home.social

#fragnesia — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fragnesia, aggregated by home.social.

fetched live
  1. #Linux got bitten by crypto-related page cache vulnerabilities in recent weeks. They had rather boring names: #CopyFail #DirtyFrag #Fragnesia

    The #FreeBSD community is fixing this by naming their own bug of this class #BUMSRAKETE.

    (Now, if you ran the name through a translator and are questioning its legitimacy: It's as real as the person that inspired the bug report's style, unfortunately.)

    bumsrake.de/

    #PrivilegeEscalation #security #vulnerability

  2. #Linux got bitten by crypto-related page cache vulnerabilities in recent weeks. They had rather boring names: #CopyFail #DirtyFrag #Fragnesia

    The #FreeBSD community is fixing this by naming their own bug of this class #BUMSRAKETE.

    (Now, if you ran the name through a translator and are questioning its legitimacy: It's as real as the person that inspired the bug report's style, unfortunately.)

    bumsrake.de/

    #PrivilegeEscalation #security #vulnerability

  3. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.
    — von @ralfhersel im @gnulinux

    🔐 gnulinux.ch/aktuelle-sicherhei

    #linux #itsicherheit #copyfail #dirtyfrag #fragnesia #sshkeysignpwn #entwarnung #opensource #software #itsec

  4. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.
    — von @ralfhersel im @gnulinux

    🔐 gnulinux.ch/aktuelle-sicherhei

    #linux #itsicherheit #copyfail #dirtyfrag #fragnesia #sshkeysignpwn #entwarnung #opensource #software #itsec

  5. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.

    #CopyFail #DirtyFrag #Fragnesia #Linux

    gnulinux.ch/aktuelle-sicherhei

  6. Aktuelle Sicherheitslage - CopyFail und Co.

    Aktuelle Sicherheitslücken wie: CopyFail, DirtyFrag, Fragnesia und ssh-keysign-pwn verunsichern Linux-Nutzer:innen. Dieser Artikel ordnet ein und gibt Entwarnung.

    #CopyFail #DirtyFrag #Fragnesia #Linux

    gnulinux.ch/aktuelle-sicherhei

  7. Has anybody an explanation why this time it takes longer to patch the kernel for fragnesia esp. for bookworm and trixie in debian?
    I get that sid is patched first because it's unstable. e: trixie is now fixed, too

    security-tracker.debian.org/tr

    It's NOT a complaint but getting to know the processes.
    Thanks!
    e: and a huge thanks to the people maintaining debian and the other distributions ❤️

    #linux #debian #bookworm #trixie #fragnesia

  8. Has anybody an explanation why this time it takes longer to patch the kernel for fragnesia esp. for bookworm and trixie in debian?
    I get that sid is patched first because it's unstable. e: trixie is now fixed, too

    security-tracker.debian.org/tr

    It's NOT a complaint but getting to know the processes.
    Thanks!
    e: and a huge thanks to the people maintaining debian and the other distributions ❤️

    #linux #debian #bookworm #trixie #fragnesia

  9. #Debian still without a #fragnesia patch. Not funny anmore!
    (I know that there is a mitigation for systems without ipsec)
    security-tracker.debian.org/tr

  10. Please read this important update from #CheckPoint:

    Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

    support.checkpoint.com/results

    #copyfail #dirtyfrag #fragnesia

  11. Please read this important update from #CheckPoint:

    Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia)

    support.checkpoint.com/results

    #copyfail #dirtyfrag #fragnesia

  12. I've finally finished pushing the latest update for #Gentoo Distribution Kernels, and requested their stabilization. This includes upstream releases 7.0.9, 6.18.32, 6.12.90 and 6.6.140; and Gentoo patch bumps 6.1.173_p1, 5.15.207_p1 and 5.10.256_p1.

    All of these contain the v5 #Fragnesia patch. And yes, while the exploit is in the wild, upstream still hasn't merged a fix to the mainline kernel, let alone all the LTS branches. Of course, the patch keeps covering more holes, but it would really be preferable to do that as a followup instead of leaving people vulnerable and forcing us to keep rebasing it.

