SNeela
PhD student working on system security, side-channel security, and CPU security at @isec_tugraz@infosec.exchange, TU Graz, Austria.
Hardware equivalent of a Sticky Note ![]()
Something I did got a big corpo nominated for the Lamest Vendor Response pwnie award once
Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon
Opinions posted here are my own.
Davide Ornaghi and Giuseppe Caruso found a very interesting bug in #Linux's in-kernel Samba3 server from 6.12 to 6.19.x. Essentially, from the commit message and #CVE description:
> Currently, ksmbd does not verify if the user attempting to reconnect to a durable handle is the same user who originally opened the file. This allows any authenticated user to hijack an orphaned durable handle by predicting or brute-forcing the persistent ID.
Very interesting stuff! The kernel let's users resume their connection to an open file even after WiFi drops (durable handle), and a bug in this code let another authenticated user become this WiFi-dropped user, letting the hijacker access all files.
https://github.com/TurtleARM/CVE-2026-31717-KSMBD-Exploit
CVE-2026-31717

