* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, August 26, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

    The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

    ‘When Calls the Heart’ Fans All Want the Same Thing After Seeing the Show’s Latest Update – yahoo.com

    When Calls the Heart’ Fans Rally Together in Excitement Over Exciting New Update!

    Quotes of the Week: Peacemaker, Project Runway, Countdown and More – yahoo.com

    This Week’s Most Memorable Quotes from Peacemaker, Project Runway, Countdown, and More!

    Drake Appears in Teaser for Bobbi Althoff’s New Podcast ‘Not This Again’ – yahoo.com

    Drake Drops a Surprise Cameo in Bobbi Althoff’s Thrilling New Podcast Teaser ‘Not This Again

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    How to watch ‘F1: The Movie’ on Prime Video – About Amazon

    Experience the Thrill: How to Stream ‘F1: The Movie’ on Prime Video

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

    How AI and Technology Are Transforming the Future of Interactive Entertainment

    Ten upcoming sports stadiums where technology takes to the field – Dezeen

    10 Futuristic Sports Stadiums Revolutionizing the Game with Cutting-Edge Technology

    Figure Technology Solutions, Inc. Files Registration Statement for Proposed Initial Public Offering – Business Wire

    Figure Technology Solutions, Inc. Unveils Exciting Plans for Its Upcoming Initial Public Offering

    UNLV Responds to Workforce Need with Microcredential in Nuclear Technology – University of Nevada, Las Vegas | UNLV

    UNLV Unveils Cutting-Edge Microcredential Program to Fuel Growth in Nuclear Technology

    Why Technology Will Never Take Over Completely – Patheos

    Why Technology Will Never Completely Control Our Lives

    Alcorn State awarded grant to boost STEM with VR technology – WJTV

    Alcorn State Secures Grant to Transform STEM Education Through Cutting-Edge VR Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

    The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

    ‘When Calls the Heart’ Fans All Want the Same Thing After Seeing the Show’s Latest Update – yahoo.com

    When Calls the Heart’ Fans Rally Together in Excitement Over Exciting New Update!

    Quotes of the Week: Peacemaker, Project Runway, Countdown and More – yahoo.com

    This Week’s Most Memorable Quotes from Peacemaker, Project Runway, Countdown, and More!

    Drake Appears in Teaser for Bobbi Althoff’s New Podcast ‘Not This Again’ – yahoo.com

    Drake Drops a Surprise Cameo in Bobbi Althoff’s Thrilling New Podcast Teaser ‘Not This Again

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    How to watch ‘F1: The Movie’ on Prime Video – About Amazon

    Experience the Thrill: How to Stream ‘F1: The Movie’ on Prime Video

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

    How AI and Technology Are Transforming the Future of Interactive Entertainment

    Ten upcoming sports stadiums where technology takes to the field – Dezeen

    10 Futuristic Sports Stadiums Revolutionizing the Game with Cutting-Edge Technology

    Figure Technology Solutions, Inc. Files Registration Statement for Proposed Initial Public Offering – Business Wire

    Figure Technology Solutions, Inc. Unveils Exciting Plans for Its Upcoming Initial Public Offering

    UNLV Responds to Workforce Need with Microcredential in Nuclear Technology – University of Nevada, Las Vegas | UNLV

    UNLV Unveils Cutting-Edge Microcredential Program to Fuel Growth in Nuclear Technology

    Why Technology Will Never Take Over Completely – Patheos

    Why Technology Will Never Completely Control Our Lives

    Alcorn State awarded grant to boost STEM with VR technology – WJTV

    Alcorn State Secures Grant to Transform STEM Education Through Cutting-Edge VR Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

March 30, 2024
in Technology
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
Share on FacebookShare on Twitter

A Linux privilege-escalation proof-of-concept exploit has been published that, according to the bug hunter who developed it, typically works effortlessly on kernel versions between at least 5.14 and 6.6.14. 

Running the exploit as a normal user on a vulnerable machine will grant you root access to the box, allowing you to do whatever you want on it. This can be used by rogue insiders or malware already on a computer to cause further damage and problems.

This affects Debian, Ubuntu, Red Hat, Fedora, and no doubt other Linux distributions. The flaw finder, known by the handle Notselwyn, issued a highly detailed technical report of the bug this week, and said their exploit had a success rate of 99.4 percent on kernel 6.4.16, for instance.

