Elektrine lite

← Feed

@Emily@infosec.exchange

Post #1823845

2026-04-29 20:31 UTC

RE: https://hachyderm.io/@petrillic/116489574280084326 I have had a confirmation that it can work on the Amazon Linux kernel, but also RHEL says "fix deferred" for all affected RHEL versions: https://access.redhat.com/security/cve/cve-2026-31431

Replies (4)

  • @chillybot@infosec.exchange 2026-04-29 20:40

    @Emily The post in @ifin discourse tracks the different distros responses which have been a lil slow https://discourse.ifin.network/t/copy-fail-732-bytes-to-root-on-every-major-linux-distributions/342

    Open ##2007663

  • @stonebear2@hachyderm.io 2026-04-29 20:42

    @Emily DUCKY. RHEL did that the *last* big sploit I remember (spectre/meltdown); Debian had a fix in a week, but it took MONTHS to get an EL fix... this is (one of many reasons) why I am selling the M1 Mac, as it won't run Deb and I'm not running Red Hat on it...

    Open ##2007664

  • @adamhotep@infosec.exchange 2026-04-29 22:20

    @Emily the directions at https://copy.fail/#mitigation can help. I don't know about what it is disabling, so I also put a note to self in there to delete the file after the kernel is patched. On my Ubuntu 24.04 systems, I already had 26.04's repos set up for cherrypicking, so I ran sudo apt install linux-image-{generic,headers}-hwe-26.04 and rebooted (I can't fully upgrade to 26.04 yet, but these packages don't depend on libc or other things that'll break the world)

    Open ##2007665

  • @Emily @catsalad That just means a gov customer is using this vuln.

    Open ##2007666