ekZepp

joined 2 years ago
MODERATOR OF
[–] ekZepp@lemmy.world 2 points 9 hours ago

And ofc the Sleepy Squid Dragon

 

cross-posted from: https://lemmy.world/post/46310739

cross-posted from: https://lemmy.world/post/46310733

Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root.

The high-severity vulnerability tracked as CVE-2026-31431 (CVSS score: 7.8) has been codenamed Copy Fail by Xint.io and Theori.

"An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root," the vulnerability research team at Xint.io and Theori said.

At its core, the vulnerability stems from a logic flaw in the Linux kernel's cryptographic subsystem, specifically within the algif_aead module. The issue was introduced in a source code commit made in August 2017.

Successful exploitation of the shortcoming could allow a simple 732-byte Python script to edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017, including Amazon Linux, RHEL, SUSE, and Ubuntu. The Python exploit involves four steps -

  • Open an AF_ALG socket and bind to authencesn(hmac(sha256),cbc(aes))
  • Construct the shellcode payload
  • Trigger the write operation to the kernel's cached copy of "/usr/bin/su"
  • Call execve("/usr/bin/su") to load the injected shellcode and run it as root

While the vulnerability is not remotely exploitable in isolation, a local unprivileged user can get root simply by corrupting the page cache of a setuid binary. The same primitive also has cross-container impacts as the page cache is shared across all processes on a system.

 

cross-posted from: https://lemmy.world/post/46310733

Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root.

The high-severity vulnerability tracked as CVE-2026-31431 (CVSS score: 7.8) has been codenamed Copy Fail by Xint.io and Theori.

"An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root," the vulnerability research team at Xint.io and Theori said.

At its core, the vulnerability stems from a logic flaw in the Linux kernel's cryptographic subsystem, specifically within the algif_aead module. The issue was introduced in a source code commit made in August 2017.

Successful exploitation of the shortcoming could allow a simple 732-byte Python script to edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017, including Amazon Linux, RHEL, SUSE, and Ubuntu. The Python exploit involves four steps -

  • Open an AF_ALG socket and bind to authencesn(hmac(sha256),cbc(aes))
  • Construct the shellcode payload
  • Trigger the write operation to the kernel's cached copy of "/usr/bin/su"
  • Call execve("/usr/bin/su") to load the injected shellcode and run it as root

While the vulnerability is not remotely exploitable in isolation, a local unprivileged user can get root simply by corrupting the page cache of a setuid binary. The same primitive also has cross-container impacts as the page cache is shared across all processes on a system.

[–] ekZepp@lemmy.world 16 points 3 days ago
[–] ekZepp@lemmy.world 3 points 3 days ago* (last edited 3 days ago) (3 children)

Arch is like your psychotic ex. Sex is great, but one day, you wake up because she's burning the sheets of your bed while you're still inside.

[–] ekZepp@lemmy.world 1 points 3 days ago

A safe bet is the best bet.

[–] ekZepp@lemmy.world 3 points 3 days ago (3 children)
[–] ekZepp@lemmy.world 2 points 3 days ago* (last edited 3 days ago) (11 children)
 

PS. This is not a critique to Debian-based distros. And i'm not suggesting you to skip Ubintu for Arch either. Arch is a bit advanced and not too easy to new users, so that won't do for some people...

... just install Linux Mint instead.

 

Freelance Zbrush artist / digital concept sculptor

https://www.artstation.com/mutte

https://www.artstation.com/artwork/nJx0xX

[–] ekZepp@lemmy.world 3 points 6 days ago* (last edited 6 days ago)

I personally would suggest you to keep Mint for the main work and install some other distro in dual boot to test out. Some Arch derivative like CachyOS or EndeavourOS are light fast and have all the latest toys of Arch with included an easy installer and some decent software manager for beginners still not too used to the terminal. Just remember, newest stuff = less tested stuff, so keep some backup.

[–] ekZepp@lemmy.world 21 points 6 days ago

Finally someone get it. Thank you. 👍

 
[–] ekZepp@lemmy.world 3 points 1 week ago

So, someone from G have actually checked the game in the end. I can only imagine the surprise.

[–] ekZepp@lemmy.world 7 points 1 week ago* (last edited 1 week ago)

They know there will be riots when the fat fuck will not step down after loosing the election so they want people to be scared and sheep away.

 

Trailer: https://www.youtube.com/watch?v=H-43VeYGiPM

Warner Bros.’ bizarre 2023 decision to shelve its live-action/animated film, Coyote vs. Acme, sparked outrage both in the industry and among fans online. But the film is finally being released, and Ketchup Entertainment, its new distributor, recently released the trailer. All I can say after watching that trailer is, what the heck was Warner Bros. even thinking? Granted, a killer trailer doesn’t automatically mean it’s a great film, but all the winning elements are here.

 

“It is a universe that lends itself to interactivity. You have detectives, a dark and horrific world, creatures, and ancestral cults devoted to ancient entities. It is a rich and expansive lore.”

So enthuses Tommaso Nuti, Game Director at Big Bad Wolf and creative mind behind the recently-released Cthulhu: The Cosmic Abyss, when asked why H.P. Lovecraft’s singular imaginings seem to be so much more popular in the gaming world than they are in other art forms. Indeed, while there’s a relative dearth of cosmic horror outings nowadays in cinema or on television, it sometimes feels like you can barely move for them on the Steam store. (...)

 
 

cross-posted from: https://lemmy.world/post/45925326

It's amazing what a difference a little bit of time can make: Two years after kicking off what looked to be a long-shot campaign to push back on the practice of shutting down server-dependent videogames once they're no longer profitable, Stop Killing Games founder Ross Scott and organizer Moritz Katzner appeared in front of the European Parliament to present their case—and it seemed to go very well.

Official Stream: https://multimedia.europarl.europa.eu/en/webstreaming/committee-on-internal-market-and-consumer-protection-ordinary-meeting-committee-on-legal-affairs-com_20260416-1100-COMMITTEE-IMCO-JURI-PETI

Digital Fairness Act: https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14622-Digital-Fairness-Act/F33096034_en

 

It's amazing what a difference a little bit of time can make: Two years after kicking off what looked to be a long-shot campaign to push back on the practice of shutting down server-dependent videogames once they're no longer profitable, Stop Killing Games founder Ross Scott and organizer Moritz Katzner appeared in front of the European Parliament to present their case—and it seemed to go very well.

Official Stream: https://multimedia.europarl.europa.eu/en/webstreaming/committee-on-internal-market-and-consumer-protection-ordinary-meeting-committee-on-legal-affairs-com_20260416-1100-COMMITTEE-IMCO-JURI-PETI

Digital Fairness Act: https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14622-Digital-Fairness-Act/F33096034_en

view more: next ›