Open post Marcin Szewczyk @wodny@mastodon.social · 5mo ago Replying to @wdormann@infosec.exchange <p>The 3 recent Linux LPEs are sort of interesting in that each one took a different path from discovery to disclosure.</p><ol><li><strong><a href="https://infosec.exchange/@wdormann/116489443704631952" target="_blank">Copy Fail</a></strong>: Publicity stunt where they claim to have done the right thing, yet didn't bother to tell a single distro vendor, and lied about updates being available.</li><li><strong><a href="https://infosec.exchange/@wdormann/116535129483797487" target="_blank">Dirty Frag</a></strong>: Attempted to do proper coordination, including notifying the <code>linux-distros</code> mailing list. But the <a href="https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline" target="_blank" rel="nofollow noopener">embargo was broken</a>, so it was disclosed unexpectedly ahead of time.</li><li><strong><a href="https://infosec.exchange/@wdormann/116536031268240371" target="_blank">Copy Fail 2</a></strong>: <a href="https://www.openwall.com/lists/oss-security/2026/05/07/12" target="_blank" rel="nofollow noopener">Discovered as an n-day by looking at kernel commit logs and Spender noticing that it was copyfail-class</a></li></ol><p>Each path had basically exactly the same outcome (No fixes at publication time). 😂</p> @wdormann@infosec.exchange Dirty Frag and Copy Fail 2 target the same bug, correct?