* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, November 19, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Bartlett Police investigating shooting at kids entertainment center, officials say – FOX13 Memphis

    Shooting at Kids Entertainment Center Under Investigation by Bartlett Police

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

    Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

    CFCC to host career discovery nights on K-12 Teacher Preparation and Chemical Technology programs – WECT

    Unlock Your Potential: Career Discovery Nights for K-12 Teacher Preparation and Chemical Technology Programs at CFCC

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Apply Now: $50,000 for AI-Powered Financial Technology Solutions – ICTworks

    Secure $50,000 to Fuel Your Groundbreaking AI-Powered FinTech Innovation – Apply Now!

    Award-Winning Pet Brand Enters Self-Cleaning Litter Box Market With Latest Innovation – ParadePets

    Revolutionary Innovation Transforms Self-Cleaning Litter Boxes by Award-Winning Pet Brand

    Girls Exploring Tomorrow’s Technology marks 25th anniversary – pottsmerc.com

    Celebrating 25 Years of Inspiring Girls to Explore Tomorrow’s Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    Claire Danes Gets Honest About Her Surprise Pregnancy at Age 44 – Yahoo

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The next Met Gala exhibit will spotlight fashion across art history – San Francisco Chronicle

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    The Running Man to David Hockney: your complete entertainment guide to the week ahead | Culture – The Guardian

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Kelly Brook opens up on ‘horrific’ miscarriage that left her never wanting to try for a baby again – Woman & Home

    Bartlett Police investigating shooting at kids entertainment center, officials say – FOX13 Memphis

    Shooting at Kids Entertainment Center Under Investigation by Bartlett Police

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

    Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

    CFCC to host career discovery nights on K-12 Teacher Preparation and Chemical Technology programs – WECT

    Unlock Your Potential: Career Discovery Nights for K-12 Teacher Preparation and Chemical Technology Programs at CFCC

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Continental Uses Vacuum Technology to Study Tire Wear Particles – Continental AG

    Apply Now: $50,000 for AI-Powered Financial Technology Solutions – ICTworks

    Secure $50,000 to Fuel Your Groundbreaking AI-Powered FinTech Innovation – Apply Now!

    Award-Winning Pet Brand Enters Self-Cleaning Litter Box Market With Latest Innovation – ParadePets

    Revolutionary Innovation Transforms Self-Cleaning Litter Boxes by Award-Winning Pet Brand

    Girls Exploring Tomorrow’s Technology marks 25th anniversary – pottsmerc.com

    Celebrating 25 Years of Inspiring Girls to Explore Tomorrow’s Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

March 30, 2024
in Technology
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
Share on FacebookShare on Twitter

A Linux privilege-escalation proof-of-concept exploit has been published that, according to the bug hunter who developed it, typically works effortlessly on kernel versions between at least 5.14 and 6.6.14. 

Running the exploit as a normal user on a vulnerable machine will grant you root access to the box, allowing you to do whatever you want on it. This can be used by rogue insiders or malware already on a computer to cause further damage and problems.

This affects Debian, Ubuntu, Red Hat, Fedora, and no doubt other Linux distributions. The flaw finder, known by the handle Notselwyn, issued a highly detailed technical report of the bug this week, and said their exploit had a success rate of 99.4 percent on kernel 6.4.16, for instance.

The vulnerability is tracked as CVE-2024-1086. It is rated 7.8 out of 10 in terms of CVSS severity. It was patched at the end of January, updates have been rolling out since then, and if you haven’t yet upgraded your vulnerable kernel and local privilege escalation (LPE) is a concern, take a closer look at this thing.

“Never had I ever gotten so much joy developing a project, specifically when dropping the first root shell with the bug,” Notselwyn enthused.

The flaw is a double-free bug in the Linux kernel’s netfilter component involving nf_tables. As the US National Vulnerability Database explained:

All of that can lead to a crash or arbitrary code execution in the kernel upon exploitation. Before heading out for the Easter weekend we’d suggest patching first, again if LPE is a critical issue for you, so the only headache that greets you on Monday morning is pain from too much chocolate.

JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat

Nvidia’s newborn ChatRTX bot patched for security bugs

These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb

‘Thousands’ of businesses at mercy of miscreants thanks to unpatched Ray AI flaw

In their analysis, Notselwyn details the steps needed to drop a universal root shell on nearly all affected Linux kernels using CVE-2024-1086. This includes a particularly interesting method that builds on an earlier Linux kernel universal exploit technique, dubbed Dirty Pagetable, that involves abusing heap-based bugs to manipulate page tables to gain unauthorized control over a system’s memory and thus operation.

The latest method has been called Dirty Pagedirectory, and Notselwyn says it allows unlimited, stable read/write access to all memory pages in a Linux system, which would give an attacker full control over the box: 

Notselwyn has also shared the source code to an exploit PoC, which is “trivial” to run.

Exploiting the bug requires that the unprivileged-user namespaces option be set to access nf_tables, which is enabled by default on Debian, Ubuntu, and other major distributions. An attacker would then need to trigger a double-free, scan the physical memory for the kernel base address, bypassing KASLR, and then access the modprobe_path kernel variable with read/write privileges.

After overwriting the modprobe_path, the exploit starts a root shell, and then it’s game over. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/03/29/linux_kernel_flaw/

Tags: Easy-to-usemake-me-roottechnology
Previous Post

IPL 2024: Why Nicholas Pooran Replaced KL Rahul At Toss For LSG vs PBKS Clash?

Next Post

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library

Putative ‘Dispersal Adaptations’ Do Not Explain the Colonisation of a Volcanic Island by Vascular Plants, but Birds Can – Wiley Online Library

Why Birds, Not Dispersal Adaptations, Drive Vascular Plant Colonization on Volcanic Islands

November 19, 2025
NVIDIA Accelerates AI for Over 80 New Science Systems Worldwide – NVIDIA Blog

NVIDIA Drives AI Innovation with Over 80 Cutting-Edge Scientific Systems Worldwide

November 19, 2025
Neanderthals and early humans ‘likely to have kissed’, say scientists – The Guardian

Did Neanderthals and Early Humans Share a Kiss? Scientists Say It’s Likely Could Neanderthals and Early Humans Have Shared a Kiss? New Research Suggests They Probably Did

November 19, 2025
People who stay genuinely happy after 50 usually practice these 7 daily rituals – VegOut

7 Daily Habits That Unlock Lasting Happiness After 50

November 19, 2025
Mid-Atlantic Technology Summit 2025 showcases next-gen tools for first responders – FireRescue1

Mid-Atlantic Technology Summit 2025 Reveals Game-Changing Tools Empowering First Responders

November 19, 2025
NFL Injury Report: Tracking latest news, updates on Josh Jacobs, Drake London and more for fantasy football in Week 12 – Yahoo Sports

Week 12 Fantasy Football Injury Update: Crucial News on Josh Jacobs, Drake London, and More

November 19, 2025
Scotland vs. Denmark: Livestream World Cup 2026 Qualifier Soccer From Anywhere – CNET

Scotland vs. Denmark: Livestream World Cup 2026 Qualifier Soccer From Anywhere – CNET

November 19, 2025
Tomorrow.Blue Economy explored the potential of the blue economy for ports, cities and corporations – Yahoo Finance

Unlocking the Future: How the Blue Economy Will Revolutionize Ports, Cities, and Corporations

November 19, 2025
Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

Liev Schreiber ‘cleared to return to work’ after weekend hospitalization, rep confirms – Los Angeles Times

November 19, 2025
Boat Electrification Is a Climate and Health Win. Making the Switch Isn’t Easy. – Inside Climate News

How Electrifying Boats Can Boost Climate and Health-And Why the Transition Is Challenging

November 19, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (926)
  • Economy (945)
  • Entertainment (21,820)
  • General (18,262)
  • Health (9,985)
  • Lifestyle (957)
  • News (22,149)
  • People (950)
  • Politics (958)
  • Science (16,159)
  • Sports (21,446)
  • Technology (15,926)
  • World (932)

Recent News

Putative ‘Dispersal Adaptations’ Do Not Explain the Colonisation of a Volcanic Island by Vascular Plants, but Birds Can – Wiley Online Library

Why Birds, Not Dispersal Adaptations, Drive Vascular Plant Colonization on Volcanic Islands

November 19, 2025
NVIDIA Accelerates AI for Over 80 New Science Systems Worldwide – NVIDIA Blog

NVIDIA Drives AI Innovation with Over 80 Cutting-Edge Scientific Systems Worldwide

November 19, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version