Local Privilege Escalation Vulnerability Affecting X.Org Server For 18 Years (www.phoronix.com)
from wizardbeard@lemmy.dbzer0.com to linux@lemmy.ml on 29 Oct 23:14
https://lemmy.dbzer0.com/post/30537529

Crosspost of lemmy.sdf.org/post/24401210

#linux

threaded - newest

9point6@lemmy.world on 29 Oct 23:19 next collapse

That thumbnail lol

maniacalmanicmania@aussie.zone on 29 Oct 23:42 next collapse

Perfect Christmas gift idea

dracs@programming.dev on 30 Oct 04:14 next collapse

I’ve got a few old PCI cards around somewhere. I should pull one of them out and give them a try at this.

Sylvartas@lemmy.world on 30 Oct 11:58 collapse

If this metal thingy is anything like the one used as dust covers inside PC cases it’ll just bend (I’ve actually tried to use one as a bottle opener).

toynbee@lemmy.world on 30 Oct 13:33 collapse

Works well for cans, though, in my experience.

For a while I had a fiber SFP that was amazing at opening cans, too.

bruhduh@lemmy.world on 30 Oct 06:38 collapse

Sysadmin job be like

Matty_r@programming.dev on 29 Oct 23:42 next collapse

Its good that people care enough to keep finding these vulnerabilities

davidgro@lemmy.world on 30 Oct 06:29 next collapse

Yeah, This case especially since it includes XWayland

drwho@beehaw.org on 30 Oct 16:15 collapse

If only for the sake of one’s CV. Making your bones by having a couple of 0-days under your belt helps a lot of folks find jobs these days.

sneak100@hexbear.net on 29 Oct 23:43 next collapse

bruh

nyan@sh.itjust.works on 30 Oct 13:42 next collapse

Yet another, “well, yeah, technically it has security ramifications, but I’m not admin’ing any multiuser machines, so I’m not losing any sleep over it” bug.

DieserTypMatthias@lemmy.ml on 30 Oct 14:20 next collapse

What do you expect? X11 is in maintenance mode. Although I’ll miss Polybar, I won’t miss the protocol.

phoenixz@lemmy.ca on 30 Oct 15:01 next collapse

Is it? Afaik it very much is not

drwho@beehaw.org on 30 Oct 16:14 next collapse

It is. That’s why Wayland is being pushed so hard, it’s a codebase that’s actually maintainable, with hopefully some more modern design and engineering principles.

tekato@lemmy.world on 30 Oct 16:35 collapse

Well, freedesktop.org is now focused on Wayland (Xorg is not getting HDR, new synchronization protocols, or proper VRR (unless through XWayland), while Wayland is). RedHat RHEL marked Xorg as deprecated last year and will not even support it by next year (RHEL 10). KDE and GNOME also default to Wayland.

tekato@lemmy.world on 30 Oct 16:24 next collapse
semperverus@lemmy.world on 31 Oct 02:08 collapse

I think it’s still valuable to document these things so that the users who insist on sticking with X11 can receive a healthy dose of this (replace diapers with vulnerabilities) when the proverbial shit hits the fan and it becomes as hackable as Windows XP

MonkderVierte@lemmy.ml on 30 Oct 14:32 collapse

Rootless Xorg is still a niche thing?