SEC-101 · Kernel Security
Reading Kernel CVEs
Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe.
Who this course is for
Engineers who must decide which kernel CVEs actually require action on their products — maintenance, security or release roles facing a feed that scores everything critical.
Prerequisites
Course outline
Day 1 — What a kernel CVE actually says
- CVE, CNA, NVD and CPE: who assigns what, and where the data comes from
- The kernel's own CVE assignment process and what its volume means for your intake
- Why CVSS base scores mislead for kernel bugs: local vs remote, privileges, configuration
- Reading the advisory: affected versions, fix-commit links and what is missing
- Fixes: tags, commit ancestry and how stable backports rewrite the version story
Day 2 — Reachability and the triage record
- Version-range failure modes: why 'fixed in 6.6.3' does not answer your question
- Code reachability: is the vulnerable function even in your source base?
- Config and module reachability: built-in, loadable module, or not compiled at all
- Exposure: which workloads, interfaces and device trees can actually reach the code
- Issuing affected / not affected / insufficient-evidence decisions with citations
- Building a triage record that survives audit and later re-opening
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: Trace a published kernel CVE from the advisory to its fixing commits with git log and Fixes: tags
- Lab: Test commit ancestry across two divergent branches and show where the NVD version range misleads
- Lab: Prove or disprove reachability of a vulnerable driver in a supplied tree using source and .config evidence
- Lab: Build a compiled-source inventory for a product build and use it to kill two false positives
- Lab: Triage a batch of recent CVEs against a product tree and issue written decisions with confidence levels
Capstone project
Triage a set of historical kernel CVEs against two supplied trees — a near-mainline kernel and an older vendor-style fork: for each CVE you produce a decision record (affected, not affected, or insufficient evidence) citing commit-ancestry, config and reachability evidence, plus an explicit uncertainty statement where the evidence runs out.
What you leave with
- A repeatable CVE-to-commit tracing method using Fixes: tags and ancestry
- Reachability analysis habits across source, .config, module and exposure layers
- A triage-record template that stands up to audit
- Realistic expectations of CVSS scores and NVD version ranges for kernels
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who must decide which kernel CVEs actually require action on their products — maintenance, security or release roles facing a feed that scores everything critical. It sits at practitioner level within the Kernel Security track.
What do I need to know already?
Specific prerequisites for this course: Comfort with git log, git show and branch anatomy on a kernel tree; Basic kernel build and .config literacy; No prior security specialisation required — this is an evidence-reading course. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 11 Oct – 12 Oct 20262 full days | RiyadhIn person · KAFD Conference Centre | 11 of 14 | — | SAR 5,250 | |
| 18 Oct – 19 Oct 20262 full days | Kuwait CityIn person · Al Hamra Tower | 6 of 14 | — | KWD 430 | |
| 25 Oct – 26 Oct 20262 full days | MuscatIn person · Knowledge Oasis Muscat | 11 of 14 | — | OMR 540 | |
| 25 Oct – 28 Oct 20264 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 9 of 20 | — | US$1,000 | |
| 26 Oct – 27 Oct 20262 full days | OttawaIn person · Kanata North Tech Park | 6 of 14 | — | CAD 1,900 | |
| 2 Nov – 3 Nov 20262 full days | TorontoIn person · MaRS Discovery District | 11 of 14 | — | CAD 1,900 | |
| 2 Nov – 5 Nov 20264 half-days | Europe bandLive online · 09:00–13:00 CET | 14 of 20 | — | US$1,000 | |
| 2 Nov – 5 Nov 20264 half-days | Americas bandLive online · 13:00–17:00 ET | 3 of 20 | — | US$1,000 | |
| 9 Nov – 10 Nov 20262 full days | LondonIn person · Shoreditch Works | 6 of 14 | GBP 980until 10 Oct | ||
| 9 Nov – 10 Nov 20262 full days | BerlinIn person · Factory Görlitzer Park | 11 of 14 | EUR 1,160until 10 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Security
SEC-1103 days
Exploit Mitigations & Hardening
The mitigations available in a modern kernel, what each actually stops, and what they cost.
Practitioner-taught
SAR 9,000Next 8 Nov
SEC-1202 days
Attack Surface Reduction
Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible.
Practitioner-taught
SAR 6,000Next 25 Oct
SEC-2013 days
Multi-Branch Backporting
Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team.
Practitioner-taught
SAR 9,000Next 1 Nov
SEC-2102 days
Stable, LTS & Vendor Tree Hygiene
Working with the upstream stable process and keeping a vendor tree that does not rot.
Practitioner-taught
SAR 5,250Next 18 Oct
SEC-2202 days
Building an Advisory Workflow
The process around the engineering: intake, assessment, communication and evidence, on a deadline.
Practitioner-taught
SAR 5,250Next 15 Nov
SEC-3013 days
LSM, SELinux & AppArmor
Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.
Practitioner-taught
SAR 9,000Next 22 Nov
SEC-3102 days
Landlock & Kernel Lockdown
Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown.
Practitioner-taught
SAR 6,000Next 8 Nov
SEC-3203 days
Integrity: IMA/EVM & dm-verity
Measuring and verifying what runs on the system, from block device to individual file.
Practitioner-taught
SAR 9,000Next 18 Oct