SEC-101 · Kernel Security · Practitioner

Reading Kernel CVEs — full syllabus

Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe.

Duration2 full days in person · 4 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 5,250 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Engineers who must decide which kernel CVEs actually require action on their products — maintenance, security or release roles facing a feed that scores everything critical.

Prerequisites

Course outline

Day 1 — What a kernel CVE actually says

  • CVE, CNA, NVD and CPE: who assigns what, and where the data comes from
  • The kernel's own CVE assignment process and what its volume means for your intake
  • Why CVSS base scores mislead for kernel bugs: local vs remote, privileges, configuration
  • Reading the advisory: affected versions, fix-commit links and what is missing
  • Fixes: tags, commit ancestry and how stable backports rewrite the version story

Day 2 — Reachability and the triage record

  • Version-range failure modes: why 'fixed in 6.6.3' does not answer your question
  • Code reachability: is the vulnerable function even in your source base?
  • Config and module reachability: built-in, loadable module, or not compiled at all
  • Exposure: which workloads, interfaces and device trees can actually reach the code
  • Issuing affected / not affected / insufficient-evidence decisions with citations
  • Building a triage record that survives audit and later re-opening

Hands-on labs

  1. Lab: Trace a published kernel CVE from the advisory to its fixing commits with git log and Fixes: tags
  2. Lab: Test commit ancestry across two divergent branches and show where the NVD version range misleads
  3. Lab: Prove or disprove reachability of a vulnerable driver in a supplied tree using source and .config evidence
  4. Lab: Build a compiled-source inventory for a product build and use it to kill two false positives
  5. Lab: Triage a batch of recent CVEs against a product tree and issue written decisions with confidence levels

Capstone project

Triage a set of historical kernel CVEs against two supplied trees — a near-mainline kernel and an older vendor-style fork: for each CVE you produce a decision record (affected, not affected, or insufficient evidence) citing commit-ancestry, config and reachability evidence, plus an explicit uncertainty statement where the evidence runs out.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
11 Oct – 12 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 11 of 14 —SAR 5,250
18 Oct – 19 Oct 20262 full days Kuwait CityIn person · Al Hamra Tower 6 of 14 —KWD 430
25 Oct – 26 Oct 20262 full days MuscatIn person · Knowledge Oasis Muscat 11 of 14 —OMR 540
25 Oct – 28 Oct 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 9 of 20 —US$1,000
26 Oct – 27 Oct 20262 full days OttawaIn person · Kanata North Tech Park 6 of 14 —CAD 1,900
2 Nov – 3 Nov 20262 full days TorontoIn person · MaRS Discovery District 11 of 14 —CAD 1,900
2 Nov – 5 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 14 of 20 —US$1,000
2 Nov – 5 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 3 of 20 —US$1,000
9 Nov – 10 Nov 20262 full days LondonIn person · Shoreditch Works 6 of 14 GBP 980until 10 OctGBP 1,090
9 Nov – 10 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 11 of 14 EUR 1,160until 10 OctEUR 1,290

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.