GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Hailey (hailey@hails.org)'s status on Friday, 08-May-2026 07:10:52 JST Hailey Hailey

    The latest (yes another) Linux kernel LPE also relies on an exotic socket type, AF_NETLINK. If you lock down allowed socket types to just internet+unix, you are safe.

    Unfortunately even rootless podman relies on AF_NETLINK sockets via pasta (user mode networking), so it's trickier if you're using containers. Good time to reconsider if you really need all the extra complexity containers bring.

    https://hails.org/@hailey/116492576900876035

    In conversation about 5 months ago from hails.org permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 07:10:51 JST Rich Felker Rich Felker
      in reply to

      @hailey AFAICT AF_NETLINK has nothing to do with the vuln. It's just the underlying mechanism for a lot of normal things. In this case user namespaces would even be a more plausible culprit for allowing users to reach the vulnerable code than AF_NETLINK is. But the culprit is splice and all the gratuitous zerocopy stuff you don't need unless you're trying to serve a video streaming platform with millions of users.

      In conversation about 5 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 17:56:32 JST Rich Felker Rich Felker
      in reply to

      @hailey The exploit I'm looking at, https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo, does not even mention AF_NETLINK. I suspect AF_NETLINK gets used by the iproute2 utilities (which they shell out to) for setting up the network namespace to do the exploit, but netlink being the mechanism is hardly relevant.

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        GitHub - 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
        Copy Fail 2: Electric Boogaloo. Contribute to 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo development by creating an account on GitHub.
    • Embed this notice
      Hailey (hailey@hails.org)'s status on Friday, 08-May-2026 17:56:33 JST Hailey Hailey
      in reply to
      • Rich Felker

      @dalias it looks like AF_NETLINK is in the critical path of the exploit poc at least? see add_xfrm_sa, it it responsible for actually writing the shellcode and does so via a netlink socket

      In conversation about 5 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.