❌

Lees weergave

Ben Hutchings: FOSS activity in July 2026

  •  

Russell Coker: Packet Edit Meme and Debian SE Linux

There’s yet another Linux kernel exploit based on container functions, here’s the result when run as user_t on a SE Linux system:

$ ./packet_edit_meme 
[*] target /bin/su as uid 1000; entry at file offset 0x4340; shellcode 48 bytes
unshare: Permission denied
[-] page-cache corruption failed

Here is the audit log entry for this failure:

type=AVC msg=audit(1785640621.498:1843): avc:  denied  { create } for  pid=1770 comm="packet_edit_mem" scontext=user_u:user_r:user_t:s0 tcontext=user_u:user_r:user_t:s0 tclass=user_namespace permissive=0

Here’s the result of running it from the unconfined_t domain:

$ ./packet_edit_meme 
[*] target /bin/su as uid 1001; entry at file offset 0x4340; shellcode 48 bytes
[+] su entry overwritten; exec'ing su -> interactive root shell
# id
uid=0(root) gid=0(root) groups=0(root),1001(test2) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
# 

Daniel Baumann wrote a blog post describing how this is fixed for Debian systems without SE Linux.

Related posts:

  1. Debian SE Linux and PinTheft We have a new Linux exploit called PinTheft [1]. I...
  2. Debian SE Linux and ssh-keysign-pwn I just tested out the ssh-keysign-pwn exploit [1] on Debian...
  3. Dirty Frag on Debian and SE Linux Hot on the heels of the Copy Fail vulnerability [1]...
  •  
❌