@freddy@social.security.plumbing
Post #1784099
2026-04-29 17:58 UTC
Replies (13)
-
@dogriley@opensocial.media 2026-04-29 18:01
@freddy Oh Boy
-
@WPalant@infosec.exchange 2026-04-29 18:02
@freddy “The same primitive also crosses container boundaries because the page cache is shared across the host.” Shit…
-
@Viss@mastodon.social 2026-04-29 18:31
@freddy holyshit
-
@nazokiyoubinbou@urusai.social 2026-04-29 18:48
@freddy Do we know what kernel versions have the fix in place?
-
@capeta@ursal.zone 2026-04-29 19:04
@freddy brutal 🤘🤓
-
@can@haz.pink 2026-04-29 19:11
@freddy RHEL 14.3 🤔
-
@giggls@karlsruhe-social.de 2026-04-29 19:13
@freddy Also works on #Debian 13
-
@jackemled@furry.engineer 2026-04-29 19:48
@freddy This article immediately feels like an advertisement for an "AI" "vulnerability scanner". Is the problem real & has it been confirmed by another party with no connections to Xint?
-
@stiiin@infosec.space 2026-04-29 19:56
@freddy This is going to be in OSCP exams for years to come.
-
@giggls@karlsruhe-social.de 2026-04-29 19:56
@freddy If the vulnerable code is only in algif_aead.ko.xz this works as a quick-fix if the algorythm is not needed: mv /lib/modules/$(uname -r)/kernel/crypto/algif_aead.ko.xz /lib/modules/$(uname -r)/kernel/crypto/algif_aead.ko.xz.keep
-
@Thorium@social.linux.pizza 2026-04-29 20:37
@freddy I didn't see this module by default on Rocky9 or 10.
-
@IvanDSM@mastodon.social 2026-04-29 22:15
@freddy Have you been able to execute the exploit provided in the post? On a test rig it fails with "Address family not supported by protocol". Kernel version 6.19.11.
-
@SpaceLifeForm@infosec.exchange 2026-04-29 23:54
@freddy Unfortunately, I doubt it will let me root Android.