home.social

#copyfail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #copyfail, aggregated by home.social.

fetched live
  1. Working on Week 11 lab write up. Need to add all the citations and references to my #CopyFail presentation slides (when did bibtex become biber???? God, I'm old.)

    Also finishing up the course reflection for this, my final #CyberSecurity course. Five courses, 20 credit hours of master's level graduate courses over about 15 months.

    So, ofc, I'm going to start a practicum for Orten Gillingham #reading instruction from next week. OG+#EnglishLearners = great?

    #K12 #K12Education #TeacherLife

  2. Working on Week 11 lab write up. Need to add all the citations and references to my #CopyFail presentation slides (when did bibtex become biber???? God, I'm old.)

    Also finishing up the course reflection for this, my final #CyberSecurity course. Five courses, 20 credit hours of master's level graduate courses over about 15 months.

    So, ofc, I'm going to start a practicum for Orten Gillingham #reading instruction from next week. OG+#EnglishLearners = great?

    #K12 #K12Education #TeacherLife

  3. spent much of the day working on my #CyberSecurity presentation about #CopyFail #Linux #kernel vulnerability. About 20 slides; I have 7 minutes. No problem.

    Tomorrow, I need to finish the other homework for the class.

  4. spent much of the day working on my #CyberSecurity presentation about #CopyFail #Linux #kernel vulnerability. About 20 slides; I have 7 minutes. No problem.

    Tomorrow, I need to finish the other homework for the class.

  5. #Linux got bitten by crypto-related page cache vulnerabilities in recent weeks. They had rather boring names: #CopyFail #DirtyFrag #Fragnesia

    The #FreeBSD community is fixing this by naming their own bug of this class #BUMSRAKETE.

    (Now, if you ran the name through a translator and are questioning its legitimacy: It's as real as the person that inspired the bug report's style, unfortunately.)

    bumsrake.de/

    #PrivilegeEscalation #security #vulnerability

  6. #Linux got bitten by crypto-related page cache vulnerabilities in recent weeks. They had rather boring names: #CopyFail #DirtyFrag #Fragnesia

    The #FreeBSD community is fixing this by naming their own bug of this class #BUMSRAKETE.

    (Now, if you ran the name through a translator and are questioning its legitimacy: It's as real as the person that inspired the bug report's style, unfortunately.)

    bumsrake.de/

    #PrivilegeEscalation #security #vulnerability

  7. "[…] The "#CopyFail" vulnerability presented a unique challenge for us. Despite our practice of deploying #Linux patch updates every two weeks, we remained vulnerable because a month-old mainline fix had yet to be backported to our primary #kernel line. Despite that, we were still able to roll out patched kernels within hours of the backport's release. In the interim, #bpf-lsm provided a surgical, no-reboot mitigation that secured our fleet. […]"

    blog.cloudflare.com/copy-fail-

    #LinuxKernel

  8. "[…] The "#CopyFail" vulnerability presented a unique challenge for us. Despite our practice of deploying #Linux patch updates every two weeks, we remained vulnerable because a month-old mainline fix had yet to be backported to our primary #kernel line. Despite that, we were still able to roll out patched kernels within hours of the backport's release. In the interim, #bpf-lsm provided a surgical, no-reboot mitigation that secured our fleet. […]"

    blog.cloudflare.com/copy-fail-

    #LinuxKernel

  9. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.
    — von @ralfhersel im @gnulinux

    🔐 gnulinux.ch/aktuelle-sicherhei

    #linux #itsicherheit #copyfail #dirtyfrag #fragnesia #sshkeysignpwn #entwarnung #opensource #software #itsec

  10. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.
    — von @ralfhersel im @gnulinux

    🔐 gnulinux.ch/aktuelle-sicherhei

    #linux #itsicherheit #copyfail #dirtyfrag #fragnesia #sshkeysignpwn #entwarnung #opensource #software #itsec

  11. Docker Engine v29.4.3 mitigates the critical Copy Fail (CVE-2026-31431) vulnerability. Update immediately if you cannot patch your Linux kernel yet.

