Linux Vulnerability Announced, Details Kept Secret  [Solved]

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Message
Author
User avatar
Mauser
Posts: 1455
Joined: Mon Jun 27, 2016 7:32 pm

Linux Vulnerability Announced, Details Kept Secret

#1 Post by Mauser »

Lunduke video on Severe (9.9 / 10) Linux Vulnerability Announced, Details Kept Secret. :eek: Hopefully this is not real. :hmm: https://www.youtube.com/watch?v=8PbTZaWFzf8
I am command line illiterate. :confused: I copy & paste to the terminal. Liars, Wiseguys, Trolls, and those without manners will be added to my ignore list. :mad:

User avatar
figueroa
Posts: 1100
Joined: Thu Dec 20, 2018 11:20 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#2 Post by figueroa »

Andy Figueroa
Using Unix from 1984; GNU/Linux from 1993

User avatar
Eadwine Rose
Administrator
Posts: 14642
Joined: Wed Jul 12, 2006 2:10 am

Re: Linux Vulnerability Announced, Details Kept Secret

#3 Post by Eadwine Rose »

Did they finally find the one responsible for all the PEBKAC issues?
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

User avatar
j2mcgreg
Global Moderator
Posts: 6814
Joined: Tue Oct 23, 2007 12:04 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#4 Post by j2mcgreg »

The boy who cried wolf has more credibility than Bryan Lunduke.
HP 15; ryzen 3 5300U APU; 500 Gb SSD; 8GB ram
HP 17; ryzen 3 3200; 500 GB SSD; 12 GB ram
Idea Center 3; 12 gen i5; 256 GB ssd;

In Linux, newer isn't always better. The best solution is the one that works.

User avatar
siamhie
Global Moderator
Posts: 3350
Joined: Fri Aug 20, 2021 5:45 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#5 Post by siamhie »

Eadwine Rose wrote: Thu Sep 26, 2024 1:52 am Did they finally find the one responsible for all the PEBKAC issues?
:rofl:
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

User avatar
siamhie
Global Moderator
Posts: 3350
Joined: Fri Aug 20, 2021 5:45 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#6 Post by siamhie »

Here is the tweet that started it all.

https://threadreaderapp.com/thread/1838 ... 35132.html


Since this threat hasn't been assigned an actual rating yet and they (all involved) have led to an agreed timeline for disclosure
  • September 30: Initial disclosure to the Openwall security mailing list.
    October 6: Full public disclosure of the vulnerability details

Simone posted this tweet (now locked) on Sep 23rd but the initial disclosure (mailing list) will be on the 30th with a public disclosure on Oct 6th but this threat was disclosed (from him) 3 weeks ago (so beginning of Sep?).

Remember that apparently this flaw has been around for 10 years and we don't even know what is affected? Could this also affect *BSD systems (CUPS is thrown around in the comments on Slashdot)?


and quoting the last line from the tweet
And YES: I LOVE hyping the sh1t out of this stuff because apparently sensationalism is the only language that forces these people to fix.
I wonder just how severe this really is...hmm? 🤔
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

User avatar
DukeComposed
Posts: 1401
Joined: Thu Mar 16, 2023 1:57 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#7 Post by DukeComposed »

Eadwine Rose wrote: Thu Sep 26, 2024 1:52 am Did they finally find the one responsible for all the PEBKAC issues?
Alan Cox hasn't been involved in the project in years.
j2mcgreg wrote: Thu Sep 26, 2024 7:31 am The boy who cried wolf has more credibility than Bryan Lunduke.
Bryan Lund, aka "Lunduke" has never been much of a journalist. He is at best a salesman whose career started as an Apple fanboy pushing software for Mac written in BASIC, pivoted to Linux "journalism" with Chris Fisher, and has now descended into the aberrant far-right political extremism of pushing a narrative that SUSE thinks 50% of its users should die because of a single anti-hate remark a SUSE employee made on a SUSE subreddit during Pride month. While I imagine that Lund has always been conservative, he has in the last few years become more extremist and reactionary than he's ever been in the past and his most recent "Linux Sucks" yearly address in which he spends a good chunk of it deliberately misinterpreting the SUSE comment is a clear example of how extreme he's gotten. His idea of Linux journalism is more tenuous and biased than ever before, and we're talking about the same man who once had a meltdown while conducting an interview with Richard M. Stallman.

User avatar
Eadwine Rose
Administrator
Posts: 14642
Joined: Wed Jul 12, 2006 2:10 am

Re: Linux Vulnerability Announced, Details Kept Secret

#8 Post by Eadwine Rose »

DukeComposed wrote: Thu Sep 26, 2024 12:56 pm
Eadwine Rose wrote: Thu Sep 26, 2024 1:52 am Did they finally find the one responsible for all the PEBKAC issues?
Alan Cox hasn't been involved in the project in years.
Who?


To be honest, I don't care about this sort of stuff on who did what and when. You use the computer, you are responsible.
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

User avatar
FullScale4Me
Posts: 1079
Joined: Fri Jan 08, 2021 11:30 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#9 Post by FullScale4Me »

Mauser wrote: Wed Sep 25, 2024 11:02 pm Lunduke video on Severe (9.9 / 10) Linux Vulnerability Announced, Details Kept Secret. :eek: Hopefully this is not real. :hmm: https://www.youtube.com/watch?v=8PbTZaWFzf8
When I clicked the link and saw I was NOT subscribed even though the creator had a huge following a quote sometimes attributed to Ringo Star came to mind - "...Nothing here to see, move along..."
Michael O'Toole
MX Linux facebook group moderator
Dell OptiPlex 7050 i7-7700, MX Linux 23 Xfce & Win 11 Pro
HP Pavilion P2-1394 i3-2120T, MX Linux 23 Xfce & Win 10 Home
Dell Inspiron N7010 Intel Core i5 M 460, MX Linux 23 Xfce & KDE, Win 10

User avatar
siamhie
Global Moderator
Posts: 3350
Joined: Fri Aug 20, 2021 5:45 pm

Re: Linux Vulnerability Announced, Details Kept Secret  [Solved]

#10 Post by siamhie »

siamhie wrote: Thu Sep 26, 2024 9:48 am Remember that apparently this flaw has been around for 10 years and we don't even know what is affected? Could this also affect *BSD systems (CUPS is thrown around in the comments on Slashdot)?

Whoever made that comment on Slashdot nailed it. He (Bryan) has an updated video out now and it is a CUPS based exploit.

The "9.9" Linux Vulnerability Revealed: It's The Printers
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

Post Reply

Return to “General”