Stupidity . . . or not (and apologies)
Stupidity . . . or not (and apologies)
Posted May 8, 2026 1:57 UTC (Fri) by Heretic_Blacksheep (guest, #169992)In reply to: Stupidity . . . or not (and apologies) by jpeisach
Parent article: Dirty Frag: a zero-day universal Linux LPE
It would be negligent if there weren't workarounds that most people could deploy immediately assuming they don't use kernel IPSEC in their environment in this specific case. Once the embargo is broken, it's *broken*. The cat is out of the bag and there's no putting it back in. This *is* the responsible thing to do for the community. We don't live in a binary world (pun intended). From any given POC, obscure origin or not, there's only a few hours on average before exploitation begins. Prepare to see a lot more of these as people use *LMs to summarize and engineer exploits as soon as patch code becomes public regardless of embargo status.
Embargos are becoming obsolete in a world where anyone can deploy LM tooling to summarize fixes and produce chained exploits in moments. Every scriptkiddie has the potential to deploy fully functional, sophisticated attack tools now. Open source or closed source are immaterial because the LMs can also reverse engineer machine code. This will be the norm until all the low hanging (read financially/resource cheap) fruit is already picked.
