SERIOUSLY? AGAIN?

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A breakdown of 'Dirty Frag', a newly disclosed Linux local privilege escalation vulnerability (or rather two chained vulnerabilities) that follows closely after the Copy Fail exploit. The first variant abuses IPSec ESP's in-place decryption on nonlinear socket buffers (SKBs) to perform an out-of-bounds write into a page cache entry for /usr/bin/su. The second, more complex variant uses the RXRPC subsystem's F-Crypt block cipher, which also decrypts in place, and brute-forces the decryption key to overwrite /etc/password so that root has no password. Both bugs exploit the same primitive: splicing file descriptors to attach privileged pages to a socket buffer, then triggering an in-place crypto operation that skips copy-on-write protections. The author notes that AI-assisted vulnerability research is likely accelerating the discovery of such kernel exploit primitives.

12m watch time
8 Impressions