Celah kernel Linux Fragnesia baru terungkap

Kerentanan eskalasi hak istimewa lokal pada Linux yang dikenal sebagai Fragnesia telah diungkap ke publik. Celah ini dideskripsikan serupa dengan Dirty Frag dan melibatkan bug logika ESP/XFRM.

Kerentanan ini memungkinkan penulisan byte arbitrer ke dalam kernel page cache dari file yang bersifat read-only. Kemampuan ini dapat memungkinkan penyerang lokal untuk mendapatkan hak istimewa yang lebih tinggi pada sistem yang terdampak.

Artikel Terkait

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
Gambar dihasilkan oleh AI

Linux CopyFail exploit threatens root access amid Ubuntu outage

Dilaporkan oleh AI Gambar dihasilkan oleh AI

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

A security researcher has disclosed Dirty Frag, a new Linux kernel exploit that allows local users to gain root privileges. The flaw affects major distributions and remains unpatched on most systems despite earlier fixes for a similar issue.

Dilaporkan oleh AI

Qualys researchers have identified a logic flaw in the Linux kernel that enables unprivileged local users to disclose sensitive files and execute arbitrary commands as root.

A proposed update to the Linux scheduler aims to reduce frame time issues on aging computers during heavy CPU loads.

Dilaporkan oleh AI

Linux kernel maintainer Greg Kroah-Hartman presented a new Rust type at RustWeek 2026 that could prevent most security vulnerabilities. The approach focuses on handling untrusted data from userspace and hardware. It builds on existing Rust safety features already in the kernel.

Situs web ini menggunakan cookie

Kami menggunakan cookie untuk analisis guna meningkatkan situs kami. Baca kebijakan privasi kami untuk informasi lebih lanjut.
Tolak