GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Hailey (hailey@hails.org)'s status on Friday, 08-May-2026 09:06:39 JST Hailey Hailey
    • Rich Felker

    @dalias oh there's an even newer one! https://www.openwall.com/lists/oss-security/2026/05/07/8

    In conversation about 5 months ago from hails.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      oss-security - Dirty Frag: Universal Linux LPE
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 09:06:38 JST Rich Felker Rich Felker
      in reply to

      @hailey Dirty frag is the same thing, just less clear what it's doing,

      In conversation about 5 months ago permalink
    • Embed this notice
      Hailey (hailey@hails.org)'s status on Friday, 08-May-2026 09:12:06 JST Hailey Hailey
      in reply to
      • Rich Felker

      @dalias oh wait no, I've got it mixed up. I think you're right

      In conversation about 5 months ago permalink
    • Embed this notice
      Hailey (hailey@hails.org)'s status on Friday, 08-May-2026 09:12:06 JST Hailey Hailey
      in reply to

      @dalias hold up, I see the iproute2 shell out. I disagree, I think AF_NETLINK is quite relevant. If you block that address family, you block the exploit. Most programs have no need for that address family, so it's unnecessary exposure. I'll revise my position when I see a poc which does not use AF_NETLINK

      In conversation about 5 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 09:22:01 JST Rich Felker Rich Felker
      in reply to

      @hailey That's what I said. You need a way to setup the network interfaces to exploit this, but it's fundamental that, if you can setup virtual network interfaces as a user, you can exploit this. The fact that AF_NETLINK is the mechanism by which you set them up isn't particularly important.

      Yes, you could cut off access to this one by preventing users from doing that, in a number of ways. Blocking netlink is just one. You could also nuke user namespaces. But now all sorts of stuff which in principle shouldn't be privileged needs suids, opening up net attack surface...

      Note that killing AF_NETLINK would break some libc interfaces applications might use, including at least mq_notify, getifaddrs, if_nameindex.

      In conversation about 5 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 10:52:43 JST Rich Felker Rich Felker
      in reply to

      @hailey If I wanted a big hammer to cut off this whole class of vuln without impacting important functionality, though, I'd just setup a global seccomp filter to block SYS_splice and related syscalls, or patch them out of the syscall table.

      In conversation about 5 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.