blasty
4.4K posts

blasty
@bl4sty
irresponsible disclosure aficionado
The Netherlands Katılım Nisan 2009
1.1K Takip Edilen17.2K Takipçiler

@bl4sty and mine supports *every* arch supported by nolibc, which is most of them
English

to celebrate the release of Copy Fail and the professional way the embargo and disclosure was handled by all involved parties i have sacrificed my lunchbreak to do a quick C port (with aarch64 support and some other small things) of the original PoC
gist.github.com/blasty/d7b5d05…
English

@andersonc0d3 no, but if I had to guess: the page cache is shared with the host, but it would only affect things that are bind-mounted or use the same underlying image overlays (eg. multiple docker containers derived from same base); mostly speculating here though :)
English

@bl4sty Cool work. So, do you know anything about this?
x.com/andersonc0d3/s…
Anderson Nascimento@andersonc0d3
Does copy.fail setuid binary technique work by default on a Docker container? If so, I made some mistakes in the past because I didn't see a shared page cache with the host. The binaries and files had different inodes.
English

@bl4sty As if there was an embargo and distros were even contacted at all
English

it really is pretty funny/sad yeah :) maybe they expect consumers to *also* grep LKML for @theori.io (&& others) attribution/patches and read each one of them carefully to form their own independent judgement!
Marco Bonelli@mebeim
> Trivially exploitable critical vulnerability impacting Linux with 10 years of coverage > Fix commit message: "there is no need to do this, simplify this piece of code"
English
blasty retweetledi

crazy, gj xint! 🦾🤖
Tim Becker@tjbecker
Very cool Linux bug found by @xint_official 100% reliable, instant LPE from a portable python script that works on all platforms and distros. Root cause is a subtle logic bug at the intersection of several subsystems. I highly recommend patching and checking out the details!

@__suto @halvarflake yeah there was this recent paper about misbehaving token providers: arxiv.org/abs/2604.08407 -- scary, but expected :)

English

@halvarflake you will never know, there is some report about these misbehaving provider few months ago on openrouter. I think it happen more than often!
English

@halvarflake curious about your setup. its super easy to burn $2.5k worth of opus-4.6 tokens and come back (mostly) empty handed. if I had to guess there's probably quite some variant overlap included in that 270 metric as well
English










