Post #2533287
2026-05-03 21:33 UTC
@Hex@kolektiva.social
"6 years and 2 api changes"
Do you have an estimate of when the copy-fail vulnerability could have earliest been used to root a machine? It's possible others found this before, but chose not to disclose it to the public.
@octonion@tech.lgbt
Replies (1)
-
@Hex@kolektiva.social 2026-05-04 08:21
@Earl@mast.john1126.com @octonion@tech.lgbt the change was introduced in 2011, it became vulnerable in 2017. I would be extremely surprised if it hadn't been found and exploited by state actors, but there would be much faster and easier ways to introduce a vulnerability if that was the objective.