• AlmaLinux OS - CVE-2024-1086 and XZ (AlmaLinux blog)

    From LWN.net@1337:1/100 to All on Wed Apr 3 19:45:05 2024
    AlmaLinux OS - CVE-2024-1086 and XZ (AlmaLinux blog)

    Date:
    Wed, 03 Apr 2024 18:39:45 +0000

    Description:
    AlmaLinux has announced updated kernels for AlmaLinux 8 and 9 to address CVE-2024-1086, a
    use-after-free vulnerability in the kernel that could be exploited to
    gain local privilege escalation. This is notable because the fix
    marks a divergence between AlmaLinux and Red Hat Enterprise Linux (RHEL): In January of this year, a kernel flaw was disclosed and named CVE-2024-1086 . This flaw is trivially exploitable on most RHEL-equivalent
    systems. There are many proof-of-concept posts available now,
    including one from our Infrastructure team lead, Jonathan Wright ( Dealing
    with CVE-2024-1086 ). In multi-user scenarios, this flaw is
    especially problematic. Though this was flagged as something to be fixed in Red Hat
    Enterprise Linux, Red Hat has only rated this as a moderate
    impact . The AlmaLinux project would also like to note that it is not
    impacted by the XZ backdoor. " Because enterprise Linux takes a bit
    longer to adopt those updates (sometimes to the chagrin of our users),
    the version of XZ that had the back door inserted hadn't made it
    further than Fedora in our ecosystem. "

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/968299/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)