Rewterz

Rewterz Threat Advisory –Microsoft Windows Vulnerable to Privilege Escalation

July 21, 2021
Rewterz

Rewterz Threat Advisory –Oracle Patches Critical Vulnerabilities

July 21, 2021

Rewterz Threat Advisory –New Linux kernel bug lets you get root on most modern distros

Severity

High

Analysis Summary

CVE-2021-33909

A size_t-to-int conversion vulnerability in the Linuxkernel’s filesystem layer: by creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB, an unprivileged local attacker can write the 10-byte string “//deleted” to an offset of exactly -2GB-10B below the beginning of a vmalloc()ated kernel buffer.

Impact

  • Full root privileges

Affected Vendors

Linux

Affected Products

  • All Linux kernel versions released since 2014

Remediation

Refer to Qualys advisory for the complete analysis and mitigation technique.

https://www.qualys.com/2021/07/20/cve-2021-33909/sequoia-local-privilege-escalation-linux.txt

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.