Skip to content

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution

xint.io
25 pointseyalitki3 comments
On HN

Comments

The presented LPE vulnerability was gradually introduced to the Linux Kernel through refactors and optimizations, each commit making sense on its own. The vulnerability itself was exploitable since 2017 (!) and also doubles as a container escape.

the real kicker is the page cache trick making it invisible to disk-based integrity checks, which means your auditd and tripwire setups are worth exactly nothing here

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.