* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, December 19, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    Walk on White features Conchettes and Santa – keysnews.com

    Uncover the Enchantment of Conchettes and Santa in Walk on White

    Blizzard Entertainment President on BlizzCon 2026, 35th Anniversary Plans – Variety

    Blizzard Entertainment President Reveals Thrilling BlizzCon 2026 and 35th Anniversary Celebrations

    SM Entertainment accelerates US push with early debut plans for rookie acts – The Korea Herald

    SM Entertainment Sets the Stage for a US Takeover with Exciting Early Debuts of New Rookie Acts

    Star Entertainment CEO Steve McCann to exit after bruising turnaround stint – Reuters

    Star Entertainment CEO Steve McCann to Step Down Following Tough Turnaround Battle

    Australia’s Star Entertainment CEO Steve McCann steps down By Reuters – Investing.com

    Australia’s Star Entertainment CEO Steve McCann steps down By Reuters – Investing.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    China exploits US-funded research on nuclear technology, a congressional report says – ABC News

    Congressional Report Uncovers China’s Exploitation of US-Funded Nuclear Technology Research

    Netcracker Dominates International Business and Technology Excellence Awards – Business Wire

    Netcracker Shines Bright at International Business and Technology Excellence Awards

    Can OpenAI Respond After Google Closes the A.I. Technology Gap? – The New York Times

    Can OpenAI Stay Ahead as Google Narrows the A.I. Technology Race?

    Abstract Technology Group moves location to Elmwood – Star City TV

    Abstract Technology Group Moves to the Vibrant Elmwood Neighborhood, Sparking Excitement

    AI coding is now everywhere. But not everyone is convinced. – MIT Technology Review

    AI coding is now everywhere. But not everyone is convinced. – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    Walk on White features Conchettes and Santa – keysnews.com

    Uncover the Enchantment of Conchettes and Santa in Walk on White

    Blizzard Entertainment President on BlizzCon 2026, 35th Anniversary Plans – Variety

    Blizzard Entertainment President Reveals Thrilling BlizzCon 2026 and 35th Anniversary Celebrations

    SM Entertainment accelerates US push with early debut plans for rookie acts – The Korea Herald

    SM Entertainment Sets the Stage for a US Takeover with Exciting Early Debuts of New Rookie Acts

    Star Entertainment CEO Steve McCann to exit after bruising turnaround stint – Reuters

    Star Entertainment CEO Steve McCann to Step Down Following Tough Turnaround Battle

    Australia’s Star Entertainment CEO Steve McCann steps down By Reuters – Investing.com

    Australia’s Star Entertainment CEO Steve McCann steps down By Reuters – Investing.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    China exploits US-funded research on nuclear technology, a congressional report says – ABC News

    Congressional Report Uncovers China’s Exploitation of US-Funded Nuclear Technology Research

    Netcracker Dominates International Business and Technology Excellence Awards – Business Wire

    Netcracker Shines Bright at International Business and Technology Excellence Awards

    Can OpenAI Respond After Google Closes the A.I. Technology Gap? – The New York Times

    Can OpenAI Stay Ahead as Google Narrows the A.I. Technology Race?

    Abstract Technology Group moves location to Elmwood – Star City TV

    Abstract Technology Group Moves to the Vibrant Elmwood Neighborhood, Sparking Excitement

    AI coding is now everywhere. But not everyone is convinced. – MIT Technology Review

    AI coding is now everywhere. But not everyone is convinced. – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

March 30, 2024
in Technology
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
Share on FacebookShare on Twitter

A Linux privilege-escalation proof-of-concept exploit has been published that, according to the bug hunter who developed it, typically works effortlessly on kernel versions between at least 5.14 and 6.6.14. 

Running the exploit as a normal user on a vulnerable machine will grant you root access to the box, allowing you to do whatever you want on it. This can be used by rogue insiders or malware already on a computer to cause further damage and problems.

This affects Debian, Ubuntu, Red Hat, Fedora, and no doubt other Linux distributions. The flaw finder, known by the handle Notselwyn, issued a highly detailed technical report of the bug this week, and said their exploit had a success rate of 99.4 percent on kernel 6.4.16, for instance.

The vulnerability is tracked as CVE-2024-1086. It is rated 7.8 out of 10 in terms of CVSS severity. It was patched at the end of January, updates have been rolling out since then, and if you haven’t yet upgraded your vulnerable kernel and local privilege escalation (LPE) is a concern, take a closer look at this thing.

