#useafterfree — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #useafterfree, aggregated by home.social.
-
RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.
#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239
-
RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.
#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239
-
RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.
#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239
-
RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public.
#RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239
-
CVE-2026-68162, a Linux kernel SCTP use-after-free flaw (CVSS 7.8), has public PoC exploit code for root privilege escalation on Ubuntu 26.04.
#Linux #CVE202668162 #PrivilegeEscalation #SCTP #Kernel #InfoSec #UseAfterFree
-
CVE-2026-68162, a Linux kernel SCTP use-after-free flaw (CVSS 7.8), has public PoC exploit code for root privilege escalation on Ubuntu 26.04.
#Linux #CVE202668162 #PrivilegeEscalation #SCTP #Kernel #InfoSec #UseAfterFree
-
CVE-2026-68162, a Linux kernel SCTP use-after-free flaw (CVSS 7.8), has public PoC exploit code for root privilege escalation on Ubuntu 26.04.
#Linux #CVE202668162 #PrivilegeEscalation #SCTP #Kernel #InfoSec #UseAfterFree
-
CVE-2026-68162, a Linux kernel SCTP use-after-free flaw (CVSS 7.8), has public PoC exploit code for root privilege escalation on Ubuntu 26.04.
#Linux #CVE202668162 #PrivilegeEscalation #SCTP #Kernel #InfoSec #UseAfterFree
-
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
CVE-2026-81934, a critical Redis RCE flaw (CVSS 9.2), now has public exploit details and PoC code. Patch your TLS-enabled servers now.
#Redis #CVE202681934 #RCE #Vulnerability #InfoSec #UseAfterFree #TLS
https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=mastodon&utm_medium=jetpack_social
-
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
-
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
-
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
-
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
-
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
-
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
-
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
-
A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.
-
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
-
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
-
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
-
CVE-2026-52912, a Linux kernel netfilter use-after-free, now has public PoC exploit code enabling root privilege escalation.
#CVE202652912 #LinuxKernel #PrivilegeEscalation #Netfilter #UseAfterFree #PoC #Exploit #InfoSec
-
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now.
#Chrome #CVE #UseAfterFree #Google #BrowserSecurity #InfoSec #PatchNow
https://securityonline.info/chrome-cve-2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
-
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now.
#Chrome #CVE #UseAfterFree #Google #BrowserSecurity #InfoSec #PatchNow
https://securityonline.info/chrome-cve-2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
-
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now.
#Chrome #CVE #UseAfterFree #Google #BrowserSecurity #InfoSec #PatchNow
https://securityonline.info/chrome-cve-2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
-
Google patches CVE-2026-76017, a critical use-after-free in Chrome, among 7 security fixes. Update to 151.0.7922.173 or later now.
#Chrome #CVE #UseAfterFree #Google #BrowserSecurity #InfoSec #PatchNow
https://securityonline.info/chrome-cve-2026-76017/?utm_source=mastodon&utm_medium=jetpack_social
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
A public PoC for CVE-2026-68138 escalates a normal Linux user to root through a qdisc rate-table race condition.
#CVE202668138 #PrivilegeEscalation #LinuxKernel #qdisc #UseAfterFree #LPE
-
Ένα απλό σχέδιο στο Zoom μπορούσε να γίνει πύλη για να επηρεάσει κάποιος την εφαρμογή σου — χωρίς να πατήσεις τίποτα.
Η επίθεση αφορούσε τη λειτουργία annotations και, σύμφωνα με την ανάλυση, μπορούσε ακόμη και να οδηγήσει σε έλεγχο της εφαρμογής.
Δεν έχει αναφερθεί χρήση σε πραγματικές επιθέσεις, αλλά οι διορθώσεις έχουν ήδη κυκλοφορήσει.
Δες αν η έκδοσή σου είναι ασφαλής.
#Cybersecurity #Zoom #OutOfBoundsWrite #OutOfBoundsRead #UseAfterFree
-
A Linux kernel RDMA/rxe use-after-free (CVE-2026-64582) enables local privilege escalation. Full details and PoC exploit code are now public.
#CVE202664582 #LinuxKernel #PrivilegeEscalation #RDMA #UseAfterFree #InfoSec
-
A Linux kernel RDMA/rxe use-after-free (CVE-2026-64582) enables local privilege escalation. Full details and PoC exploit code are now public.
#CVE202664582 #LinuxKernel #PrivilegeEscalation #RDMA #UseAfterFree #InfoSec
-
A Linux kernel RDMA/rxe use-after-free (CVE-2026-64582) enables local privilege escalation. Full details and PoC exploit code are now public.
#CVE202664582 #LinuxKernel #PrivilegeEscalation #RDMA #UseAfterFree #InfoSec
-
A Linux kernel RDMA/rxe use-after-free (CVE-2026-64582) enables local privilege escalation. Full details and PoC exploit code are now public.
#CVE202664582 #LinuxKernel #PrivilegeEscalation #RDMA #UseAfterFree #InfoSec
-
A Linux kernel RDMA/rxe use-after-free (CVE-2026-64582) enables local privilege escalation. Full details and PoC exploit code are now public.
#CVE202664582 #LinuxKernel #PrivilegeEscalation #RDMA #UseAfterFree #InfoSec
-
У nginx сжатие заголовков одностороннее
Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.
https://habr.com/ru/articles/1070310/
#nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http
-
У nginx сжатие заголовков одностороннее
Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.
https://habr.com/ru/articles/1070310/
#nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http
-
У nginx сжатие заголовков одностороннее
Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.
https://habr.com/ru/articles/1070310/
#nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http
-
Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.
#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity
-
Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.
#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity
-
Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.
#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity
-
Linux Flaw Exposes Host to Root Access
A critical 18-year-old flaw in Linux's SCTP networking code, dubbed "SCTPhantom," has been discovered, allowing hackers to gain root access to a host; the vulnerability, tracked as CVE-2026-64564, has been present in every Linux kernel released since 2008.
https://osintsights.com/linux-flaw-exposes-host-to-root-access?utm_source=mastodon&utm_medium=social
-
A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
-
A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
-
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
-
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
-
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
-
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
-
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
-
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
-
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
-
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
-
Google's Chrome security update fixes four high-severity bugs, including CVE-2026-16807, a Codecs flaw that could enable a sandbox escape. Update now.
#Chrome #ChromeUpdate #SandboxEscape #UseAfterFree #Google #PatchNow
-
Chrome security update 150.0.7871.128 patches 7 flaws, including three critical use-after-free bugs in CameraCapture, GPU, and Network. Update now.
#Chrome #GoogleChrome #CVE202615899 #UseAfterFree #BrowserSecurity #Chromium #CyberSecurity
-
Chrome security update 150.0.7871.128 patches 7 flaws, including three critical use-after-free bugs in CameraCapture, GPU, and Network. Update now.
#Chrome #GoogleChrome #CVE202615899 #UseAfterFree #BrowserSecurity #Chromium #CyberSecurity
-
Chrome security update 150.0.7871.128 patches 7 flaws, including three critical use-after-free bugs in CameraCapture, GPU, and Network. Update now.
#Chrome #GoogleChrome #CVE202615899 #UseAfterFree #BrowserSecurity #Chromium #CyberSecurity
-
X.Org Server ships fixes for two flaws, including CVE-2026-56000, a CVSS 9.0 use-after-free. Update xorg-server and Xwayland now.
#XorgServer #Xwayland #UseAfterFree #CVE202656000 #LinuxSecurity #PatchNow #InfoSec