Dirty Frag Is a Zero-Day Disaster for Linux

https://hackster.imgix.net/uploads/attachments/1955200/_4RZZha9lv8.blob?auto=compress%2Cformat&w=600&h=450&fit=min

This past week has been a brutal time to be a Linux user. Under normal circumstances, we gloat at Windows users about how our daily drivers are virtually unhackable. We laugh about how they use malware scanners and antivirus software. "Maybe try a real operating system," we say. But the Copy Fail exploit revealed last week, and now the Dirty Frag exploit that was just announced, have us Linux users eating a big slice of humble pie.

Dirty Frag is the latest in a growing line of devastating Linux privilege-escalation vulnerabilities, and security researchers are already calling it one of the most dangerous kernel bugs in years. Like Dirty Pipe and Copy Fail before it, the exploit abuses Linux page cache behavior to overwrite protected memory in ways the kernel should never allow. The exploit allows any local user on an affected machine to gain full root access almost instantly.

...

Copyright of this story solely belongs to hackster.io. To see the full text click HERE