io_uring
kernel subsystem and we look
at vulnerability fixes for Netatalk, Jupyter Core, Vim, SSSD, GNU binutils, GLib
and more.
For our 199th episode Andrei looks at Fuzzing Configurations of Program Options
plus we discuss Google’s findings on the io_uring
kernel subsystem and we look
at vulnerability fixes for Netatalk, Jupyter Core, Vim, SSSD, GNU binutils, GLib
and more.
53 unique CVEs addressed
Subject DN
field - this
would then be used directly in the query and would be interpreted as
parameters in the LDAP query - could then allow a malicious client to provide
a crafted certificate which performs arbitrary LDAP queries etc - such that
when used in conjunction with FreeIPA they could elevate their privilegesio_uring
in ChromeOS and their production servers (12:00)io_uring
- with around
$1m USD rewarded for io_uring
submissions alone - and io_uring
was used in all
submissions which bypassed their mitigations
io_uring
in ChromeOS (was originally enabled back in
November 2022 to increase performance of their arcvm
which is used to run
Android apps on ChromeOS) but then now disabled 4 months later in Feb this
yeario_uring
to Android applications and in the
future will also use SELinux to restrict access even further to only select
system processesio_uring
on their production serversio_uring
and ongoing development of features
for it, it presents too much of a risk for use by untrusted applications etc