Several vulnerabilities have been discovered in the Linux kernel
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Several vulnerabilities have been discovered in the Linux kernel
Unofficial Hacker News client; not affiliated with Y Combinator.
strenholme · · focus · HN ↗
• Two remote denial of service attacks against the DNS-over-TCP service (the DNS-over-UDP service did not appear affected), which is disabled by default.
• One network leak of 19 bytes of unallocated memory on the heap. Looking at those 19 bytes, no information of note appears to be present there.
Note that, pre-AI, there were a couple of remote memory leaks and two remote “packet of death” bugs found, but nothing earth shattering has been found since the beginning of these AI-assisted security audits.
Considering that a lot more bugs have been found in the Linux kernel, there is a reason I don’t blindly trust its /dev/urandom to always return completely random numbers I can safely use, and I don’t think the kernel has done a better job implementing a CSPRNG (cryptographic secure pseudo random number generator) than I did.