The vulnerability is tracked as CVE-2024-1086. It is rated 7.8 out of 10 in terms of CVSS severity. It was patched at the end of January, updates have been rolling out since then, and if you haven’t yet upgraded your vulnerable kernel and local privilege escalation (LPE) is a concern, take a closer look at this thing.

“Never had I ever gotten so much joy developing a project, specifically when dropping the first root shell with the bug,” Notselwyn enthused.

The flaw is a double-free bug in the Linux kernel’s netfilter component involving nf_tables. As the US National Vulnerability Database explained:

All of that can lead to a crash or arbitrary code execution in the kernel upon exploitation. Before heading out for the Easter weekend we’d suggest patching first, again if LPE is a critical issue for you, so the only headache that greets you on Monday morning is pain from too much chocolate.

JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat

Nvidia’s newborn ChatRTX bot patched for security bugs

These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb

‘Thousands’ of businesses at mercy of miscreants thanks to unpatched Ray AI flaw

In their analysis, Notselwyn details the steps needed to drop a universal root shell on nearly all affected Linux kernels using CVE-2024-1086. This includes a particularly interesting method that builds on an earlier Linux kernel universal exploit technique, dubbed Dirty Pagetable, that involves abusing heap-based bugs to manipulate page tables to gain unauthorized control over a system’s memory and thus operation.

The latest method has been called Dirty Pagedirectory, and Notselwyn says it allows unlimited, stable read/write access to all memory pages in a Linux system, which would give an attacker full control over the box: 

Notselwyn has also shared the source code to an exploit PoC, which is “trivial” to run.

Exploiting the bug requires that the unprivileged-user namespaces option be set to access nf_tables, which is enabled by default on Debian, Ubuntu, and other major distributions. An attacker would then need to trigger a double-free, scan the physical memory for the kernel base address, bypassing KASLR, and then access the modprobe_path kernel variable with read/write privileges.

After overwriting the modprobe_path, the exploit starts a root shell, and then it’s game over. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/03/29/linux_kernel_flaw/

Tags: Easy-to-usemake-me-roottechnology
Previous Post

IPL 2024: Why Nicholas Pooran Replaced KL Rahul At Toss For LSG vs PBKS Clash?

Next Post

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

August 26, 2025
Bishop Kearney girls’ hockey team partners with UR Medicine for science-based training – 13wham.com

Bishop Kearney Girls’ Hockey Team Teams Up with UR Medicine for Cutting-Edge Science-Based Training

August 26, 2025
STEM camps offered at National Museum of Nuclear Science and History – KRQE

Discover Thrilling STEM Camps Now Open at the National Museum of Nuclear Science and History!

August 26, 2025
7 things people do when they care too much about what others think – VegOut

7 Signs You’re Caring Too Much About What Others Think

August 26, 2025
The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

How AI and Technology Are Transforming the Future of Interactive Entertainment

August 26, 2025
First look: ‘Whistle Blowers’ doc focuses on the crisis facing youth sports officials – NBC 5 Dallas-Fort Worth

Inside the Crisis Facing Youth Sports Officials: An Eye-Opening Look at ‘Whistle Blowers

August 26, 2025
South Carolina city selected to host 2027 Diamond Youth Baseball World Series – WRDW

South Carolina City Selected to Host the Exciting 2027 Diamond Youth Baseball World Series

August 25, 2025

Brazil’s low-voltage consumers could save 16% on power bills – Valor International

August 25, 2025
‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

August 25, 2025
Georgia lawmakers plan for federal cuts to already ‘underfunded’ public health services – Grice Connect

Georgia Lawmakers Prepare to Fight Federal Cuts Threatening Public Health Services

August 25, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (790)
  • Economy (809)
  • Entertainment (21,689)
  • General (16,673)
  • Health (9,850)
  • Lifestyle (823)
  • News (22,149)
  • People (811)
  • Politics (818)
  • Science (16,020)
  • Sports (21,309)
  • Technology (15,791)
  • World (791)

Recent News

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

August 26, 2025
Bishop Kearney girls’ hockey team partners with UR Medicine for science-based training – 13wham.com

Bishop Kearney Girls’ Hockey Team Teams Up with UR Medicine for Cutting-Edge Science-Based Training

August 26, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version