Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. Federal agency warns critical Linux vulnerability being actively exploited

Federal agency warns critical Linux vulnerability being actively exploited

Scheduled Pinned Locked Moved The Insider News
comsysadminlinuxsecurityannouncement
3 Posts 3 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kent Sharkey
    wrote on last edited by
    #1

    Ars Technica[^]:

    Cybersecurity and Infrastructure Security Agency urges affected users to update ASAP.

    More eyes fixing the bugs, even more eyes finding the bugs

    D P 2 Replies Last reply
    0
    • K Kent Sharkey

      Ars Technica[^]:

      Cybersecurity and Infrastructure Security Agency urges affected users to update ASAP.

      More eyes fixing the bugs, even more eyes finding the bugs

      D Offline
      D Offline
      David ONeil
      wrote on last edited by
      #2

      Quote:

      A deep-dive write-up of the vulnerability reveals that these exploits provide “a very powerful double-free primitive when the correct code paths are hit.”

      Double-plus ungood!

      Our Forgotten Astronomy | Object Oriented Programming with C++ | Wordle solver

      1 Reply Last reply
      0
      • K Kent Sharkey

        Ars Technica[^]:

        Cybersecurity and Infrastructure Security Agency urges affected users to update ASAP.

        More eyes fixing the bugs, even more eyes finding the bugs

        P Offline
        P Offline
        Peter_in_2780
        wrote on last edited by
        #3

        Slow news day?

        Quote:

        The vulnerability, tracked as CVE-2024-1086 and carrying a severity rating of 7.8 out of a possible 10, allows people who have already gained a foothold inside an affected system to escalate their system privileges.

        Quote:

        It was patched in January, but as the CISA advisory indicates, some production systems have yet to install it.

        My emphasis.

        Software rusts. Simon Stephenson, ca 1994. So does this signature. me, 2012

        1 Reply Last reply
        0
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups