Post #2773594
2026-05-07 20:40 UTC
@phnt@fluffytail.org @mia@shrimptest.0x0.st
>XFRM SA registration requires CAP_NET_ADMIN
first one looks like a nothingburger
>The target of this variant is line 1 (the root entry) of /etc/passwd. The normal line starts with "root:x:0:0:root:/root:/bin/bash", and the exploit replaces chars 4..15 with last-write-wins into the shape "::0:0:GGGGGG:", making the final line 1 "root::0:0:GGGGGG:/root:/bin/bash". That is, the passwd field becomes an empty string
second one is the most interesting, I wonder if you can root andr*id with a variant of it
Replies (1)
-
@mia@shrimptest.0x0.st 2026-05-07 21:16
@romin@shitposter.world @phnt@fluffytail.org it’s also kind of a nothingburger because RxRPC has very few users and the kernel module should not be loaded on most systems