Live data from Hacker News

Dirty Frag: Universal Linux LPE

openwall.com

321–330 of 370 posts

Re: Dirty Frag: Universal Linux LPE

#322

Does anyone know whether Debian is vulnerable? I tried the exploit on a Debian 12+Debian 13 machine but wasn't able to reproduce it myself.

https://security-tracker.debian.org/tracker/CVE-2026-43500

https://security-tracker.debian.org/tracker/CVE-2026-43284

Re: Dirty Frag: Universal Linux LPE

#323

Earlier quoted context omitted.

The attack gives you ability to overwrite any cached page. So you don't need to be root to "edit" /etc/passwd.

Not of the host system, assuming we're talking about a compromised VM, running as a non-root user.

I assume you mean container, not VM. But yes, container makes it harder.

Re: Dirty Frag: Universal Linux LPE

#325
post #20

Earlier quoted context omitted.

There is a finite number of bugs and betters tools that find them mean there is less bugs in the code.

We already find bugs constantly in Linux and they go unaddressed, no one even keeps up with syzkaller reports lol AI is neat because it's higher signal but yeah no, we're not getting anywhere close to "safe linux", AI or not.

I want to believe, okay

Re: Dirty Frag: Universal Linux LPE

#326

Earlier quoted context omitted.

> When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. Very much aligns with my experience. For me this is the most unsatisfying thing about AI-based workflows in general, they miss stuff humans would never miss. All the time I wonder what am I missing that's right nearby? It's remarkable how many times I have to ask Claude code to fully ingest something…

Actually lately I’ve been feeling the other way around with it. The LLM catches things I would have overlooked. I ask for a new feature in a certain file, and the LLM suggests fixing a tangentially related file to accommodate the new feature without breaking something else. Maybe this is just the crap legacy codebase I’m working with and how tangled up everything is, but I definitely have found several times now that…

> The LLM catches things I would have overlooked. I ask for a new feature in a certain file, and the LLM suggests fixing a tangentially related file to accommodate the new feature without breaking something e

What are you using? Do you think this behavior is in response to prompting? My goal at times is to "rabbit hole" the LLM to get it to go down rabbit holes and find bigger and bigger picture issues until it homes in on something fundamentally broken that could have big impact if fixed. But it's not trivial to push the agent in that direction for me.

Re: Dirty Frag: Universal Linux LPE

#327

Earlier quoted context omitted.

> When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. Very much aligns with my experience. For me this is the most unsatisfying thing about AI-based workflows in general, they miss stuff humans would never miss. All the time I wonder what am I missing that's right nearby? It's remarkable how many times I have to ask Claude code to fully ingest something…

Do you think this is inherent or an artifact of prompting? Curiosity and side quests leads to higher token usage and longer time to finish, so I could understand why current harnesses and system prompts would not encourage that sort of thing. But what if a coding agent was prompted to be more curious during development? Like a human developer, make mental notes of alternatives to try out and chase suspicious looking…

> Do you think this is inherent or an artifact of prompting?

Not sure! I mean, look at this sibling comment for example: https://news.ycombinator.com/item?id=48062797. Not my experience, but apparently others have this experience.

> But what if a coding agent was prompted to be more curious during development?

I've tried using the language of curiosity. My qualitative take was that it did have a positive impact, but not much. And I can only tinker with system prompting so much, before I get drawn into LLM driving :)

> which is that everyone's style of work is going to converge

yeah I imagine even people's styles of thinking will converge as a result of this, more so than from reading other people's prose or programs. I think I saw something on HN to this effect within the last month, too.

Re: Dirty Frag: Universal Linux LPE

#328
post #18

This is very similar in root cause and exploitation to Copy Fail. Which illustrates pretty well something that's lost when relying heavily on LLMs to do work for you: exploration. I find that doing vulnerability research using AI really hinders my creativity. When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. It's like a genie - you get exactly what yo…

Where does it say that the Dirty Frag one was found by LLMs? The research site with all the information doesn't mention LLM or AI at all.

Re: Dirty Frag: Universal Linux LPE

#329
post #60
post #40

Earlier quoted context omitted.

I don't follow. LLMs spotted these bugs in the first place . You seem to be saying that these discoveries are indications that they're bad for vulnerability discovery.

I don't think the copy.fail people understood the issue they found, as is evident by the heavy focus on AF_ALG/aead_algif, which is essentially "innocent" as we're seeing here. I think LLMs are great for vulnerability discovery, but you need to not skimp on the legwork and understanding what even you just found there.

Am I missing something? Where does it say that the researcher that found Dirty Frag used LLM to find it? Have you read the original report from the researcher?

Re: Dirty Frag: Universal Linux LPE

#330

Earlier quoted context omitted.

Actually lately I’ve been feeling the other way around with it. The LLM catches things I would have overlooked. I ask for a new feature in a certain file, and the LLM suggests fixing a tangentially related file to accommodate the new feature without breaking something else. Maybe this is just the crap legacy codebase I’m working with and how tangled up everything is, but I definitely have found several times now that…

> The LLM catches things I would have overlooked. I ask for a new feature in a certain file, and the LLM suggests fixing a tangentially related file to accommodate the new feature without breaking something e What are you using? Do you think this behavior is in response to prompting? My goal at times is to "rabbit hole" the LLM to get it to go down rabbit holes and find bigger and bigger picture issues until it homes…

I sort of switch around, Claude, sometimes Codex. Probably more Claude than Codex. If Claude’s down then codex, or Gemini.
Post reply on HN