our lab environment due to the hardening done in the Container-Optimized OS.” This is a Chromium-based operating system for Google Compute Engine virtual machines that is designed to run in Docker Containers.

However, since this quarterly bonus supplements Android's VRP rewards, farms operating on Android could also be eligible for up to $250,000.

Google's environment has some specific requirements that were demonstrated by Google security engineer Andy Nguyen, who found the BleedingTooth bug (CVE-2021-22555) in the Linux Bluetooth stack, where it had existed for 15 years.

See also: Netflix introduces 5 games for Android mobile

Vela recommends participants also include a patch if they want extra cash through the Patch Rewards Program.

Given the nature of open-source software development, Google notes that it doesn't want to receive details about unpatched vulnerabilities before they're publicly disclosed and fixed. Researchers must provide the exploit code and the algorithm used to calculate the identifier. However, it would like to receive a rough description of the exploitation strategy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS