注册并分享邀请链接,可获得视频播放与邀请奖励。

Pirat_Nation 🔴 (@Pirat_Nation) “A newly discovered security vulnerability known as Copy Fail, or CVE-2026-31431,” — TopicDigg

Pirat_Nation 🔴 的个人资料封面
Pirat_Nation 🔴 的头像
Pirat_Nation 🔴
@Pirat_Nation
Tech & gaming analysis with the latest updates | TV & Films | alt: @piratnation | Official @skinscom Affiliate
加入 July 2022
94 正在关注    327.7K 粉丝
A newly discovered security vulnerability known as Copy Fail, or CVE-2026-31431, has been disclosed in the Linux kernel. It affects virtually every major Linux distribution released since 2017. The flaw sits in the kernel’s cryptographic subsystem and stems from a logic error introduced back in 2017: >It allows any local user without special privileges to escalate directly to root. >The exploit is unusually simple: a short Python script can reliably achieve this by modifying data only in the system’s memory cache rather than on disk. >In practice, an attacker can target any readable file, such as a setuid-root binary like sudo or su, and alter it only in RAM. >The change is invisible to file integrity monitors and leaves no trace on the hard drive. >The same technique also works from inside containers, potentially allowing an escape from Docker, Kubernetes, or similar environments to compromise the host server. >This makes Copy Fail both stealthy and highly portable across systems. Patches have already begun rolling out from major distributors. System administrators should apply the latest kernel updates and reboot as soon as possible.
显示更多
0
25
1.6K
150
转发到社区