• Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    ·
    edit-2
    17 hours ago

    wtf

    An unprivileged local user can write 4 controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root.

    If your kernel was built between 2017 and the patch — which covers essentially every mainstream Linux distribution — you’re in scope.

    how does that only get a CVE score of 7.8, the impact of this is huge

      • nyan@sh.itjust.works
        link
        fedilink
        arrow-up
        20
        ·
        14 hours ago

        Exactly. It’s Yet Another Privilege Escalation Vulnerability. Unless you’re dealing with a multiuser machine, the attacker first needs to use some other vuln to get into an unprivileged account. Without that additional vulnerability, this exploit is useless.

        • solrize@lemmy.ml
          link
          fedilink
          arrow-up
          16
          ·
          13 hours ago

          some other vuln

          You mean like inveigling it into a pypi or npm or whatever package? Checks out.

          • olosta@lemmy.world
            link
            fedilink
            arrow-up
            4
            ·
            3 hours ago

            I manage multi user systems and try to be on top of this and no, privilege escalation with a working public exploit are very rare. There’s quite a lot of CVEs with potential privilege excalation, but most of the time there is no real world exploit. And a large part of those are related to user namespaces in one way or another.

            This one is truly scary, at least the immediate mitigation is pretty straightforward.

          • nyan@sh.itjust.works
            link
            fedilink
            arrow-up
            6
            ·
            13 hours ago

            Well, it often feels like every “Linux security issue” flagged in the tech press is a privilege escalation, but I admit that I haven’t sat down and done the math.

        • sakuraba@lemmy.ml
          link
          fedilink
          arrow-up
          7
          ·
          edit-2
          14 hours ago

          hey these exploits keep the lights on for some tech youtubers, stop making fun of it!! it is very dangerous!!!

          (video titled: LINUX HAS BEEN HACKED, AGAIN?!)