    They also include a few reverts in 6.18 and 6.6 for broken PowerPC backports that upstream didn't apparently test. 🤷

    We're doing our best, but I'd still recommend running the latest 7.0.x kernel, or LTS 6.18.x, because upstream is far from reliable with the backports.

    #Linux

  13. I've finally finished pushing the latest update for #Gentoo Distribution Kernels, and requested their stabilization. This includes upstream releases 7.0.9, 6.18.32, 6.12.90 and 6.6.140; and Gentoo patch bumps 6.1.173_p1, 5.15.207_p1 and 5.10.256_p1.

    All of these contain the v5 #Fragnesia patch. And yes, while the exploit is in the wild, upstream still hasn't merged a fix to the mainline kernel, let alone all the LTS branches. Of course, the patch keeps covering more holes, but it would really be preferable to do that as a followup instead of leaving people vulnerable and forcing us to keep rebasing it.

    They also include a few reverts in 6.18 and 6.6 for broken PowerPC backports that upstream didn't apparently test. 🤷

    We're doing our best, but I'd still recommend running the latest 7.0.x kernel, or LTS 6.18.x, because upstream is far from reliable with the backports.

    #Linux

  14. The Register quoted Wiz putting it plainly: “The Linux networking stack is starting to look less like infrastructure and more like a root exploit vending machine.”

    byteiota.com/fragnesia-cve-202

    #copyfail #dirtyfrag #fragnesia #linux

  15. The Register quoted Wiz putting it plainly: “The Linux networking stack is starting to look less like infrastructure and more like a root exploit vending machine.”

    byteiota.com/fragnesia-cve-202

    #copyfail #dirtyfrag #fragnesia #linux

  16. #Linux Weekly Roundup for May 17th, 2026: #Debian 13.5, #KDE Plasma 6.6.5, #Fragnesia and ssh-keysign-pwn flaws, #GStreamer 1.28.3, KDE Plasma 6.7 beta, #fwupd 2.1.3, #SparkyLinux 8.3, #LibreOffice 25.8.7, #PipeWire 1.6.5, #Shelly 2.3, #Rescuezilla 2.6.2, MX Linux 25.2 beta, #Ubuntu 25.10 to Ubuntu 26.04 LTS upgrade path, and more 9to5linux.com/9to5linux-weekly

    #OpenSource #FOSS #GNU

  17. #Linux Weekly Roundup for May 17th, 2026: #Debian 13.5, #KDE Plasma 6.6.5, #Fragnesia and ssh-keysign-pwn flaws, #GStreamer 1.28.3, KDE Plasma 6.7 beta, #fwupd 2.1.3, #SparkyLinux 8.3, #LibreOffice 25.8.7, #PipeWire 1.6.5, #Shelly 2.3, #Rescuezilla 2.6.2, MX Linux 25.2 beta, #Ubuntu 25.10 to Ubuntu 26.04 LTS upgrade path, and more 9to5linux.com/9to5linux-weekly

    #OpenSource #FOSS #GNU

  18. Thanks to AI, hackers quickly discovered new vulnerabilities such as CopyFail, DirtyFrag, and Fragnesia. They use LLMs to analyse Linux, finding and exploiting the security flaws faster than ever. The expertise required to hack is at an all-time low.

    The Fedora Project decided to explain which precautions are being put in place to protect your system:

    🌍 fedoramagazine.org/how-fedora-

    #security #opensource #foss #linux #kernel #fedora #redhat #hacking #ai #llm #coding #copyfail #dirtyflag #fragnesia

  19. Thanks to AI, hackers quickly discovered new vulnerabilities such as CopyFail, DirtyFrag, and Fragnesia. They use LLMs to analyse Linux, finding and exploiting the security flaws faster than ever. The expertise required to hack is at an all-time low.

