Google has launched a special quarterly bug bounty, targeting flaws in the Linux kernel with a triple reward for security researchers.

See also: Google Photos: New button scans for similar images
The new bounty announced this week, is offering up to $31,337 (Leet) to security researchers who can exploit privilege escalation in Google's lab environment in a patched vulnerability, and $50,337 to anyone who can find a previously undisclosed flaw or zero-day, or discover a new exploitation technique.
"We continuously invest in the security of the Linux kernel because so much of the internet and Google, from the devices in our pockets to the services running on Kubernetes in the cloud, depend on its security," said Eduardo Vela from the Google Bug Hunters team.
The Linux kernel now powers most of the leading websites and internet infrastructure, from AWS to Microsoft Azure, Google, Facebook, and Wikipedia.
Google's base bounty for each publicly patched vulnerability is $31,337, with a cap of one exploit per vulnerability. However, the bounty can go up to $50,337 if the bug has not been patched or if the exploit uses a new attack or technique in Google's opinion.
See also: Google Chrome: Emergency update to fix zero-day vulnerabilities

"We hope that the new rewards will encourage the security community to explore new kernel exploitation techniques to achieve privilege escalation and lead to faster fixes for these vulnerabilities," Vela said.
He adds that “the most easily exploited bugs are not available in our lab environment due to the hardening done in the Container-Optimized OS.” This is a Chromium-based operating system for Google Compute Engine virtual machines that is designed to run in Docker Containers.
However, since this quarterly bonus supplements Android's VRP rewards, farms operating on Android could also be eligible for up to $250,000.
Google's environment has some specific requirements that were demonstrated by Google security engineer Andy Nguyen, who found the BleedingTooth bug (CVE-2021-22555) in the Linux Bluetooth stack, where it had existed for 15 years.
See also: Netflix introduces 5 games for Android mobile
Vela recommends participants also include a patch if they want extra cash through the Patch Rewards Program.
Given the nature of open-source software development, Google notes that it doesn't want to receive details about unpatched vulnerabilities before they're publicly disclosed and fixed. Researchers must provide the exploit code and the algorithm used to calculate the identifier. However, it would like to receive a rough description of the exploitation strategy.
