14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers

A 14-year-old Linux kernel vulnerability can let a local attacker escalate to root privileges and, in a proof-of-concept environment, escape a Docker container to compromise the underlying host. The flaw in Linux’s AF_ALG userspace cryptographic interface stems from unsafe concurrent writes to the same socket used for operations like AES encryption and decryption. Because an […]

This article has been indexed from Cyber Security News

Read the original article: