Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. ⚠️ 🤪 🔥 Nouvelle vuln kernel Linux aujourd'hui : ssh-keysign-pwn 🔑

⚠️ 🤪 🔥 Nouvelle vuln kernel Linux aujourd'hui : ssh-keysign-pwn 🔑

Scheduled Pinned Locked Moved Uncategorized
cyberveillelinuxsshkeysignpwn
3 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • decio@infosec.exchangeD This user is from outside of this forum
    decio@infosec.exchangeD This user is from outside of this forum
    decio@infosec.exchange
    wrote last edited by
    #1

    ⚠️ 🤪 🔥
    Nouvelle vuln kernel Linux aujourd'hui : ssh-keysign-pwn 🔑

    Pas une LPE cette fois, mais lecture de fichiers root en user non-privilégié :
    • Clés privées SSH host (ecdsa/ed25519/rsa)
    • /etc/shadow → crack offline

    Le bug : ptrace_may_access() saute le check dumpable quand mm=NULL. Race window entre exit_mm() et exit_files(). Flaggé par Jann Horn en 2020... corrigé en 2026. 6 ans.

    Confirmé sur : Debian 13, Ubuntu 22/24/26, Arch, CentOS, RPi OS. Pas de prérequis CONFIG spécifique donc cela semblerait bien plus universel que Fragnesia.

    Patch mergé dans mainline par Linus aujourd'hui (31e62c2ebbfd), pas encore dans les kernels stables.
    Pas de CVE assigné à ce stade.
    👇
    https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn

    "Six-Year-Old Linux Kernel Flaw Lets Unprivileged Users Read Root-Owned Files
    "
    ⬇️
    https://9to5linux.com/six-year-old-linux-kernel-flaw-lets-unprivileged-users-read-root-owned-files

    #cyberVeille #Linux #sshkeysignpwn

    decio@infosec.exchangeD 1 Reply Last reply
    0
    • decio@infosec.exchangeD decio@infosec.exchange

      ⚠️ 🤪 🔥
      Nouvelle vuln kernel Linux aujourd'hui : ssh-keysign-pwn 🔑

      Pas une LPE cette fois, mais lecture de fichiers root en user non-privilégié :
      • Clés privées SSH host (ecdsa/ed25519/rsa)
      • /etc/shadow → crack offline

      Le bug : ptrace_may_access() saute le check dumpable quand mm=NULL. Race window entre exit_mm() et exit_files(). Flaggé par Jann Horn en 2020... corrigé en 2026. 6 ans.

      Confirmé sur : Debian 13, Ubuntu 22/24/26, Arch, CentOS, RPi OS. Pas de prérequis CONFIG spécifique donc cela semblerait bien plus universel que Fragnesia.

      Patch mergé dans mainline par Linus aujourd'hui (31e62c2ebbfd), pas encore dans les kernels stables.
      Pas de CVE assigné à ce stade.
      👇
      https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn

      "Six-Year-Old Linux Kernel Flaw Lets Unprivileged Users Read Root-Owned Files
      "
      ⬇️
      https://9to5linux.com/six-year-old-linux-kernel-flaw-lets-unprivileged-users-read-root-owned-files

      #cyberVeille #Linux #sshkeysignpwn

      decio@infosec.exchangeD This user is from outside of this forum
      decio@infosec.exchangeD This user is from outside of this forum
      decio@infosec.exchange
      wrote last edited by
      #2

      "Logic bug in the Linux kernel's __ptrace_may_access() function"
      👇
      https://www.openwall.com/lists/oss-security/2026/05/15/2

      #CyberVeille #sshkeysignpwn

      decio@infosec.exchangeD 1 Reply Last reply
      0
      • decio@infosec.exchangeD decio@infosec.exchange

        "Logic bug in the Linux kernel's __ptrace_may_access() function"
        👇
        https://www.openwall.com/lists/oss-security/2026/05/15/2

        #CyberVeille #sshkeysignpwn

        decio@infosec.exchangeD This user is from outside of this forum
        decio@infosec.exchangeD This user is from outside of this forum
        decio@infosec.exchange
        wrote last edited by
        #3

        #sshkeysignpwn

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups