computer-science
Patch Your Kernel NOW: 732byte Python rootkit, cracks all distros since 2017
Key takeaways
- Detector and proof-of-concept LPE for the Linux algif_aead / authencesn page-cache scratch-write bug disclosed 2026-04-29.
- Disclosure writeup: https://xint.io/blog/copy-fail-linux-distributions
- Use only on hosts you own or are explicitly engaged to assess.
Detector and proof-of-concept LPE for the Linux algif_aead / authencesn page-cache scratch-write bug disclosed 2026-04-29.
Disclosure writeup: https://xint.io/blog/copy-fail-linux-distributions
Use only on hosts you own or are explicitly engaged to assess. The LPE modifies in-memory state (page cache) but the technique is real privilege escalation — running it on systems without authorization is illegal in most jurisdictions.
Article preview — originally published by Hacker News. Full story at the source.
Read full story on Hacker News →
More top stories
Aggregated and edited by the Scoop newsroom. We surface news from Hacker News alongside other reporting so you can compare coverage in one place.
Editorial policy · Corrections · About Scoop