PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch
ID: 211aa8e2-5971-5e8d-bd13-3336dd0539ee
STIX ID: report--211aa8e2-5971-5e8d-bd13-3336dd0539ee
Feed Name: Security Affairs
Threat Score
PinTheft is a local privilege escalation vulnerability in the Linux kernel's RDS zerocopy path that can lead to page-cache overwrite and root if exploited; a public proof-of-concept exists. Exposure is primarily to Arch Linux (RDS is loaded by default there), and affected users should apply the kernel patch immediately or mitigate by unloading and blacklisting the RDS modules (rmmod rds_tcp rds; add install rules to /etc/modprobe.d).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
