Sam James <[email protected]> writes: > Jan Schaumann <[email protected]> writes: > >> Hi, >> >> This is currently making the rounds and looks pretty >> severe: >> >> https://copy.fail/ >> >> A local privilege escalation vulnerability with a >> working PoC python script exploiting a logic flaw in >> the kernel crypto API (AF_ALG) affecting most Linux >> distributions. >> >> More detailed write-up: >> https://xint.io/blog/copy-fail-linux-distributions >> >> [...] > > Are we aware of what precisely xint disclosed to the kernel security > team? > > My assumption based on the tool output in the write-up is that enough > was disclosed to know this was at least an easily-exploitable LPE (*).
It's been pointed out to me that Brad Spengler has commented on X [0], linking to Brian Pak of xint saying [1]: > We also provided a fully working exploit to the kernel security team > when we reported. We’ve since learned that such details don’t > automatically get forwarded downstream and that Linux kernel commit > messages are typically kept minimal. That’s simply how the process works. So yes, the kernel team were very much aware of the impact from the offset. I hadn't seen Brian's thread until now, it is interesting reading [2]. Thanks to Brad and the person who sent me the link to the tweet. > > (*) Because part of their promotion here is for the tool's ability to > get the analysis right, so it implies that they didn't figure it out > later, and that the tool did "most of the work". Whether or not that's > actually the case, I of course don't know. > > thanks, > sam [0] https://xcancel.com/spendergrsec/status/2051045704487829878 [1] https://xcancel.com/brian_pak/status/2050255271184994538 [2] https://xcancel.com/brian_pak/status/2050255258098766101#m
signature.asc
Description: PGP signature
