My team prefixes [security-crew] to our mailing list, and Christophe designed a logo for those characters. For the back of the shirt, I re-modified pixel art of defending angels slaying demons and shared it with Christophe. He knew exactly what I was looking!
A researcher from @VulnCheckAI noticed out that the below domains are all being used to generate CVEs.
My hunch is that someone is farming CVEs from @vuldb and @MITREcorp. Both have assigned ~500 CVEs for these "projects".
@spendergrsec The feels appropriate if BlueZ agrees to use Kernel as a CNA.
( CVE's don't specifying *requiring* CPE, or CVSS, or even a useful description )
@spendergrsec Have you requested a revocation?
If the Kernel CNA doesn't respond or revoke, raise this to their root/lr-root CNA. And if they don't address it, the Secretariat of the CVE Program.
Keep an eye on https://t.co/Y0apPHShvg
The โpesky pipeโ attack from RFPโs Phrack 55 article (1999) was recently used twenty-five years later in Qualysโ LPE in needrestart disclosure (2024):
https://t.co/1xdIpDo59h
The Qualys Threat Research Unit (TRU) has discovered five vulnerabilities. These vulnerabilities can be exploited by any unprivileged user to gain full root access without requiring user interaction. Read about TRU's discovery in our #blog. https://t.co/fMGIqNVeHD #needrestart
Giving a talk later today @linuxplumbers about kernelCTF and mitigations! We had to upload the slides before the talk, so sharing them here too because why not ;-P https://t.co/XHYLCJfTR6
Great write-up by Rory McNamara (@PsychoMario) for @snyksec on a root privilege escalation toolchain which leverages DBus, CUPS, and WPA on Ubuntu: https://t.co/f7B1nHHL3G
@spendergrsec@evilsocket@daveaitel@grsecurity This is good advice, but if this is not public I would work with upstream and distro security teams first. If they take no action, you can always disclose to distros later. The issue with distros is that you want a patch in hand, since there is a 14 day maximum disclosure period.