▲ 334 ▼ Serious Linux vulnerability affecting nearly every system. Patch your systems. (copy.fail) submitted 4 months ago by Flax_vert@feddit.uk to c/selfhosted@lemmy.world 74 comments fedilink hide all child comments
[–] BlackLaZoR@lemmy.world 6 points 4 months ago* (3 children) Nothing much to do for me. Just apply patches as normal. Edit: I wonder how bad is it on Android permalink fedilink source hideshow 6 child comments replies: [–] Hobo@lemmy.world 3 points 4 months ago I don't think af_alg is exposed to non-root users on android. permalink fedilink source parent [–] GamingChairModel@lemmy.world 2 points 4 months ago (1 child) Android doesn't have su, which this proof of concept exploit requires. Although rooted Android does, so in theory malware written for rooted Android could escalate to root privileges. Also, the underlying vulnerabilities might be exploitable without su but I don't fully understand the AF_ALG and authencesn bug limits things, or what other executables can escalate privileges. permalink fedilink source parent hideshow 2 child comments replies: [–] wewbull@feddit.uk 2 points 4 months ago (1 child) Don't need specifically SU by my understanding. Just any suid executable. permalink fedilink source parent hideshow 2 child comments replies: [–] GamingChairModel@lemmy.world 2 points 4 months ago Ah yeah. Plus apparently Android's default SELinux configuration blocks this separately, as well. permalink fedilink source parent [–] mexicancartel@lemmy.dbzer0.com 0 points 4 months ago I wished android is affected but no permalink fedilink source parent
[–] Hobo@lemmy.world 3 points 4 months ago I don't think af_alg is exposed to non-root users on android. permalink fedilink source parent
[–] GamingChairModel@lemmy.world 2 points 4 months ago (1 child) Android doesn't have su, which this proof of concept exploit requires. Although rooted Android does, so in theory malware written for rooted Android could escalate to root privileges. Also, the underlying vulnerabilities might be exploitable without su but I don't fully understand the AF_ALG and authencesn bug limits things, or what other executables can escalate privileges. permalink fedilink source parent hideshow 2 child comments replies: [–] wewbull@feddit.uk 2 points 4 months ago (1 child) Don't need specifically SU by my understanding. Just any suid executable. permalink fedilink source parent hideshow 2 child comments replies: [–] GamingChairModel@lemmy.world 2 points 4 months ago Ah yeah. Plus apparently Android's default SELinux configuration blocks this separately, as well. permalink fedilink source parent
[–] wewbull@feddit.uk 2 points 4 months ago (1 child) Don't need specifically SU by my understanding. Just any suid executable. permalink fedilink source parent hideshow 2 child comments replies: [–] GamingChairModel@lemmy.world 2 points 4 months ago Ah yeah. Plus apparently Android's default SELinux configuration blocks this separately, as well. permalink fedilink source parent
[–] GamingChairModel@lemmy.world 2 points 4 months ago Ah yeah. Plus apparently Android's default SELinux configuration blocks this separately, as well. permalink fedilink source parent
[–] mexicancartel@lemmy.dbzer0.com 0 points 4 months ago I wished android is affected but no permalink fedilink source parent