Daaaaamn: "GhostLock was introduced in Linux 2.6.39 and fixed in Linux 7.1."
GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
51–60 of 209 posts
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#52Earlier quoted context omitted.
Since this enables container escape, sounds like this might still impact quite a lot of us?
I guess, if you thought Docker/etc. was a security boundary
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#53> This is the same shape as many other life-cycle bugs [...] Claude-ism detected. IME with Claude Code an object does not have a type or definition, apparently, but rather a shape (or at least it reaches for that word before more technically-accurate ones). Problems are not of a similar class or type, but of the same shape. Functions are not defined by their signatures but by their shape. Who talks like this and how…
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#54Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#55Earlier quoted context omitted.
I guess, if you thought Docker/etc. was a security boundary
They are a security boundary. The fact that you need a vulnerability to escape them is proof of that. They just don't have a particularly high cost of escape because reachable kernel vulnerabilities are so common.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#56Earlier quoted context omitted.
I think you're probably right that the article was AI-assisted, but (if so) it's important not to confuse that with the thing the article is about. Google wouldn't pay $90k for a hallucination. I don't mean that as a criticism—the question of how to receive AI-processed content is chaotic right now. I'm working on a post about that here: https://news.ycombinator.com/item?id=48887149 . Btw, Nebula Sec is a YC startup…
A thing that notably triggers my allergies is that if significant human effort went into something, a few paragraphs written by a human seems like a trivial additional investment; if that last touch is missing, it's really hard for me to extend the benefit of the doubt that there really is something there. Obviously this is only one signal among many, one that can be overruled, but the ick remains regardless.
For example, non-native English speakers (as is the case with these guys IIRC) frequently use these tools. Maybe they shouldn't—as I've been telling a lot of people who email, mistakes are rapidly becoming a sign of authenticity at this point—but the belief that they need to is widespread, and this doesn't mean they didn't do significant work.
(Side note: it's a common assumption that machine-translated text is in a different category from LLM-edited text. From what we're seeing, that assumption is unfortunately wrong.)
Another important case is people with disabilities who find these technologies assistive. Again, one can argue that they're increasingly better off just posting their own writing in the raw, but this is a pretty obscure point to get across to people, and in some cases it would impose a significant burden.
Beyond those cases, a lot of people just don't write easily, and/or don't feel their writing is any good. A lot of them are using LLMs to compensate for that, and this by no means implies that their work is bad. Maybe they just have a phobia about writing and/or don't express themselves well that way.
People who enjoy writing or are confident writers fail to understand how emotionally fraught writing is for many others.
Personally I'm down with the "writing is thinking" view, from which it follows that bad writing is bad thinking. But it doesn't follow that "thinking is writing" - that's a much stronger claim, from which it would follow that good thinking is good writing—and this I think is false.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#57Earlier quoted context omitted.
Seems low considering the wide impact, but maybe the only thing corporations throw big money at is remote exploits?
That's a huge amount of money for a vulnerability.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#58Earlier quoted context omitted.
[flagged]
Please don't be snarky or cross into putdowns or personal attack. We're all in (let's call it) the unlucky 10,000 about something. About most things actually. https://news.ycombinator.com/newsguidelines.html
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#59Earlier quoted context omitted.
A thing that notably triggers my allergies is that if significant human effort went into something, a few paragraphs written by a human seems like a trivial additional investment; if that last touch is missing, it's really hard for me to extend the benefit of the doubt that there really is something there. Obviously this is only one signal among many, one that can be overruled, but the ick remains regardless.
I agree to an extent, but there are many exceptions, so one can't really withhold the benefit of the doubt. For example, non-native English speakers (as is the case with these guys IIRC) frequently use these tools. Maybe they shouldn't—as I've been telling a lot of people who email, mistakes are rapidly becoming a sign of authenticity at this point—but the belief that they need to is widespread, and this doesn't mean…
If one doesn’t put effort in their writing, I am not going to put effort to read whatever slop they put out instead. Simple as that.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#60Earlier quoted context omitted.
I agree to an extent, but there are many exceptions, so one can't really withhold the benefit of the doubt. For example, non-native English speakers (as is the case with these guys IIRC) frequently use these tools. Maybe they shouldn't—as I've been telling a lot of people who email, mistakes are rapidly becoming a sign of authenticity at this point—but the belief that they need to is widespread, and this doesn't mean…
Non-native speakers have learned and improved their English for decades by trial-and-error, let’s stop using that as an excuse to use LLMs. I have been there, and making mistakes is how one learns to communicate effectively in another language. If one doesn’t put effort in their writing, I am not going to put effort to read whatever slop they put out instead. Simple as that.
That may sound like too fine a distinction, but it isn't. Here's an example: Show HN: Getting GLM 5.2 running on my slow computer - https://news.ycombinator.com/item?id=48842459, which was the #1 thread on HN a couple days ago (https://news.ycombinator.com/front?day=2026-07-09).
That user is a non-native English speaker who helped get his posts into a format that HN could appreciate. His work is obviously excellent—the community response was unambiguous. But I don't think it would have made it through without our help.
I'm sure you weren't saying that if someone can't describe their work in good English then it must be slop, but the space is larger than you make it sound. Which is unfortunate in a way—it would be easier to narrow it down, but then we'd miss posts like that one.