What went wrong with this case?
Theori appear to have only contacted the linux kernel devs with the vulnerability, as opposed to going the usual CVD route that includes all of the major Linux distros.
Why is this a problem? Since the linux kernel became a CNA, there has been a flood of CVEs for the Linux kernel. The Linux kernel devs' arguments is that any given kernel flaw could presumably be leveraged to behave as a vulnerability, and it's not worth their time to determine "vulnerability" or "not a vulnerability". Everything gets a CVE.
Now the case with copy.fail? It was indeed reported to the kernel devs. And it got a CVE. A single CVE buried in flood of all of the Linux kernel CVEs.
And it appears that every distro on the planet was blindsided by this proven-exploitable vulnerability because they were not given any warning. Or even any suggestion to pick this single CVE out of the sea of Linux kernel CVEs as worth cherry picking.
Much to the chagrin of the Linux devs, RHEL doesn't use up-to-date Linux kernels. They cherry pick CVEs to backport to their chosen kernel version. (e.g. the latest and greates RHEL 10.1 uses 6.12.0, which was released November 17 2024). And in this world where bad actors like Theori don't involve vendors in vulnerability coordination, and just about every Linux kernel bug gets a CVE, this workflow fails. Hard.
Good times...
Anyone saying "Scientists don't want you to know this fact" has never met a scientist.
Scientists are famous oversharers.
Dear #gitlab a Work Item is not something I want to be concerned with in #FreeSoftware stuff I do in my free time. Can't we have names that are more motivating like "Puzzles to solve"?
Today I have spent way too much time handling the https://copy.fail situation #copyfail
The persons who discovered it didn't notify the distribution security list, so no patched kernels was available for people to install when they released it.
But they did have time to write an exploit, and thought it was a good idea to distribute that on day one, before vendors had time to provide patches.
I'm not very impressed with xint.io, I guess it's the marketing department that runs the show.
@PeterMotte This was just a silly computer joke. "GPT" can also mean "GUID Partition Table".
I don't understand the hate against GPT. I think it's a great technology, and definitely a step in the right direction. Of course there are those who will resist it, but we should all accept it's here to stay.
For example, having a backup copy of the partition table at the end of the disk greatly increases the chances of being able to recover from disk corruption at the first few sectors of the disk.
...chatbot? What chatbot?
CopyFail Was Not Disclosed to Distros : https://www.openwall.com/lists/oss-security/2026/04/30/10
Update: not available
I'm donating #Pixel3 with installed #PostmarketOS #Phosh edge. It helps me open #mobileLinux world and now I prefer a more modern hardware.
I'd be happy to post it to someone who needs it as long it's in the EU. No payment needed.
You can also come collect it in #Helsinki
https://wiki.postmarketos.org/wiki/Google_Pixel_3_(google-blueline)
Update:
Thank you for the support. I'm going to send the phone to Hamburg. Happy coding!