FatGid: FreeBSD 14.x kernel local privilege escalation
37 points by WhyNotHugo 4 hours ago | 8 comments

socphoenix 2 hours ago
Not sure why this is saying it isn’t patched, they released the notice including fix for 14.4 yesterday?
reply
irishcoffee 7 minutes ago
[dead]
reply
turkeyboi 44 minutes ago
Why does this need to be a whole ass website
reply
tptacek 6 minutes ago
Why not? This weird complaint has been happening since ~2010 and it has never made any sense. You are strictly better off with the website than without it. When it was vulnerability researchers getting all peevish about the status competition they were running, I at least understood where the complaint was coming from, but even among practitioners, branded vulnerabilities are so much the norm at this point that there's no status implication anymore.
reply
dragontamer 30 minutes ago
What?

Is there something in this website that feels unnecessary? It seems like a good format of sharing high quality information.

This looks like a full bug into a complete root escalation of a kernel. That's hard to do and deserving of praise. The fact that we have a writeup organized like this is awesome.

-------

This is sort of the expert level stuff that I thought HackerNews would most enjoy.

reply
cryo32 10 minutes ago
You're not going to get anywhere in the security sector unless you gain notoriety i.e. are noticed.

This appears to come from dressing up like Elton John in a feather suit and hiring a marketing team.

reply
tptacek 3 minutes ago
It's a wall of text about a kernel stack overflow. I'm not sure where the "Elton John" part is. Is it... that they used an accent color?
reply
djha-skin 23 minutes ago
TrueNAS is on FreeBSD, as well as lots of network equipment. This does affect us more than we think as operators.
reply
ActionHank 18 minutes ago
Possibly Playstation as well.
reply