this is why you don't contact distro mailing list. responsible disclosure is dead.
HN user
x4132
to which distros? how do you ensure fairness? Do you report this to the maintainer of Red Star OS (north korea)?
The kernel security team was given the heads up a month ago. At that point it is their decision.
sorry yeah, I saw not exploitable on Android and thought most SELinux would be ok. Not super sure on this case what the surface is
so what? we should never disclose anything? this will only result in companies suppressing disclosure and leaving vulnerabilities unpatched.
are you sure containerization would be more secure? this is also a rootless podman escape. the lesson here is to not give random people shell access to your systems.
this is because the `su` binary is replaced with x86 shellcode, replace it with aarch64 and it will work just the same.
there is a PoC floating around for Alpine.
it's advertising their AI, not the talents of their humans :D
i mean, it doesn't work on any SELinux, but it's still quite severe anyhow
ctrl + o isn't live - that's not what users want, what users want is the OPTION to choose what we want to see.
not surprised about the chrome part, but pretty shocked at the phone OS part. I know APFS migration was done in this way, but wouldn't storage considerations for this be massive?
goddamn, almost missed out such a cool extra layer, thanks for the tip!