Post #1843040
2026-04-29 22:16 UTC
wtf
An unprivileged local user can write 4 controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root.
If your kernel was built between 2017 and the patch — which covers essentially every mainstream Linux distribution — you’re in scope.
how does that only get a CVE score of 7.8, the impact of this is huge
Replies (2)
-
@Bitflip@lemmy.ml 2026-04-29 22:42
Probably because the attack vector is having a user account on the target
-
@KairuByte@lemmy.dbzer0.com 2026-04-30 02:47
It’s not an interaction-less RCE, for one.