Post #3581123
2026-07-04 13:59 UTC
PinTheft: CVE-2026-43494, a local root exploit chaining two Linux kernel subsystems. A local unprivileged code execution, needs the RDS/RDS_TCP kernel modules to be loadable, io_uring enabled, a readable SUID-root binary, and just x86_64. Not remotely exploitable, it's a local-root escalation, same class as the DirtyClone family.
I previously talked about kernel modules, but assume that an exploit WILL LOAD the modules even if they are not already loaded into the kernel.
That being said, this is still just another local priv escalation.
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
Replies (0)
No replies.