💥 Introducing "Dirty Frag"
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation.
Details:
https://t.co/9nqku4svkY
@dynatodd The last metric by which one should measure their AI usage if they do not have equity in the product — self-selling person of the year award.
Future job prediction:
🚨 Corporate Ghostbusters 👻🤖
When AI models start going rogue in enterprise environments, someone’s gotta step in, debug the chaos, and trap wild algorithms before they take down production. „Who you gonna call?“
I too woke up and choose violence today as the fail-copy POC dropped.
Made a clean exploit including fixing the UID post exploitation without rebooting the target server. Smoke those CTF’s in hack the box.
https://t.co/nRiFyXQzRe