Jan Schaumann <[email protected]> writes: > Hi, > > This is currently making the rounds and looks pretty > severe: > > https://copy.fail/ > > A local privilege escalation vulnerability with a > working PoC python script exploiting a logic flaw in > the kernel crypto API (AF_ALG) affecting most Linux > distributions. > > More detailed write-up: > https://xint.io/blog/copy-fail-linux-distributions > > [...]
Are we aware of what precisely xint disclosed to the kernel security team? My assumption based on the tool output in the write-up is that enough was disclosed to know this was at least an easily-exploitable LPE (*). (*) Because part of their promotion here is for the tool's ability to get the analysis right, so it implies that they didn't figure it out later, and that the tool did "most of the work". Whether or not that's actually the case, I of course don't know. thanks, sam
signature.asc
Description: PGP signature
