another day another LPE exploit - Fragnesia

AnthonySmithAnthonySmith AdministratorHosting ProviderOGSenpai
edited May 13 in Technical

https://lwn.net/Articles/1072647/
https://lwn.net/ml/all/[email protected]/

This is a separate bug in the ESP/XFRM from dirtyfrag which has received its own patch. However, it is in the same surface and the mitigation is the same as for dirtyfrag.

It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to achieve arbitrary byte writes into the kernel page cache of read-only files, without requiring any race condition.

TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x3, FR, AU, PL, NL
FREE tokens on sign up, try before you buy. | Join us on Reddit

Thanked by (5)oloke tentor WSS host_c sh97

Comments

Sign In or Register to comment.