Posts
2563
Following
163
Followers
82
AS4242423219 on DN42
Also @noisytoot@mice.tel in case chinchillas eat the cables
repeated

Quickly dove into the copy.fail exploit.

1. Yes, it's real.
2. Current chain can write any arbitrary content to any user-readable file (into the page cache).
3. Current chain relies on an available target suid binary that you can open() as a lowpriv user.
4. Current exploit relies on that binary being /bin/su and then being able to execve(/bin/sh, 0, 0) (which doesn't work on alpine, etc.). The former is easily replaced in the code. The latter needs a rebuilt payload ELF (also easy).

6
8
2

Want to make your system immune to copyfail (CVE-2026-31431) but compiled your kernel with CONFIG_CRYPTO_USER_API_AEAD=y so you can’t disable the module and don’t want to reboot? Use BPF-LSM to block AF_ALG sockets from being created!

/* SPDX-License-Identifier: GPL-2.0-or-later OR MIT */

#include <linux/bpf.h>
#include <bpf/bpf_helpers.h>
#include <bpf/bpf_tracing.h>

#define EPERM 1
#define AF_ALG 38

char LICENSE[] SEC("license") = "Dual MIT/GPL";

SEC("lsm/socket_create")
int BPF_PROG(socket_create_block_af_alg, int family, int type, int protocol, int kern, int ret)
{
  if (ret) return ret;          /* don't override a previous denial */
  if (family == AF_ALG) return -EPERM;
  return 0;
}

Compile with clang -Wall -Wextra -Wno-unused-parameter -g -O2 -target bpf -c -o nocopyfail.o nocopyfail.c and load with bpftool prog load nocopyfail.o /sys/fs/bpf/nocopyfail autoattach (as root).

0
1
2
re: injury
Show content
attempting to reassemble it would of course be pointless but I kept the fragments in a cardboard box anyway
0
0
0
injury
Show content
fuck, I just broke my favourite mug neocat_sad
... and cut my finger while picking up the pieces
1
0
0
@famfo debian stable/oldstable/oldoldstable seems to still be vulnerable, no new kernel updates... I'll just prevent algif_aead from loading for now
0
0
1
@famfo why, is there a new privilege escalation vulnerability?
2
0
0
@fun @fossdd if someone revives GTK2 then hexchat can be revived too
0
0
0
@fun @fossdd hopefully this will allow hexchat to be packaged in alpine again
1
0
0
repeated
Edited 5 months ago

I’m not saying I need new electronics but who wouldn’t want a I apologize but I cannot complete this task it requires using trademarked brand names which goes against OpenAI use policy. Is there anything else I can assist you with-16” 32GB RAM

1
5
1
@cwebber @lanodan at least on LCSC the PY32F002AL15S6TU seems to actually be the cheapest currently (ranging from $0.1294 each for 5-50 to $0.083 each for 5000+), whereas couldn't find any CH32V003s for 9 cents: the cheapest is the CH32V003J4M6 at $0.2145 each for 5-50 or $0.1035 each for 5000+

maybe it is available for 9 cents elsewhere though, I only looked on LCSC and the article doesn't specify where
0
0
0
re: death
Show content
@uwuspace I didn't know @memdmp but it's still sad neocat_sob

rest in peace
0
0
0
repeated

In light of recent events, I just want to put out a PSA

You are seen
You are loved
You are valuable

I’m kind of terrible with words, but I like being here for people. If you ever feel alone, please reach out. I promise there are people who see you and care.

4
6
1
Ed Balls
0
0
0
good night
0
0
0
@catsalad for legal reasons I would argue that activitypub is a form of email
1
0
5
@april https://jesterlinux.org/install/ says the USB drive must be ≥4GB but the ISO is 6.7GB
0
0
0
repeated

April (@ Remo Clan) The Pink ⋆☾╶⃝⃤☽⋆ [AS208709]

Edited 5 months ago
Yay okay so its finally time!
I'm announcing Jester Linux, my own distro based on NixOS for work and gaming, no Nix knowledge required! boost_ok
https://jesterlinux.org/blog/hello-world/
3
4
0
Show older