LibreTechni.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
☆ Yσɠƚԋσʂ ☆@lemmy.ml to Linux@lemmy.mlEnglish · 13 hours ago

Fragnesia: New Linux Privilege Escalation Exploit

github.com

external-link
message-square
22
fedilink
  • cross-posted to:
  • linux@programming.dev
58
external-link

Fragnesia: New Linux Privilege Escalation Exploit

github.com

☆ Yσɠƚԋσʂ ☆@lemmy.ml to Linux@lemmy.mlEnglish · 13 hours ago
message-square
22
fedilink
  • cross-posted to:
  • linux@programming.dev
pocs/fragnesia at main · v12-security/pocs
github.com
external-link
poc it like it's hot. Contribute to v12-security/pocs development by creating an account on GitHub.
alert-triangle
You must log in or register to comment.
  • altphoto@lemmy.today
    link
    fedilink
    arrow-up
    1
    ·
    28 minutes ago

    Scarry! Uoi guys on windows better stay away…ohhh privilege!

  • ghost_laptop@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    2 hours ago

    what’s a scenario where you could suffer from this vulnerability?

  • Goingdown@sopuli.xyz
    link
    fedilink
    arrow-up
    9
    ·
    8 hours ago

    Same workaround works here as with dirty frag. Just disable those kernel modules.

    • FoundFootFootage78@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      36 minutes ago

      Maybe the solution is to just, delete a bunch of kernel modules.

      How many of them are actually important anyway?

  • inari@piefed.zip
    link
    fedilink
    English
    arrow-up
    10
    ·
    8 hours ago

    Good news. One fewer zero-day.

    • chgxvjh [he/him, comrade/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      there is more where that came from https://xcancel.com/IntCyberDigest/status/2053802477019906058

  • blobjim [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    5
    ·
    8 hours ago

    It’s frustrating that there isn’t much of an effort to turn Linux into more of a microkernel. Instead the kernel just keeps getting bigger with even more subsystems and modules that can be exploited.

    • CarrotsHaveEars@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      2 hours ago

      Systems built on microkernels exist, you know. See Redox.
      https://redox-os.org/

  • chgxvjh [he/him, comrade/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 hours ago

    Fuck it, taking my home server offline for a while.

    • chgxvjh [he/him, comrade/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      1
      ·
      43 minutes ago

      Mainly because of the nginx RCE

  • Infernal_pizza@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    7 hours ago

    At this point we might as well just run everything as root anyway

    • ranzispa@mander.xyz
      link
      fedilink
      arrow-up
      2
      ·
      31 minutes ago

      Leave ssh root access open with no password. Attackers will try to escalate privileges as their default strategy, when that fails they’ll add your IP to their unhackable blacklist.

    • chgxvjh [he/him, comrade/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 hours ago

      docker

  • Arthur Besse@lemmy.mlM
    link
    fedilink
    English
    arrow-up
    41
    ·
    13 hours ago

    "i wake up cat" meme format
top text: i wake up
bottom text: there is a new local privilege escalation exploit for Linux

    • Runecrush376@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      12 hours ago

      😂😂😂

  • wickedrando@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 hours ago

    apparmor ftw

  • Fatur.New@lemmy.ml
    link
    fedilink
    English
    arrow-up
    13
    ·
    13 hours ago

    If this is quickly solved, there is nothing to worry about

    Sorry if my english is bad

    • Azzu@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      4
      ·
      7 hours ago

      It is already solved. The dirtyfrag patch fixes it already.

    • neon_nova@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      7
      ·
      12 hours ago

      Only think you forgot was punctuation marks at the ends of your sentences.

      • pastermil@sh.itjust.works
        link
        fedilink
        arrow-up
        6
        ·
        10 hours ago

        This simply means the person isn’t finished talking.

  • Cat_Daddy [any, any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    9
    ·
    13 hours ago

  • nyan@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    11 hours ago

    I think you might be able to deactivate this one by turning off XFRM support in a custom-configured kernel, at the cost of losing some types of tunneling. Not going to actually test that, though.

Linux@lemmy.ml

linux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@lemmy.ml

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !opensource@lemmy.ml
  • !libre_culture@lemmy.ml
  • !technology@lemmy.ml
  • !libre_hardware@lemmy.ml

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 680 users / day
  • 2.09K users / week
  • 5.09K users / month
  • 13.5K users / 6 months
  • 3 local subscribers
  • 65.2K subscribers
  • 5.71K Posts
  • 115K Comments
  • Modlog
  • mods:
  • nooter692@lemmy.ml
  • MarcellusDrum@lemmy.ml
  • Arthur Besse@lemmy.ml
  • Cyclohexane@lemmy.ml
  • d3Xt3r@lemmy.nz
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org