Lemmy LIETUVA
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
HM King Charles III DG FD@feddit.uk to Selfhosted@lemmy.worldEnglish · 2 months ago

Serious Linux vulnerability affecting nearly every system. Patch your systems.

copy.fail

external-link
message-square
68
link
fedilink
  • cross-posted to:
  • selfhosted@lemmy.world
  • cybersecurity@sh.itjust.works
  • cybersecurity@infosec.pub
  • linux@sh.itjust.works
  • linux@lemmy.ml
  • technology@lemmy.world
  • cybersecurity@sh.itjust.works
  • linux@programming.dev
  • linux@lemmy.ml
1
external-link

Serious Linux vulnerability affecting nearly every system. Patch your systems.

copy.fail

HM King Charles III DG FD@feddit.uk to Selfhosted@lemmy.worldEnglish · 2 months ago
message-square
68
link
fedilink
  • cross-posted to:
  • selfhosted@lemmy.world
  • cybersecurity@sh.itjust.works
  • cybersecurity@infosec.pub
  • linux@sh.itjust.works
  • linux@lemmy.ml
  • technology@lemmy.world
  • cybersecurity@sh.itjust.works
  • linux@programming.dev
  • linux@lemmy.ml
Copy Fail — 732 Bytes to Root
copy.fail
external-link
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    A local compromise happens more than you think

    • ipp0@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Do you have a source for how often it happens or is this conjecture? I guess this would most often happen through supply chain attacks or physical access, the first not being all that common in my understanding and the latter not being a typical threat model for a home computer. But if you have a source explaining what actually happens, I would love to read it.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        There are plenty of way to get a local unprivileged shell

        For instance, if you are running a old version of cups someone could chain together several vulnerabilities to gain root on your system

        https://www.bleepingcomputer.com/news/security/cups-flaws-enable-linux-remote-code-execution-but-theres-a-catch/

        Having a MAC like SELinux helps to mitigate this but you still should patch as soon as possible

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don’t duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 50 users / day
  • 397 users / week
  • 1.74K users / month
  • 3.07K users / 6 months
  • 0 local subscribers
  • 59.9K subscribers
  • 921 Posts
  • 11.9K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • ayyy@sh.itjust.works
  • curbstickle@anarchist.nexus
  • curbstickle_lw@lemmy.world
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org