I'm too based for Shitter and most of the Fediverse, I guess? You may know me or not... Read pinned posts before copypasting someone elses opinion as your own! Follow Requests without prior interaction and/or public posts & profile description will be declined. Repeat offenders will be blocked for spamming follow requests. Pronouns: he/him
TelH90
@kkarhan@mastodon.social
mastodon.social
Replying to
@nixCraft@mastodon.social
@nixCraft@mastodon.social all I do is use a #minimalist #Desktop #Linux on a VAIO #P11Z & #EeePC701 because there's yet to be any decent device in that size category…
And if it comes down to it I'd rather #DIY @OS1337@infosec.space instead…
RefluXFS (CVE-2026-64600) is a race-condition in the Linux kernel's XFS copy-on-write path.
(Kernel updates are available.)
On an XFS filesystem with reflink enabled (Default on RHEL and similar, plus Amazon Linux), if you win a race during the copy-on-write remap lets the unprivileged local user overwrite the on-disk contents of any readable file on that volume including /etc/passwd or a SUID-root binary.
What makes this wild: the changes persist across reboots, produce no kernel logs, bypass SELinux and Kernel Address Space Randomization (KASLR).
PoCs reliably exploiting the vuln.
Check if you are in scope:
# xfs_info / | grep -i "reflink=1"
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
Two previously disclosed CVEs are actively-weaponized kernel root exploits. GhostLock CVE-2026-43499, and Bad Epoll CVE-2026-46242, are both public highly reliable exploits. Ghostlock also appears to enable a container escape and Bad Epoll is also working on Android.
Both are fixed in kernel 6.12.96-1.
If you have local user, upgrade the kernel & boot it.
BRB have to reboot :)
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
440 CVEs dropped to kernel cve-announce in the last 24 hrs?!?!?!?
Whoa, calm thy horses! It looks like a backlog dump of resolved issues all sequentially numbered. No RCEs and all resolved.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
okuto morikawa
@omorikawa@social.vivaldi.net
Theoretical Physicist, Non-perturbative aspects of quantum fields, Postdoc@RIKEN<-Osaka U.<-Kyushu U.
social.vivaldi.net
My #minimalist #backpacker setup:
Clothes - #uniqlo
Shoes - #clarks
Bag - #cabinzero
Wallet - #crazyhorsecraft
A couple things this morning. CVE-2026-46242 "Bad Epoll" Linux kernel, CVSS 7.8, local privilege escalation was already mentioned CVE published around May.
1: What's new today: it is now fully weaponized and publicly written up. It's a use-after-free race in the kernel's eventpoll subsystem (ep_remove()/ep_remove_file()). An unprivileged local user can win a race condition and get root.
2: Affected: kernel 5.10 through 6.11.
3: The Attack surface is broad because epoll underlies nginx, Node.js, Python asyncio, databases, Android's event loop.
So, basically anything async I/O.
An App can be the foot in the door, the race condition can lead to root.
I'm running Kernel 6.12.94+deb13-amd64. So driving on.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
Podman CVE-2026-44517: A breakout can happen during container build using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive. This is weird, essentially it is a path traversal, which has been fixed in 1.43.2.
Still pulling malicious code into a container, we can agree, is not ideal path traversal or not.
Have not explored the exploitation on this one.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
PinTheft: CVE-2026-43494, a local root exploit chaining two Linux kernel subsystems. A local unprivileged code execution, needs the RDS/RDS_TCP kernel modules to be loadable, io_uring enabled, a readable SUID-root binary, and just x86_64. Not remotely exploitable, it's a local-root escalation, same class as the DirtyClone family.
I previously talked about kernel modules, but assume that an exploit WILL LOAD the modules even if they are not already loaded into the kernel.
That being said, this is still just another local priv escalation.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
This one seems interesting.
Podman CVE-2026-57231
A malicious container image with a malformed Env entry (a key with no value) can trick podman run into leaking the host environment variables into the container. The wildcard glob makes it worse, it can return all host env vars from the launching session without knowing their names.
#minimalist
#Linux #Selfhosting #selfhosted #selfhost #InfoSec
#Exploit
The "weaponization watch" script pulled up two Debian-13 kernel root exploits with public PoCs that the KEV list doesn't include:
CVE-2026-46331 "pedit COW" weaponized sometime around 6/16, unprivileged user to root on Debian 13 trixie (the user namespaces is open by default).
RHEL 10 is also in scope (again, local priv escalation not remote.)
CVE-2026-46333: ptrace logic flaw, local root + credential disclosure, exploits circulating.
Then from yesterday:
DirtyClone (CVE-2026-43503) confirmed against Debian.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec
~meoralis~
@meoralis@pixelfed.social
Camera roll dumps of all the things that caught my attention. Loves to travel in Europe. Based in Germany. Random thoughts in German and English, terrible puns included :)
pixelfed.social
Supermacaw for #MinimalismMonday 🦸♀️
#MinimalistMonday #minimalist #minimalistic #minimalism #minimalistisch #Minimalismus #bird #Vogel #Papagei #Ara #Scharlachara #HellroterAra #Arakanga #macaw #scarletMacaw #redAndYellowMacaw #redAndBlueMacaw #redBreastedMacaw #birdsOfMastodon #birdPhotography #AraMacao #MacawMonday #VogelparkWalsrode #WeltvogelparkWalsrode
Replying to
@lproven@social.vivaldi.net
@theregister@geeknews.chat @lproven@social.vivaldi.net I think that is bad and @linuxfoundation@social.lfx.dev should not have caved in on said pressure but stricly banned #AIslop contributions and treated it like they treated malicious contributions the same way #Valve deals with #Cheaters!
Plus the removal of #i486 support is IMHO bad because it was fine and shpuld've been left in.And I'm not just complaining because I maintain a #minimalist distro (@OS1337@infosec.space) that targets i486 (SX), like #Vortex86…
Why is it so easy to be sad and so hard to be happy
#art #artwork #blackandwhite #depression #anxiety #doodle #drawing #handdrawn #illustration #melancholy #mentalhealth #mentalhealthawareness #minimalist #healing
You've seen all posts