Live data from Hacker News

Dirty Frag: Universal Linux LPE

openwall.com

331–340 of 370 posts

Re: Dirty Frag: Universal Linux LPE

#331
post #18

This is very similar in root cause and exploitation to Copy Fail. Which illustrates pretty well something that's lost when relying heavily on LLMs to do work for you: exploration. I find that doing vulnerability research using AI really hinders my creativity. When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. It's like a genie - you get exactly what yo…

Maybe. This phenomenon of security holes being found closely to each other was also common before LLMs. People attention gets directed to a place and typically more issues are getting found.

Re: Dirty Frag: Universal Linux LPE

#332

Earlier quoted context omitted.

At present it looks to me like the embargo was broken by someone identifying the patch as fixing a vulnerability, not someone leaking the mailing list. More information may come out, or I might be missing something, but assuming that the above is accurate, this isn't a problem with responsible disclosure or mailing list opsec; it's a problem with the nature of open source. Right? Or are folks seriously proposing that…

> Or are folks seriously proposing that the patch/mitigations should have been circulated to distro maintainers privately before going to mainline? I always assumed that distro maintainers got early access to patches before going mainline but maybe that’s not true?

[deleted]

Re: Dirty Frag: Universal Linux LPE

#334

Earlier quoted context omitted.

Can you elaborate on that?

Have a look at https://github.com/atgreen/rhel-block-copyfail

I was aware of commercial antivirus vendors (Crowdstrike) doing something like this, but this is the first I've seen it published by somebody in the open!

Have you considered writing up a blog post and submitting this to HN?

Re: Dirty Frag: Universal Linux LPE

#336
post #18

This is very similar in root cause and exploitation to Copy Fail. Which illustrates pretty well something that's lost when relying heavily on LLMs to do work for you: exploration. I find that doing vulnerability research using AI really hinders my creativity. When your workflow consists of asking questions and getting answers immediately, you don't get to see what's nearby. It's like a genie - you get exactly what yo…

AI or not, it’s always been reasonable common that a bunch of related vulnerabilities get discovered after shortly after the original one.

Re: Dirty Frag: Universal Linux LPE

#337
post #13

I'm curious what broke the embargo. Did it leak or did a third party find it independently?

It seems like the embargo bit is a bit spun. The exploit is a reasonable extension of ideas from Copy Fail and was independently discovered in public (on X, it seems like) before Kim's "embargo" had expired. No one broke any trust, the independent discoverer just didn't follow as rigorous a process.

Re: Dirty Frag: Universal Linux LPE

#338

Earlier quoted context omitted.

And again it's band-aiding the problem. Can authencesn not be fixed or what?

Maybe write to the LKML if you have some privy information?

I don't have enough hubris to assume I know things the people on LKML (or actually netdev in this case) don't. If anything, I might unicast a mail to Steffen.

Re: Dirty Frag: Universal Linux LPE

#339
post #236
post #55

Earlier quoted context omitted.

https://www.androidpolice.com/google-support-linux-kernels-a... Google relies on Linux LTS kernels. When the Linux LTS team dropped support from 6 years down to 2 years, Google stepped in to cover the 4-year gap. It is Linux. It's basically a distro.

When people say Linux they mean GNU/Linux.

[deleted]

Re: Dirty Frag: Universal Linux LPE

#340
post #241
post #236

Earlier quoted context omitted.

When people say Linux they mean GNU/Linux.

In common parlance, yes -- because there is no practical distinction. But in cases where something is just using the Linux kernel without GNU and other common userpand components (and there is a practical distinction) then it's definitionally untrue to say that it's "not Linux" if you really meant to say "it's not GNU/Linux".

I've always thought this was extremely interesting: https://chimera-linux.org/
Post reply on HN