Our security labs team found a privilege escalation vulnerability chain in Ubuntu 24.04. Read about the journey of discovery and exploitation here: https://t.co/CLtJJicd5P #vulnerability#0day
[1/6] We survived the "RCE Linux" apocalypse which finally turned out to be a bunch of vulns in CUPS (printing softw for Unix). Writeup by @evilsocket is still funny and well-written but the real impact is very limited by the fact that CUPS is not typically installed in servers.
🚨 New advisory was just published! 🚨
A critical out-of-bound access vulnerability has been identified in the Linux Kernel. This vulnerability was disclosed by a security researcher participating in TyphoonPWN 2024.
https://t.co/cMyDiEPrDL
In the spirit of kicking a dead horse while it's down, here's a PoC for what *was* another n_gsm 0day: https://t.co/ANsuVISXgM
This is patched in newer kernels since 67c3775689, but is probably still 0day for anything <6.6, or anything not on an LTS release.
have fun
We (@vaber_b and I) have discovered a Google Chrome zero-day that is actively used in targeted attacks. It was just fixed as CVE-2024-4947 and we're going to reveal more details soon 🔥🔥🔥. Update now! https://t.co/8guemaDow0
However, due to an issue that arose a few days ago, an exploit for the same vulnerability was made public. Consequently, I've decided to share my research findings a bit earlier than planned.
Some might wonder why I'm disclosing a zero-day exploit. I discovered this vulnerability a few months ago and had no intention of making it public until a patch was released.
I've reported the vulnerabilities that have been analyzed, and I plan to report the remaining ones shortly. It's likely that I will soon make a brief post about how I analyzed n_gsm, including the fuzzing process.
https://t.co/QmHFZopsLu
It seems there has been an interesting incident related to the n_gsm vector of the Linux kernel.
While it's still unclear who is right and who is wrong, one thing can be asserted: my bug will soon be patched, and I need more caffeine. 😂
https://t.co/23Wwtwmqis
The person who first posted about this bug, jmpeax, claims to have run syzkaller on n_gsm. I also used syzkaller to fuzz the same vector and found several other vulnerabilities, not just the one in question.
I don't often tweet about patched bugs, but here's one that looks interesting - let's discuss ZDI-24-195 or kernel commit 38d20c62903d669693a1869aa68c4dd5674e2544, in a short 🧵
I found a couple vulnerabilities in ksmbd, and plan to blog a writeup on how I found them in the near future.
ZDI-24-194, ZDI-24-195
https://t.co/pnMI7JS6af