testing the #copy-fail #security PoC against podman #containers, which, surprisingly, contained it because of “User Namespace UID mappings”; explains how to get strace to work there instead of PTRACE_TRACEME: Operation not permitted. Also how to use bpftrace instead of strace to see syscalls from suid.
prevent #Linux from loading any modules after boot time for some #security hardening, including against #copy-fail
on 02026-04-30Today’s #security hole in #Linux, a local root, discovered in an hour with #AI, called #copy-fail.
on 02026-04-29