Post #1787498
2026-04-29 19:26 UTC
Replies (7)
-
@thibaultmol@en.osm.town 2026-04-29 19:53
@darkrat@chaosfurs.social It's weird how the code they want you to curl and run is minified and has a binary section in it.... just weird.... edit: tbc, my friend said this, I hadn't checked it yet. He said that this is not normally how proof of concepts are written I really hope someone on fedi who knows this stuff can verify this cause I'm not boosting it without seeing that
-
@human_equivalent@rage.love 2026-04-29 21:46
@darkrat I wonder how much is trying to create a panic and how much is a serious issue right now (for those who patch regularly). My debian machines don't have the algif_aead module loaded (and it's CONFIG_CRYPT_AEAD=m in default debian kernel, i *guess* that's the right setting). That said debian lists it as vulnerable... https://security-tracker.debian.org/tracker/CVE-2026-31431
-
@flippac@types.pl 2026-04-29 23:21
@darkrat That'll be a good laugh once agentic AIs find their way to it!
-
@v_v@mastodon.catgirl.cloud 2026-04-30 01:19
@darkrat tried detonating it on my server, alpine's binary kernel dist seems to be unaffected same thing on my lappy with a slightly tweaked kernel, looks like building it from source finally paid off
-
@ShnoofleBear@curly.cat 2026-04-30 01:32
@darkrat That POC exploit script is suspicious as fuck.
-
@AVincentInSpace@furry.engineer 2026-04-30 05:34
@darkrat PoC doesn't seem to be working on my machine. I don't think my kernel is new enough to be patched... does it just not work on NixOS?
-
@char@ioc.exchange 2026-05-01 08:42
@darkrat It worked on: Ubuntu 24.04 noble x86_64 Linux 6.8.0-106-generic It not worked on: Arch x86_64 Linux 6.19.14-arch1-1