Tuesday, June 21, 2022
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Bug in Linux kernel allows privilege escalation

June 8, 2022
in World
0
0
SHARES
245
VIEWS
Share on FacebookShare on Twitter

Security researcher Aaron Adams found a use-after-free bug in the Linux kernel that could allow local users to become superusers. The bug affects the NFTables kernel component, which is active by default on most Linux systems and is a further development of Linux’s own iptables firewall.

For an attack to be successful, an attacker needs a local user on the target system who must also be able to create their own NFTables namespaces. However, this setting is enabled by default, at least on current Ubuntu systems. In his message on the OSS Security mailing list, Adams also provides a proof-of-concept exploit (PoC).

Exploit code for nftables bugs

With this code example, the vulnerability on a system with Ubuntu 22.04 can be successfully exploited for root access, explains the security researcher. However, we could not confirm this in our own tests.

Apparently due to a misunderstanding, the bug received two CVE IDs, namely CVE-2022-1966 and CVE-2022-32250. However, the ID CVE-1022-1966 originally assigned by Red Hat should prevail. The severity of the vulnerability in the form of a CVSS score has not yet been determined, but the maintainers of Ubuntu and Red Hat rate it as “high”.

The developers of the Linux kernel have already fixed the bug in the source code, but at the time of the report no update packages had been released by any distribution. However, administrators of multi-user systems should act now to prevent attacks from malicious users.

The Ubuntu IT specialists explain that two sysctl commands can help with their own distributions. This will cause users to lose the ability to create NFTables namespaces, which should prevent exploitation of the vulnerability. However, the authors of Ubuntu do not write anything about possible side effects in their security advisory:
$sudo sysctl -w kernel.unprivileged_user_clone=0
$ echo kernel.unprivileged_userns_clone=0 | sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

Since most systems have such configuration files, it should work there as well. If necessary, administrators should check whether the file /etc/sysctl.d/99-disable-unpriv-userns.conf is present and adjust the line if necessary.

(dmk)

To home page

#Bug #Linux #kernel #privilege #escalation

Source

Tags: BugescalationEscalation of RightskernelLinuxLinux and open sourcenftablesprivilegesecurity breach

Related Posts

World

Social Security gains 72,111 foreign affiliates in May and marks a historical maximum

by pmdii
June 21, 2022
World

Study: Western Europe is catching up with the fifth mobile generation 5G

by pmdii
June 21, 2022
World

How to write yegar or arrive

by pmdii
June 21, 2022
World

Google Colab: How to Customize Python Scripts with Input Fields

by pmdii
June 21, 2022
World

Leroy Merlin’s very low ceiling fan that will save you from the heat wave

by pmdii
June 21, 2022
Next Post

The best beaches to go with children in Spain

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Andalusia Andalusian Apple Apps check Data EU euros Gas Google government Home iOS iOS 16 iPad iPhone June life Linux and open source live macOS Madrid Microsoft million Moreno online people PSOE Russia security security breach series Spain Spanish summer Sánchez Test time today Ukraine Update Vox War world years

Recent Posts

  • Social Security gains 72,111 foreign affiliates in May and marks a historical maximum
  • GREECE 2022: 5 Month Sales and Top 20 Motorcycles – MotorBike.gr
  • Study: Western Europe is catching up with the fifth mobile generation 5G
  • About Us
  • DMCA
  • Disclaimer
  • Privacy Policy

© Kiratas 2022. All Rights Reserved.

No Result
View All Result
  • Home
  • World
  • Lifestyle
  • Business
  • Entertainment
  • Sports

© Kiratas 2022. All Rights Reserved.