Hot on the Heels of Copy Fail, New Linux Bugs Grant Root Privileges
Multiple Linux exploits have been uncovered over the last few weeks, including Copy Fail, and the newest of which are dubbed "PinTheft" and "SSH-keysign-pwn." Both have been recently patched, but relate to long-running bugs that have been present in the Linux kernel for years, which means many systems are vulnerable and should be patched as soon as possible.
PinTheft is the less severe of the two, since it only applies to a flaw present in Arch Linux, that requires multiple features to be enabled. That said, Arch users are still advised to patch anyway. SteamOS is based on Arch as well, so those users may also want to prioritize system updates sooner rather than later.
SSH-keysign-pwn Example.
The more concerning exploit is definitely SSH-keysign-pwn, which has been confirmed to work across various Ubuntu versions, Debian 13, CentOS 3, Arch Linux, and Raspberry Pi OS Bookwork 6.12.75. SSH-keysign-pwn was discovered...
Copyright of this story solely belongs to hothardware.com. To see the full text click HERE