Dirty Frag: Universal Linux LPE
191–200 of 370 posts
Re: Dirty Frag: Universal Linux LPE
#192Earlier quoted context omitted.
I don’t think that’s what the OP is saying at all, just that using LLMs needs to be a cooperative research process. Also I see you jumping around a lot to the defense of LLMs when I don’t think anyone is really attacking them. Maybe cool it a bit.
From the thread that ensued I feel comfortable that my interpretation of the comment (or rather, my confusion about it) was in fact germane.
So like I said, just chill out.
Re: Dirty Frag: Universal Linux LPE
#193If this indeed works on all major distributions, I just continue to be amazed by how irresponsible the maintainers are. We're talking about optional kernel functionality that's presumably useful to something like This feels like the practice of Linux distros back in 1999 when they'd ship default installs with dozens of network services exposed to the internet. Except it's not 1999 anymore.
Distro maintainers blacklisting specific functionality because they believe YAGNI is a pretty big ask. They just don't know who is using what. It's always possible for users to go back and tailor their builds for the stuff they actually want. And... I remember the early days of Linux where I ran `make menuconfig` and selected exactly the functionality I wanted in my kernel. I'd... rather not end up back there. That s…
We have forgotten what a distro is, and its modern corruption of the concept is now taken as the definition.
Distributions weren't meant to be competing generic universal bundles of userspace tools in addition to the kernel.
Re: Dirty Frag: Universal Linux LPE
#194Tanenbaum was right
Re: Dirty Frag: Universal Linux LPE
#195Re: Dirty Frag: Universal Linux LPE
#196Earlier quoted context omitted.
Are they already vulnerable to RCE as an unprivileged user? Hopefully not. An LPE only allows an attacker who can already execute code on the system to become root. So, bad, yes, but it doesn't mean you are immediately pwned.
Should I rush to Lambda or ECS and turn off all my containers sharing a host with who the hell knows?
Re: Dirty Frag: Universal Linux LPE
#197If this indeed works on all major distributions, I just continue to be amazed by how irresponsible the maintainers are. We're talking about optional kernel functionality that's presumably useful to something like This feels like the practice of Linux distros back in 1999 when they'd ship default installs with dozens of network services exposed to the internet. Except it's not 1999 anymore.
Linux distro maintainers are the most responsible software maintainers on the planet. Their security practices are miles beyond the stupid programming language package managers, they maintain a select list of packages, vet changes, patch bugs, resolve complex packaging issues, backport fixes, use tiered releases, distribute files to global mirrors, and cryptographically validate all files. And might I remind you, they do all this for free.
Re: Dirty Frag: Universal Linux LPE
#198can this also be used to obtain container escape ?
If your container has setuid binaries and these modules are loaded, yes.
Re: Dirty Frag: Universal Linux LPE
#199Earlier quoted context omitted.
You appear to want to die on the hill of "This vulnerability would never have been found if we lived in a world without LLM AI" which is a very strange hill to die on. There's no question that we live in the world where LLM AI was involved in finding the copy fail vulnerability at this specific time, and it's completely normal for people to see a vulnerability and then look closer and find related vulnerabilities or…
It's weird to say I want to "die on this hill" because that's not even something I believe. There was nothing especially difficult about this particular vulnerability. My only observation that nobody did find it before, then an LLM security firm went out looking for Linux LPEs, and thus it was discovered. That is a very difficult fact pattern to which to attach the conclusion "LLMs have sabotaged security research" (…
Re: Dirty Frag: Universal Linux LPE
#200I would like to see the same hate comments about Linux than the ones we would see if it was a Windows vulnerability...