ノーマルビュー

今日 — 2026年6月10日 ガジェット系

High-Severity Vulnerability In Linux Caused By a Single Errant Character

著者: BeauHD
2026年6月10日 05:00

🤖 AI Summary

Linux内核において、単一の誤った記号が引き起こす高severityの脆弱性についての記事を要約します。

1. **脆弱性概要**: リナックス内で発見された CVE-2026-23111 の脆弱性は、nf_tables (ルーティング規則管理用のLinux内核サブシステム) に存在し、単一の誤った記号が原因です。この脆弱性により、未信頼なユーザーもしくはプロセスがroot権限を獲得できる可能性があります。

2. **脆弱性詳細**: 脆弱性は、use-after-free型のバグによるもので、特定のメモリ領域に悪意のあるコードが配置され、その領域の以前の内容が適切に開放されていない場合に起こります。この脆弱性は、ルーティング規則内の「catchall要素」によって引き起こされます。

3. **攻撃手法**: 脆弱性を活用する攻撃者は、決定済みのルールと一致しないパケットについて検索を行うと、「catchall要素」がアクティブになり、特定の動作が実行されます。結果として、メモリ領域から決定のマップが削除されると「catchall要素」が無効になり、チェーンの参照カウンタが減少します。

4. **対策**: 脆弱性は2月に修正されました。しかし、FuzzingLabsとExodus Intelligenceによる複数の概念証明の攻撃手法も公表されており、DebianやUbuntuでも動作するものです。

5. **関連情報**: 本記事はSlashdotで発表され、他の技術ニュースも提供されています。
An anonymous reader quotes a report from Ars Technica: Researchers have analyzed a high-severity vulnerability in Linux that's able to escalate untrusted users to root by exploiting a bug you don't often see: a single errant character inside the kernel. The vulnerability, tracked as CVE-2026-23111, is located in nf_tables, a subsystem of the Linux kernel that provides packet filtering capabilities. It's used to manage firewall rules and replaces older subsystems such as iptables, ip6tables, arptables, and ebtables. The presence of a single mis-issued exclamation point in code implementing nf_tables introduced a use-after-free, a class of vulnerability that corrupts memory by placing malicious code at memory addresses that haven't been properly freed of their previous contents. CVE-2026-23111 can be exploited by an unprivileged user or process to elevate system rights to root. The exploit works by disrupting the deletion of verdicts -- a determination within the nf_tables framework that determines if a packet matches a rule calling for a certain action to be performed. This process can use what are known as catchall elements, which act as a wildcard in the event a lookup doesn't match any other element in the set. When a verdict map is deleted from memory, catchall elements are deactivated and a chain's reference counter is decremented. When errors occur the deletion can be reversed and the counter incremented. CVE-2026-53111 allows for that process to be altered. As a result, the exploit can decrement the variable an arbitrary number of times and then delete and free the chain when some objects still point to it. Although the kernel vulnerability was fixed in February, multiple proof-of-concept exploits have since emerged, including one from FuzzingLabs in April and another from Exodus Intelligence that works on Debian and Ubuntu.

Read more of this story at Slashdot.

Microsoft Hacked To Deliver Malware To Claude and Gemini Users

著者: BeauHD
2026年6月10日 02:00

🤖 AI Summary

Microsoftが自身のGitHubリポジトリ約70個を一斉に停止し、セキュリティ研究者らによる調査を行っていることに関する報告があります。ハッカーは、AIコーディングツール(Claude CodeやGemini CLIなど)で開くと個人情報が収集されるようなマルウェアを埋め込むために、durabletaskのリポジトリに悪意のあるコードをプッシュしました。

具体的な脅威の詳細は明らかになっていません。Microsoftは声明で、「顧客とより広いエコシステムを保護する優先事項です。潜在的な脅威を調査するために一時的に一部のリポジトリを停止しました。レビュー後には再開していますが、他のリポジトリは現在も停止している場合があります。」と述べています。

この行動は非常に異例で、特にMicrosoftのような大企業にとっては不思議なことです。GitHubは5月31日に73つのMicrosoftのリポジトリを一時的に停止したことを発表しています。これらのリポジトリにはAzureやAI関連のものも含まれていました。

この事件がAI開発者コミュニティに大きな影響を与える可能性があります。Microsoftは、関連するリポジトリから内容を取り下げた一部のユーザーに対して直接通知を行ったと述べています。
An anonymous reader quotes a report from 404 Media: Microsoft has shut down a wave of its own repositories on GitHub, including those related to Azure and AI coding agents, as it investigates a data breach, according to research from cybersecurity researchers and a statement given to 404 Media by Microsoft. Hackers planted malware that would harvest peoples' credentials when they opened it in AI coding tools like Claude Code or Gemini CLI, according to one set of researchers. The exact contours of the breach are unclear, but researchers say Microsoft has disabled more than 70 of its own repositories, and pointed to a particular package that was previously compromised. Last week, cybersecurity website OpenSourceMalware.com, which acts as a clearing house for indicators of supply chain attacks so defenders can secure their own networks, and which also publishes its own write-ups, wrote about the mass disabling of Microsoft GitHub repositories. "GitHub disabled 73 Microsoft repositories across four of its GitHub organizations -- the entire Azure Functions org, the whole Durable Task family, and a row of AI sample apps -- in a 105-second sweep on June 5," the website wrote on Friday. Is it very unusual for any company, let alone Microsoft, to disable so many of its own repositories in one go. They include 49 related to Azure, Microsoft's cloud computing arm, and some concerning AI agents. The shutdown repositories also include ones related to durabletask, a Microsoft development tool. Researchers from StepSecurity wrote on Friday that the GitHub closures came after a malicious commit was pushed to the durabletask repository. That attack planted configuration files that would harvest peoples' credentials when they opened the repository in Claude Code, Gemini CLI, Cursor, or VS Code, StepSecurity wrote. Microsoft said in a statement: "Our priority is to protect customers and the broader ecosystem. We temporarily removed some repositories as we investigated potential malicious content. Some of these repos have been restored after review, while others may remain offline while work continues. As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels."

Read more of this story at Slashdot.

❌