New Dirty Frag Linux Bug Emerges
The vulnerability class is a potent new iteration of kernel bugs that corrupt the page cache of read-only files and is a follow-on to the recently disclosed Copy Fail Linux LPE bug.
All topics
The vulnerability class is a potent new iteration of kernel bugs that corrupt the page cache of read-only files and is a follow-on to the recently disclosed Copy Fail Linux LPE bug.
The latest branded bug is a slick, portable LPE in many Linux kernels going back to 2017.
Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.
The flaw is in the way that the telnetd server handles some specific user-supplied data. An attacker who exploits this vulnerability would be able to bypass the authentication path and gain root privileges.
GitHub said the changes will help "fortify the security of the software supply chain" after a recent surge of attacks targeting the npm ecosystem.