TGViewer
Channel Public Channel
Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
Subscribers
4.74K
Photos
123
Videos
0
Links
356

Showing posts older than #86 · Back to latest

Older Posts 20 shown
Post #85 1.02K
Post #84 2.81K
Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits

A research about introducing vulnerabilities into the kernel while pretending to fix bugs. The researchers succeeded.

This research was done last year, but subsequent (seemingly unrelated) work by the same authors is now causing a lot of drama in the Linux kernel community.

Paper: https://github.com/QiushiWu/QiushiWu.github.io/blob/main/papers/OpenSourceInsecurity.pdf
Drama: https://twitter.com/gregkh/status/1384785747874656257
GitHub qiushiwu.github.io/papers/OpenSourceInsecurity.pdf at main · QiushiWu/qiushiwu.github.io Contribute to QiushiWu/qiushiwu.github.io development by creating an account on GitHub.
Post #83 900
Rust in the Linux kernel

An RFC patch series that adds Rust support to the kernel has been posted. It aims to provide wrappers for the core kernel APIs and allow implementing kernel modules in safe Rust.

The series includes a work-in-progress Rust implementation of the Android binder driver.

See the cover letter for the high-level design outline and the blog post for a deeper explanation of the implementation of an example module.

Cover letter: https://lore.kernel.org/lkml/20210414184604.23473-1-ojeda@kernel.org/
Blog post: https://security.googleblog.com/2021/04/rust-in-linux-kernel.html
Google Online Security Blog Rust in the Linux kernel Posted by Wedson Almeida Filho, Android Team In our previous post , we announced that Android now supports the Rust programming language...
Post #82 929
Post #81 1.41K
BleedingTooth: Exploiting Bluetooth RCE in the Linux kernel

BleedingTooth is a set of zero-click vulnerabilities in the Linux Bluetooth subsystem that can allow an unauthenticated remote attacker in short distance to execute arbitrary code with kernel privileges on vulnerable devices.

https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup
security-research BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Post #78 896
Post #77 834
Android Security Bulletin — January 2021

A fix for an uninitialized memory disclosure in core files, two fixes for speculative execution bugs, and a bunch of fixes for Qualcomm drivers.

A note regarding one of the latter: "There are indications that CVE-2020-11261 may be under limited, targeted exploitation."

https://source.android.com/security/bulletin/2021-01-01#kernel-compoents
https://source.android.com/security/bulletin/2021-01-01#qualcomm-components
  • 👍 1
Post #72 827
Post #67 759
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →