New RefluXFS Linux flaw lets attackers gain root privileges
… The list of impacted Linux distros includes Red Hat Enterprise Linux RHEL , Oracle Linux, Amazon Linux and Fedora, as well as CentOS Stream, Rocky Linux, AlmaLinux and CloudLinux. …
Tracked topic
Linux is the open-source operating-system kernel and the ecosystem of distributions built on it, spanning desktop, server, and embedded use; distinct from Linux gaming, which has its own topic.
… The list of impacted Linux distros includes Red Hat Enterprise Linux RHEL , Oracle Linux, Amazon Linux and Fedora, as well as CentOS Stream, Rocky Linux, AlmaLinux and CloudLinux. …
… Mengjia and Trujillo tested the attack starting from the assumption that an attacker can run arbitrary, unprivileged code on a Linux target machine to leak data from the kernel. …
… Download Now Related Articles: New Linux 'Dirty Frag' zero-day gives root on all major distros CISA says ‘Copy Fail’ flaw now exploited to root Linux systems New Linux ‘Copy Fail’ flaw gives hackers root on major distros Recently leaked Windows zero-days now exploited in attacks New ‘Pack2TheRoot’ … …
… Unlike the previously documented Linux version, the Windows variant adds kernel-level stealth capabilities allowing operators to hide malware artifacts and communicate with the backdoor through traffic redirected from arbitrary TCP ports The two variants are WIN DRV, which features kernel drivers f… …
… This limits the attack surface to Linux distributions that closely follow the latest upstream kernel releases, including Fedora, Arch Linux, and openSUSE Tumbleweed. However, V12's proof-of-concept exploit has only been tested against Fedora and the mainline Linux kernel. …
… "Sadly, the RDS kernel module this requires is only default on Arch Linux among the common distributions we tested," V12 added. Linux users on affected distros are advised to install the latest kernel updates as soon as possible. …
… This results in better stealth and reduced detection surface. “The Kernel leader is the one elected Kernel module that communicates with the Bridge module on behalf of the other Kernel modules, reducing visibility by avoiding large volumes of external traffic from multiple infected hosts,” explains… …
… Linux kernel maintainers released a patch for the Januscape vulnerability, a flaw that allows attackers to escape a virtual machine and execute arbitrary code on the host. …
… Get the whitepaper Related Articles: Google fixes one actively exploited Android zero-day, 124 flaws Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Hackers exploit FortiClient EMS flaw to push infostealer malware Hackers bypass SonicWall VPN MFA due to incomplete patching Hac… …
… According to researchers at supply-chain and devops company JFrog, IronWorm is written in Rust, hides behind an eBPF kernel rootkit, and communicates with the operator over the Tor network. …