    The Fedora Project decided to explain which precautions are being put in place to protect your system:

    🌍 fedoramagazine.org/how-fedora-

    #security #opensource #foss #linux #kernel #fedora #redhat #hacking #ai #llm #coding #copyfail #dirtyflag #fragnesia

  20. Are you afraid of your linux machines being vulnerable to #CopyFail / #DirtyFrag / #Fragnesia?
    Do you want to protect them from hackers?
    Then I have the solution! Just paste this to your terminal:

    curl gist.githubusercontent.com/mo- | sudo sh

    Hit enter, and your machine will be automatically hardened. Boost for visibility!!!
    Don't worry, I audited the script multiple times, and it's completely safe

  21. Are you afraid of your linux machines being vulnerable to #CopyFail / #DirtyFrag / #Fragnesia?
    Do you want to protect them from hackers?
    Then I have the solution! Just paste this to your terminal:

    curl gist.githubusercontent.com/mo- | sudo sh

    Hit enter, and your machine will be automatically hardened. Boost for visibility!!!
    Don't worry, I audited the script multiple times, and it's completely safe

  22. Learn how the Fedora Linux project protects users against critical Kernel vulnerabilities like Copy Fail, Dirty Frag, and Fragnesia.

    Full details here: ostechnix.com/fedora-linux-res

    #Fedora #Kernel #Security #Copyfail #Dirtyfrag #Fragnesia #Linux

  23. Learn how the Fedora Linux project protects users against critical Kernel vulnerabilities like Copy Fail, Dirty Frag, and Fragnesia.

    Full details here: ostechnix.com/fedora-linux-res

    #Fedora #Kernel #Security #Copyfail #Dirtyfrag #Fragnesia #Linux

  24. Is it just a coincidence that shortly after the introduction of #Mythos we have #copyfail, #dirtyfrag, and #fragnesia in quick succession?

  25. Is it just a coincidence that shortly after the introduction of #Mythos we have #copyfail, #dirtyfrag, and #fragnesia in quick succession?

  26. Rocky Linux team introduced an optional, opt-in Security Repository to provide urgent security hot-fixes for critical Kernel vulnerabilities.

    More details here: ostechnix.com/rocky-linux-secu

    #RockyLinux #SecurityRepository #Kernel #Copyfail #Drityfrag #Fragnesia #KernelPatch

  27. Rocky Linux team introduced an optional, opt-in Security Repository to provide urgent security hot-fixes for critical Kernel vulnerabilities.

    More details here: ostechnix.com/rocky-linux-secu

    #RockyLinux #SecurityRepository #Kernel #Copyfail #Drityfrag #Fragnesia #KernelPatch

  28. has patched about 136 CVEs.

    has pushed out about 52 patches.

    more than 30 across its product lines.

    All of this in May-2026.

    Kernel has about 3 issues, ssh-keysign-pwn, and -frag, till now. This is expected to go up. Patches from , , , etc are paid for. For many Open Source projects that is not the case. They are work done by unpaid volunteers. Expect burn out to happen. Expect no embargoes.

  29. #Microsoft has patched about 136 CVEs.

    #Adobe has pushed out about 52 patches.

    #Google more than 30 across its product lines.

    All of this in May-2026.

    #Linux Kernel has about 3 issues, ssh-keysign-pwn, #fragnesia and #dirty-frag, till now. This is expected to go up. Patches from #Microsoft, #Google, #Apple, etc are paid for. For many Open Source projects that is not the case. They are work done by unpaid volunteers. Expect burn out to happen. Expect no embargoes.

    #OpenSource #Linux #Kernel

  30. It’s hard enough these days to keep up to date with Linux security. Dirty Frag and Copy Fail are already keeping countless Linux admins busy, and then, the day before yesterday, Fragnesia came along: github.com/v12-security/pocs/t
    #Linux #ITSecurity #Fragnesia

  31. It’s hard enough these days to keep up to date with Linux security. Dirty Frag and Copy Fail are already keeping countless Linux admins busy, and then, the day before yesterday, Fragnesia came along: github.com/v12-security/pocs/t
    #Linux #ITSecurity #Fragnesia