ULS 254: Dirty Frags, Dirty Hacks

Untitled Linux Show #254 - “Dirty Frags, Dirty Hacks”

Episode 254 of Untitled Linux Show is now available.

  • Critical “Dirty Frag” kernel vulnerability requires immediate patching for local privilege escalation
  • Raspberry Pi Imager gains organization support and secure boot features for CM5
  • Valve unveils redesigned Steam Controller with 35-hour battery and Grip Sense technology
  • Ubuntu’s Twitter account compromised; VideoLAN previews dav2d AV2 decoder
  • AlmaLinux commits to 32-bit support following RHEL’s discontinuation

#Linux #OpenSource #Security #RaspberryPi #Valve #Ubuntu #AlmaLinux

I had to roll out Copy Fail mitigations last week, and this week I already had to run a scan to see if we’re vulnerable to Dirty Pipe on our servers.

Since there’s already official patches out for Copy Fail, at the end of the month I also have to roll back the custom mitigation because they have performance impacts (i think?)