Elektrine lite

← Feed

@rene_mobile@infosec.exchange

Post #2604728

2026-05-10 22:15 UTC

@rayk@techhub.social Leaking the bug (potentially to some limited list) is still not the same as leaking the full exploit and making a lot of noise about it. Even it the exploit can be recreated, why make it so easy for everybody to exploit it immediately? Sure, there's always lots of gray in the spectrum of coordinated disclosure. But from what I can see, they didn't seem to try very hard to help people get their systems into a safer state. The bug release page first and foremost points out how easy the exploit it and on how many distributions it works. This is showing off, and not making systems more secure. Yeah, I am not amused.

Replies (1)

  • @rayk@techhub.social 2026-05-11 18:20

    @rene_mobile@infosec.exchange > After discovering Dirty Frag, Hyunwoo Kim was reportedly working with Linux developers to fix the issue before publicly disclosing it. However, an unnamed third party published a working proof of concept earlier than anticipated, forcing the researcher to disclose the vulnerability more than a month ahead of schedule. https://www.techspot.com/news/112365-newly-disclosed-dirty-frag-vulnerability-left-linux-exposed.html

    Open ##2604729