Scoopfeeds — Intelligent news, curated.
computer-science

Patch Your Kernel NOW: 732byte Python rootkit, cracks all distros since 2017

Hacker News · Apr 30, 2026, 8:48 PM

Key takeaways

  • Detector and proof-of-concept LPE for the Linux algif_aead / authencesn page-cache scratch-write bug disclosed 2026-04-29.
  • Disclosure writeup: https://xint.io/blog/copy-fail-linux-distributions
  • Use only on hosts you own or are explicitly engaged to assess.

Detector and proof-of-concept LPE for the Linux algif_aead / authencesn page-cache scratch-write bug disclosed 2026-04-29.

Disclosure writeup: https://xint.io/blog/copy-fail-linux-distributions

Use only on hosts you own or are explicitly engaged to assess. The LPE modifies in-memory state (page cache) but the technique is real privilege escalation — running it on systems without authorization is illegal in most jurisdictions.

Article preview — originally published by Hacker News. Full story at the source.
Read full story on Hacker News → More top stories
Aggregated and edited by the Scoop newsroom. We surface news from Hacker News alongside other reporting so you can compare coverage in one place. Editorial policy · Corrections · About Scoop