#minimalist

15 posts · Last used 15d

Replying to
@nixCraft@mastodon.social all I do is use a #minimalist #Desktop #Linux on a VAIO #P11Z & #EeePC701 because there's yet to be any decent device in that size category… And if it comes down to it I'd rather #DIY @OS1337@infosec.space instead…
0
0
0
0
RefluXFS (CVE-2026-64600) is a race-condition in the Linux kernel's XFS copy-on-write path. (Kernel updates are available.) On an XFS filesystem with reflink enabled (Default on RHEL and similar, plus Amazon Linux), if you win a race during the copy-on-write remap lets the unprivileged local user overwrite the on-disk contents of any readable file on that volume including /etc/passwd or a SUID-root binary. What makes this wild: the changes persist across reboots, produce no kernel logs, bypass SELinux and Kernel Address Space Randomization (KASLR). PoCs reliably exploiting the vuln. Check if you are in scope: # xfs_info / | grep -i "reflink=1" #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
0
0
0
0
Two previously disclosed CVEs are actively-weaponized kernel root exploits. GhostLock CVE-2026-43499, and Bad Epoll CVE-2026-46242, are both public highly reliable exploits. Ghostlock also appears to enable a container escape and Bad Epoll is also working on Android. Both are fixed in kernel 6.12.96-1. If you have local user, upgrade the kernel & boot it. BRB have to reboot :) #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
2
0
6
0
A couple things this morning. CVE-2026-46242 "Bad Epoll" Linux kernel, CVSS 7.8, local privilege escalation was already mentioned CVE published around May. 1: What's new today: it is now fully weaponized and publicly written up. It's a use-after-free race in the kernel's eventpoll subsystem (ep_remove()/ep_remove_file()). An unprivileged local user can win a race condition and get root. 2: Affected: kernel 5.10 through 6.11. 3: The Attack surface is broad because epoll underlies nginx, Node.js, Python asyncio, databases, Android's event loop. So, basically anything async I/O. An App can be the foot in the door, the race condition can lead to root. I'm running Kernel 6.12.94+deb13-amd64. So driving on. #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
1
0
1
0
Podman CVE-2026-44517: A breakout can happen during container build using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive. This is weird, essentially it is a path traversal, which has been fixed in 1.43.2. Still pulling malicious code into a container, we can agree, is not ideal path traversal or not. Have not explored the exploitation on this one. #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
1
0
1
0
PinTheft: CVE-2026-43494, a local root exploit chaining two Linux kernel subsystems. A local unprivileged code execution, needs the RDS/RDS_TCP kernel modules to be loadable, io_uring enabled, a readable SUID-root binary, and just x86_64. Not remotely exploitable, it's a local-root escalation, same class as the DirtyClone family. I previously talked about kernel modules, but assume that an exploit WILL LOAD the modules even if they are not already loaded into the kernel. That being said, this is still just another local priv escalation. #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
0
0
2
0
The "weaponization watch" script pulled up two Debian-13 kernel root exploits with public PoCs that the KEV list doesn't include: CVE-2026-46331 "pedit COW" weaponized sometime around 6/16, unprivileged user to root on Debian 13 trixie (the user namespaces is open by default). RHEL 10 is also in scope (again, local priv escalation not remote.) CVE-2026-46333: ptrace logic flaw, local root + credential disclosure, exploits circulating. Then from yesterday: DirtyClone (CVE-2026-43503) confirmed against Debian. #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec
0
0
0
0
Replying to
@theregister@geeknews.chat @lproven@social.vivaldi.net I think that is bad and @linuxfoundation@social.lfx.dev should not have caved in on said pressure but stricly banned #AIslop contributions and treated it like they treated malicious contributions the same way #Valve deals with #Cheaters! Plus the removal of #i486 support is IMHO bad because it was fine and shpuld've been left in.And I'm not just complaining because I maintain a #minimalist distro (@OS1337@infosec.space) that targets i486 (SX), like #Vortex86…
0
0
0
0
You've seen all posts