QUICK NEWS

{NEW} - More to come for this tab...

{OLD} - A new css video is up.


Video of the moment:


Internal Links

SMF Sites

Quick Info

CVE Messages

Started by Neša, Jul 04, 2024, 06:36 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Skhilled

Copied and posted to my sites and friends sites. :rgton

Neša

Not sure why I can't edit the other posts.

CVE-2026-31431
has been found, if you haven't already update your kernel Alma Linux has a new patched kernel to stop this exploit.

This lets any user to grant themselves root privileges using this exploit they only need access to be able to run code on your machine.
https://xint.io/blog/copy-fail-linux-distributions


Skhilled

#17
Thank you!  :rgton

EDIT: And, cPanel has a new upgrade as well.

Skhilled

Dirty Frag [CVE Pending]: Mitigation and Kernel Update on CloudLinux

Dirty Frag [CVE Pending] is a Linux kernel local privilege escalation in the xfrm subsystem. The flaw lives in the ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path and is reachable via the XFRM user netlink interface, which auto-loads the relevant modules. A working public proof-of-concept exists; any unprivileged local user can use it to gain root in a single command.
The vulnerability is in the same class as Copy Fail (CVE-2026-31431) but lives in a different subsystem.

Neša

#19
Thanks, I've checked the modules that are used in the exploit are not loaded on this server so we are safe until the new AlmaLinux kernel patch.

Edit:
New patched kernels are out.