PokeTina
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Zenlix@lemmy.ml to Technology@lemmy.worldEnglish · 2 days ago

There is a new linux vulnerability that allows every unprivileged user to become root super easily

copy.fail

external-link
message-square
10
link
fedilink
  • cross-posted to:
  • [email protected]
8
external-link

There is a new linux vulnerability that allows every unprivileged user to become root super easily

copy.fail

Zenlix@lemmy.ml to Technology@lemmy.worldEnglish · 2 days ago
message-square
10
link
fedilink
  • cross-posted to:
  • [email protected]
Copy Fail — 732 Bytes to Root
copy.fail
external-link
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
alert-triangle
You must log in or # to comment.
  • MasterNerd@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    Hmm seems like that report is AI generated

    • thesmokingman@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      1 day ago

      It is. The vuln itself was found with guidance of an AI tool. Doesn’t make the vuln any less bad. Does make Xint look really shitty for constantly shilling with boilerplate AI instead of a good human analysis (or at least something above boilerplate).

  • Corngood@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    It feels weird that it has it’s own domain name and slogan. I get that there’s a promotional aspect to it, but it seems a bit much.

    • Rossphorus@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      This is not uncommon for high-profile CVEs. For example, brokenwire.fail, heartbleed.com, spectreattack.com, etc…

  • Björn@swg-empire.de
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    Ugh, another new “sudo” clone.

    • ryannathans@aussie.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Much smaller than sudo

      • RiceMunk@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        surprise new linux feature: Much more space-efficient sudo command

  • corsicanguppy@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    2
    ·
    1 day ago

    Only if you enable the mode for rootless containers. If you run more safe, this thing is apparently impotent.

    No containers here, no cry.

    • Tim@lemmy.snowgoons.ro
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      Where are you getting that from? That’s not the case at all.

  • Dadifer@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    In the writeup, they say there’s multiple other vulnerabilities on this attack surface, but they’re still working on responsible disclosure.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2.95K users / day
  • 0 users / week
  • 0 users / month
  • 0 users / 6 months
  • 1 local subscriber
  • 84.3K subscribers
  • 135 Posts
  • 1.57K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.worldB
  • L3s@hackingne.ws
  • UI: unknown version
  • BE: 0.19.18
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org