Sopuli
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
☆ Yσɠƚԋσʂ ☆@lemmy.ml to Linux@lemmy.mlEnglish · 17 天前

Fragnesia: New Linux Privilege Escalation Exploit

github.com

external-link
message-square
20
link
fedilink
  • cross-posted to:
  • blueteamsec@infosec.pub
  • linux@programming.dev
  • main@0xdd.org.ru
77
external-link

Fragnesia: New Linux Privilege Escalation Exploit

github.com

☆ Yσɠƚԋσʂ ☆@lemmy.ml to Linux@lemmy.mlEnglish · 17 天前
message-square
20
link
fedilink
  • cross-posted to:
  • blueteamsec@infosec.pub
  • linux@programming.dev
  • main@0xdd.org.ru
pocs/fragnesia at main · v12-security/pocs
github.com
external-link
poc it like it's hot. Contribute to v12-security/pocs development by creating an account on GitHub.
alert-triangle
You must log in or # to comment.
  • Arthur Besse@lemmy.mlM
    link
    fedilink
    English
    arrow-up
    57
    ·
    17 天前

    "i wake up cat" meme format
top text: i wake up
bottom text: there is a new local privilege escalation exploit for Linux

    • Runecrush376@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      17 天前

      😂😂😂

  • inari@piefed.zip
    link
    fedilink
    English
    arrow-up
    20
    ·
    17 天前

    Good news. One fewer zero-day.

  • Fatur.New@lemmy.ml
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    17 天前

    If this is quickly solved, there is nothing to worry about

    Sorry if my english is bad

    • Azzu@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      8
      ·
      17 天前

      It is already solved. The dirtyfrag patch fixes it already.

    • neon_nova@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      2
      ·
      17 天前

      Only think you forgot was punctuation marks at the ends of your sentences.

      • pastermil@sh.itjust.works
        link
        fedilink
        arrow-up
        15
        ·
        17 天前

        This simply means the person isn’t finished talking.

  • Goingdown
    link
    fedilink
    arrow-up
    14
    ·
    17 天前

    Same workaround works here as with dirty frag. Just disable those kernel modules.

    • FoundFootFootage78@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      ·
      17 天前

      Maybe the solution is to just, delete a bunch of kernel modules.

      How many of them are actually important anyway?

      • nyan@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        16 天前

        Unless you deliberately set out to compile a minimalistic custom kernel, less than half of them. Problem is, you may not be able to easily tell which half.

  • AstroLightz@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    16 天前

    I’m sure removing the root user will prevent all escalation exploits. Can’t get root if there is no root!

    /j

    • racoon@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      16 天前

      Make root login 2FA with yubikey or TOTP

  • Cantaloupe@lemmy.fedioasis.cc
    link
    fedilink
    English
    arrow-up
    7
    ·
    16 天前

    Ah shit, here we go again.

  • wickedrando@lemmy.ml
    link
    fedilink
    English
    arrow-up
    7
    ·
    17 天前

    apparmor ftw

  • Infernal_pizza@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    17 天前

    At this point we might as well just run everything as root anyway

    • ranzispa@mander.xyz
      link
      fedilink
      arrow-up
      9
      ·
      17 天前

      Leave ssh root access open with no password. Attackers will try to escalate privileges as their default strategy, when that fails they’ll add your IP to their unhackable blacklist.

  • ghost_laptop@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    17 天前

    what’s a scenario where you could suffer from this vulnerability?

    • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
      link
      fedilink
      arrow-up
      6
      ·
      17 天前

      if somebody already has access to your machine, but doesn’t have root privileges

  • nyan@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    17 天前

    I think you might be able to deactivate this one by turning off XFRM support in a custom-configured kernel, at the cost of losing some types of tunneling. Not going to actually test that, though.

  • altphoto@lemmy.today
    link
    fedilink
    arrow-up
    2
    ·
    17 天前

    Scarry! Uoi guys on windows better stay away…ohhh privilege!

Linux@lemmy.ml

linux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@lemmy.ml

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !opensource@lemmy.ml
  • !libre_culture@lemmy.ml
  • !technology@lemmy.ml
  • !libre_hardware@lemmy.ml

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 205 users / day
  • 1.91K users / week
  • 4.64K users / month
  • 13.5K users / 6 months
  • 690 local subscribers
  • 65.5K subscribers
  • 10.5K Posts
  • 243K Comments
  • Modlog
  • mods:
  • AgreeableLandscape@lemmy.mldeleted by creator
  • nooter692@lemmy.ml
  • MarcellusDrum@lemmy.ml
  • Arthur Besse@lemmy.ml
  • Cyclohexane@lemmy.ml
  • d3Xt3r@lemmy.nzdeleted by creator
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org