Live data from Hacker News

FatGid: FreeBSD 14.x kernel local privilege escalation

fatgid.io

31–40 of 46 posts

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#32

TrueNAS is on FreeBSD, as well as lots of network equipment. This does affect us more than we think as operators.

Possibly Playstation as well.

PlayStation 4 was a fork of FreeBSD 9, and is immune to this bug introduced in 14. Sony also changes a LOT, I'm not sure anything dealing with unix credentials even exists in this fork. It's not clear how much FreeBSD is even used in PlayStation 5 (2020), but it would be based off 12 or earlier (also immune to this bug from 14) (13 was released in 2021).

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#33
post #22

Earlier quoted context omitted.

> You are strictly better off with the website than without it. Why? This is a better resource in every way: https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f... It details the actual problem instead of showing off tired stack exploit tricks.

No, that commit log is obviously not better than the page explaining the vulnerability and the exploit vectors. Case in point: what's "tired" about the stack exploitation techniques they're using here? And, while you're not right, even stipulating that you were, what would that matter? How is anyone better off with less explanation of a vulnerability?

The website explains an exploit. I've seen exploits before. The commit explains the unique issue.

I'm more interested in the why than the how.

I suppose people with different overall goals will see that differently.

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#34
post #22

Earlier quoted context omitted.

No, that commit log is obviously not better than the page explaining the vulnerability and the exploit vectors. Case in point: what's "tired" about the stack exploitation techniques they're using here? And, while you're not right, even stipulating that you were, what would that matter? How is anyone better off with less explanation of a vulnerability?

The website explains an exploit. I've seen exploits before. The commit explains the unique issue. I'm more interested in the why than the how. I suppose people with different overall goals will see that differently.

You didn't answer my question. What's "tired" about the exploit technique here?

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#36

TrueNAS is on FreeBSD, as well as lots of network equipment. This does affect us more than we think as operators.

Juniper JunOS is based on FreeBSD IIRC.

They've been moving their NOSes to a linux based platform.

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#37

Earlier quoted context omitted.

Alas, TrueNAS actually switched to Linux a couple of years ago.

FreeBSD was the reason I chose TrueNAS Core. Unfortunately, you are right, TrueNAS Scale (Linux) is where they are focusing all their attention. At this point I will not purchase additional TrueNAS equipment as I feel I was "rug pulled." I get that they are going after more of the Docker container/app market, but I just want a solid ZFS w/excellent networking NAS device. Linux is close to this ideal, but it isn't as…

> solid ZFS w/excellent networking NAS device.

illumos distros might be a good alternative. I have OmniOS[0] as a filer and SmartOS[1] running hypervisor duties on zones and bhyve.

[0] https://omnios.org [1] https://docs.smartos.org

Re: FatGid: FreeBSD 14.x kernel local privilege escalation

#40

I'm curious to see how many issues an LLM can find for OpenBSD. Not knocking OpenBSD at all, genuinely curious to see if all the careful development can stand up to LLMs.

Someone posted vague screenshots overnight of a bug in exit I think. Waiting on the write up.

Edit: ref: https://xcancel.com/ortegaalfredo/status/2057109561702580311

Post reply on HN