“Never had I ever gotten so much joy developing a project, specifically when dropping the first root shell with the bug,” Notselwyn enthused.

The flaw is a double-free bug in the Linux kernel’s netfilter component involving nf_tables. As the US National Vulnerability Database explained:

All of that can lead to a crash or arbitrary code execution in the kernel upon exploitation. Before heading out for the Easter weekend we’d suggest patching first, again if LPE is a critical issue for you, so the only headache that greets you on Monday morning is pain from too much chocolate.

JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat

Nvidia’s newborn ChatRTX bot patched for security bugs

These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb

‘Thousands’ of businesses at mercy of miscreants thanks to unpatched Ray AI flaw

In their analysis, Notselwyn details the steps needed to drop a universal root shell on nearly all affected Linux kernels using CVE-2024-1086. This includes a particularly interesting method that builds on an earlier Linux kernel universal exploit technique, dubbed Dirty Pagetable, that involves abusing heap-based bugs to manipulate page tables to gain unauthorized control over a system’s memory and thus operation.

The latest method has been called Dirty Pagedirectory, and Notselwyn says it allows unlimited, stable read/write access to all memory pages in a Linux system, which would give an attacker full control over the box: 

Notselwyn has also shared the source code to an exploit PoC, which is “trivial” to run.

Exploiting the bug requires that the unprivileged-user namespaces option be set to access nf_tables, which is enabled by default on Debian, Ubuntu, and other major distributions. An attacker would then need to trigger a double-free, scan the physical memory for the kernel base address, bypassing KASLR, and then access the modprobe_path kernel variable with read/write privileges.

After overwriting the modprobe_path, the exploit starts a root shell, and then it’s game over. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/03/29/linux_kernel_flaw/

Tags: Easy-to-usemake-me-roottechnology
Previous Post

IPL 2024: Why Nicholas Pooran Replaced KL Rahul At Toss For LSG vs PBKS Clash?

Next Post

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library

Saudi Arabia’s 2034 World Cup stadium plans face delays and cost-cutting – The Guardian

Saudi Arabia’s Ambitious 2034 World Cup Stadium Plans Hit Delays and Budget Cuts

December 19, 2025
Engaging Diversity: An Inclusive Approach to Undergraduate Mentorship in Mobilization and Political Economy – Political Science Now

Engaging Diversity: An Inclusive Approach to Undergraduate Mentorship in Mobilization and Political Economy – Political Science Now

December 19, 2025
State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

December 19, 2025
Mpox transmission, US flu surveillance highlighted in first Public Health Alerts reports – CIDRAP

Breaking New Ground: Essential Insights into Mpox Transmission and US Flu Surveillance Unveiled

December 19, 2025
The hard politics of climate overshoot – Financial Times

The High-Stakes Battle Over Climate Overshoot

December 19, 2025
How can we protect cool water in Western Washington’s forest streams? – Department of Ecology – State of Washington (.gov)

Safeguarding Western Washington’s Forest Streams: Strategies to Preserve Cool, Healthy Waters

December 19, 2025
Swearing Actually Seems to Make Humans Physically Stronger – ScienceAlert

Swearing Actually Boosts Human Physical Strength

December 19, 2025
2025 Science Activation Opportunity – NASA Science (.gov)

2025 Science Activation Opportunity – NASA Science (.gov)

December 19, 2025
7 holiday hosting rules Boomers stress over that younger hosts ignore completely – VegOut

7 Holiday Hosting Rules Boomers Swear By That Younger Hosts Totally Overlook

December 19, 2025
Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

December 19, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (976)
  • Economy (995)
  • Entertainment (21,872)
  • General (18,826)
  • Health (10,035)
  • Lifestyle (1,007)
  • News (22,149)
  • People (1,001)
  • Politics (1,009)
  • Science (16,210)
  • Sports (21,495)
  • Technology (15,977)
  • World (984)

Recent News

Saudi Arabia’s 2034 World Cup stadium plans face delays and cost-cutting – The Guardian

Saudi Arabia’s Ambitious 2034 World Cup Stadium Plans Hit Delays and Budget Cuts

December 19, 2025
Engaging Diversity: An Inclusive Approach to Undergraduate Mentorship in Mobilization and Political Economy – Political Science Now

Engaging Diversity: An Inclusive Approach to Undergraduate Mentorship in Mobilization and Political Economy – Political Science Now

December 19, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version