    More details here: ostechnix.com/docker-copy-fail

    #Docker #Copyfail #CVE202631431 #Pagecache #Linuxkernel

  12. Docker Engine v29.4.3 mitigates the critical Copy Fail (CVE-2026-31431) vulnerability. Update immediately if you cannot patch your Linux kernel yet.

    More details here: ostechnix.com/docker-copy-fail

    #Docker #Copyfail #CVE202631431 #Pagecache #Linuxkernel

  13. Если вы всё ещё беспокоитесь о [copy.fail](copy.fail/) в своих `kubernetes` кластерах - вот изи-фикс.

    Маленький `DaemonSet`, грузит BPF-LSM хук на `socket_create` и режет любые попытки открыть `AF_ALG`. Без ребута, без пересборки ядра, без правки cmdline.
    Работает на Talos Linux, где `rmmod` архитектурно недоступен (SELinux + lockdown + контроллер не умеет unload).

    Ставится одной командой:
    `kubectl apply -f`
    raw.githubusercontent.com/cozy

    github.com/cozystack/copy-fail

    #kubernetes #copyfail

  14. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.

    #CopyFail #DirtyFrag #Fragnesia #Linux

    gnulinux.ch/aktuelle-sicherhei

  15. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.

    #CopyFail #DirtyFrag #Fragnesia #Linux

    gnulinux.ch/aktuelle-sicherhei

  16. EVERYONE GETS AN LPE

    Windows:
    #BlueHammer (#CVE_2026_33825)
    #RedSun (#CVE_2026_41091)
    #UnDefend (#CVE_2026_45498)
    #WindowsInstaller (#CVE_2026_27910):

    Linux:
    #CopyFail (#CVE_2026_31431)
    #SSHKeysignPwn (#CVE_2026_46333)

    FreeBSD:
    #FatGid (#CVE_2026_45250)
    #ExecveBug (#CVE_2026_7270)

  17. EVERYONE GETS AN LPE

    Windows:
    #BlueHammer (#CVE_2026_33825)
    #RedSun (#CVE_2026_41091)
    #UnDefend (#CVE_2026_45498)
    #WindowsInstaller (#CVE_2026_27910):

    Linux:
    #CopyFail (#CVE_2026_31431)
    #SSHKeysignPwn (#CVE_2026_46333)

    FreeBSD:
    #FatGid (#CVE_2026_45250)
    #ExecveBug (#CVE_2026_7270)

  18. Am i being wrong to think, that it's a GOOD usage of AI when serious issues in the Kernel like #dirtyfrag and #copyfail are found and released?
    Of course they should not be used to cause harm, but imho this is a huge advantage of Open Source because the issues can be fixed quickly!

    #opensource #linux

  19. According to Phoronix, Eric Biggers now has a commit to remove zero-copy support from AF_ALG, one of its riskiest aspects and one which enabled the #CopyFail exploit. This change could become a part of Linux 7.2:

    phoronix.com/news/Linux-AF-ALF

    #linux #security #cve_2026_31431 #copyfail

  20. According to Phoronix, Eric Biggers now has a commit to remove zero-copy support from AF_ALG, one of its riskiest aspects and one which enabled the exploit. This change could become a part of Linux 7.2:

    phoronix.com/news/Linux-AF-ALF

  21. Please read this important update from #CheckPoint:

    Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

    support.checkpoint.com/results

    #copyfail #dirtyfrag #fragnesia

  22. Please read this important update from #CheckPoint:

    Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

    support.checkpoint.com/results

    #copyfail #dirtyfrag #fragnesia

  23. The Register quoted Wiz putting it plainly: “The Linux networking stack is starting to look less like infrastructure and more like a root exploit vending machine.”

    byteiota.com/fragnesia-cve-202

    #copyfail #dirtyfrag #fragnesia #linux

  24. The Register quoted Wiz putting it plainly: “The Linux networking stack is starting to look less like infrastructure and more like a root exploit vending machine.”

    byteiota.com/fragnesia-cve-202

    #copyfail #dirtyfrag #fragnesia #linux