Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Another Logic Bug Found in Linux Kernel

Дата публикации: 01-06-2026 14:27:35

Qualys has discovered a vulnerability in the Linux kernel that can be used to elevate standard user privileges.

Основное содержимое страницы с новостью.

Qualys has discovered a vulnerability in the Linux kernel that can be used to elevate standard user privileges.

The kernel function __ptrace_may_access() has been found to contain a vulnerability that is exploitable via a race condition. The function determines if one process is permitted to inspect another process and uses credential verification, process ancestry, and the "dumpable" flag to make the determination.

Qualys released an advisory that includes four proofs-of-concept (PoCs) that include exploits against chage, ssh-keysign, pkexec, and accounts-daemon that illustrate how the PoCs can be used by unprivileged attackers to read password hashes, steal SSH keys, and run random commands with root privileges. Qualys has also confirmed these PoCs work on Debian 13, Fedora 43 and 44, and Ubuntu 24.04 and 26.04.

It is important to note that Qualys stated in the advisory, "Please note that we have not exhaustively searched for exploitable userland programs (set-uid, set-gid, set-capabilities binaries, and root daemons); we simply remembered the four that we found from past research projects, and other, possibly better, exploitable programs may exist."

The report also points out how even SELinux can be skirted: "On Fedora, SELinux prevents accounts-daemon from starting a transient systemd unit, but we can send a request to another dbus-daemon instead; for example, we can send a request to accounts-daemon itself, to set an administrator's password (SetPassword) of our choice, and then su to this administrator, and then sudo to root."

The good news is that a patch has been issued by the Linux kernel developer team.
 
 

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Yet Another Linux Kernel Vulnerability Discovered08.3427-07-2026
2New Vulnerability Discovered in Linux Kernel017.1717-07-2026
3New Linux Flaw Lets Attackers Escape VMs08.5713-07-2026
4How Linux Security Teams Spot Vulnerabilities Before CVEs Are Published0714-07-2026
5432 отчёта об уязвимостях в ядре Linux. Локальная root-уязвимость Frag Gap013.8422-07-2026
6В древней Linux-утилите найдена критическая «дыра», которую не замечали 11 лет. Она открывает всем желающим root-доступ. Эксплойт умещается в одну строку-2823-01-2026
7KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"-2702-07-2026
8Linux Kernel Fragnesia Critical Privilege Escalation CVE-2026-46300-1714-05-2026
9Hardening Linux KVM Against VM Escape Attacks0707-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 7.74. Источник: www.linux-magazine.com.