This is very similar in root cause and exploitation to Copy Fail. Which illustrates pretty well something that's lost when relying heavily on LLMs to do work for you: exploration. I find that doing vulnerability research using AI really hinders my creativity. When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. It's like a genie - you get exactly what yo…
Dirty Frag: Universal Linux LPE
331–340 of 370 posts
Re: Dirty Frag: Universal Linux LPE
#332Earlier quoted context omitted.
At present it looks to me like the embargo was broken by someone identifying the patch as fixing a vulnerability, not someone leaking the mailing list. More information may come out, or I might be missing something, but assuming that the above is accurate, this isn't a problem with responsible disclosure or mailing list opsec; it's a problem with the nature of open source. Right? Or are folks seriously proposing that…
> Or are folks seriously proposing that the patch/mitigations should have been circulated to distro maintainers privately before going to mainline? I always assumed that distro maintainers got early access to patches before going mainline but maybe that’s not true?
Re: Dirty Frag: Universal Linux LPE
#333Does anyone know whether Debian is vulnerable? I tried the exploit on a Debian 12+Debian 13 machine but wasn't able to reproduce it myself.
Re: Dirty Frag: Universal Linux LPE
#334Earlier quoted context omitted.
Can you elaborate on that?
Have a look at https://github.com/atgreen/rhel-block-copyfail
Have you considered writing up a blog post and submitting this to HN?
Re: Dirty Frag: Universal Linux LPE
#335Re: Dirty Frag: Universal Linux LPE
#336This is very similar in root cause and exploitation to Copy Fail. Which illustrates pretty well something that's lost when relying heavily on LLMs to do work for you: exploration. I find that doing vulnerability research using AI really hinders my creativity. When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. It's like a genie - you get exactly what yo…
Re: Dirty Frag: Universal Linux LPE
#337I'm curious what broke the embargo. Did it leak or did a third party find it independently?
Re: Dirty Frag: Universal Linux LPE
#338Earlier quoted context omitted.
And again it's band-aiding the problem. Can authencesn not be fixed or what?
Maybe write to the LKML if you have some privy information?
Re: Dirty Frag: Universal Linux LPE
#339Earlier quoted context omitted.
https://www.androidpolice.com/google-support-linux-kernels-a... Google relies on Linux LTS kernels. When the Linux LTS team dropped support from 6 years down to 2 years, Google stepped in to cover the 4-year gap. It is Linux. It's basically a distro.
When people say Linux they mean GNU/Linux.
Re: Dirty Frag: Universal Linux LPE
#340Earlier quoted context omitted.
When people say Linux they mean GNU/Linux.
In common parlance, yes -- because there is no practical distinction. But in cases where something is just using the Linux kernel without GNU and other common userpand components (and there is a practical distinction) then it's definitionally untrue to say that it's "not Linux" if you really meant to say "it's not GNU/Linux".