ノーマルビュー

High-Severity Vulnerability In Linux Caused By a Single Errant Character

著者: BeauHD
2026年6月10日 05:00

🤖 AI Summary

Linux内核に重大な脆弱性が存在し、これにより不信任用户可将系统权限提升至root。该漏洞名为CVE-2026-23111,位于提供包过滤功能的nf_tables子系统中,用于管理防火墙规则并取代了旧的iptables等子系统。

研究人员认为,由于在实施nf_tables的代码中误输入了一个感叹号,从而引入了一种名为use-after-free的漏洞。此漏洞通过将恶意代码放置在未被正确释放的内容的内存地址来破坏内存。CVE-2026-23111可使不具有系统权限的用户或进程将其权限提升为root。

该漏洞利用机制通过干扰删除verdicts(nf_tables框架中的一个决定,确定数据包是否匹配规则并要求执行特定操作),利用所谓的通配符catchall元素。当从内存中删除verdict map时,catchall元素会失效,并且链的引用计数会减少。当错误发生时,该删除可以被撤销并重新增加计数。

尽管内核漏洞已在2月修复,但自那时起已经出现了多个概念验证攻击代码,包括FuzzingLabs在4月发布的和Exodus Intelligence针对Debian和Ubuntu的操作系统开发的版本。
An anonymous reader quotes a report from Ars Technica: Researchers have analyzed a high-severity vulnerability in Linux that's able to escalate untrusted users to root by exploiting a bug you don't often see: a single errant character inside the kernel. The vulnerability, tracked as CVE-2026-23111, is located in nf_tables, a subsystem of the Linux kernel that provides packet filtering capabilities. It's used to manage firewall rules and replaces older subsystems such as iptables, ip6tables, arptables, and ebtables. The presence of a single mis-issued exclamation point in code implementing nf_tables introduced a use-after-free, a class of vulnerability that corrupts memory by placing malicious code at memory addresses that haven't been properly freed of their previous contents. CVE-2026-23111 can be exploited by an unprivileged user or process to elevate system rights to root. The exploit works by disrupting the deletion of verdicts -- a determination within the nf_tables framework that determines if a packet matches a rule calling for a certain action to be performed. This process can use what are known as catchall elements, which act as a wildcard in the event a lookup doesn't match any other element in the set. When a verdict map is deleted from memory, catchall elements are deactivated and a chain's reference counter is decremented. When errors occur the deletion can be reversed and the counter incremented. CVE-2026-53111 allows for that process to be altered. As a result, the exploit can decrement the variable an arbitrary number of times and then delete and free the chain when some objects still point to it. Although the kernel vulnerability was fixed in February, multiple proof-of-concept exploits have since emerged, including one from FuzzingLabs in April and another from Exodus Intelligence that works on Debian and Ubuntu.

Read more of this story at Slashdot.

Microsoft Hacked To Deliver Malware To Claude and Gemini Users

著者: BeauHD
2026年6月10日 02:00

🤖 AI Summary

マイクロソフトが自身のリポジトリにマルウェアを配布するためにハッキングされたと報告されています。404 Mediaの記事によると、微软遭遇了自己的仓库被黑客植入恶意软件,以分发给Claude和Gemini用户

1. マイクロソフトはGitHub上の自身のリポジトリ約70を一時的に停止しました。この措置はAzureやAIコーディングツールに関連するものでした。
2. サイバーセキュリティ研究者らは、クラウド工具有りの「durabletask」リポジトリに悪意のあるコミットが送られた後、GitHubがこれらのリポジトリを一時的に停止したと報告しています。
3. その攻撃は、Claude CodeやGemini CLIなどAIコーディングツールを開くときにユーザーの資格情報を収集するための設定ファイルを植え付けるように設計されていました。
4. マイクロソフトは、「当社の優先事項は顧客と広範な生態系を保護することです。潜在的な悪意のあるコンテンツ調査中、一部のリポジトリはレビュー後に復旧されましたが、他のものについては作業が継続される場合があります」と声明を発表しました。

この事件はマイクロソフト自身のGitHubリソースに攻撃者が侵入したため、異例の事態として注目を集めています。
An anonymous reader quotes a report from 404 Media: Microsoft has shut down a wave of its own repositories on GitHub, including those related to Azure and AI coding agents, as it investigates a data breach, according to research from cybersecurity researchers and a statement given to 404 Media by Microsoft. Hackers planted malware that would harvest peoples' credentials when they opened it in AI coding tools like Claude Code or Gemini CLI, according to one set of researchers. The exact contours of the breach are unclear, but researchers say Microsoft has disabled more than 70 of its own repositories, and pointed to a particular package that was previously compromised. Last week, cybersecurity website OpenSourceMalware.com, which acts as a clearing house for indicators of supply chain attacks so defenders can secure their own networks, and which also publishes its own write-ups, wrote about the mass disabling of Microsoft GitHub repositories. "GitHub disabled 73 Microsoft repositories across four of its GitHub organizations -- the entire Azure Functions org, the whole Durable Task family, and a row of AI sample apps -- in a 105-second sweep on June 5," the website wrote on Friday. Is it very unusual for any company, let alone Microsoft, to disable so many of its own repositories in one go. They include 49 related to Azure, Microsoft's cloud computing arm, and some concerning AI agents. The shutdown repositories also include ones related to durabletask, a Microsoft development tool. Researchers from StepSecurity wrote on Friday that the GitHub closures came after a malicious commit was pushed to the durabletask repository. That attack planted configuration files that would harvest peoples' credentials when they opened the repository in Claude Code, Gemini CLI, Cursor, or VS Code, StepSecurity wrote. Microsoft said in a statement: "Our priority is to protect customers and the broader ecosystem. We temporarily removed some repositories as we investigated potential malicious content. Some of these repos have been restored after review, while others may remain offline while work continues. As part of our investigation, we notified a small number of customers who may have pulled down content from the affected repositories. We will continue to investigate, and if anything further is identified that requires customer action, we will reach out directly through our established support channels."

Read more of this story at Slashdot.

❌