About Linux Sudo Access Exploit

3 days ago a new exploit was shared by copy.fail that effects all the linux distros after 2017.

This script makes sudo command or knowing the password unnecessary by manipulating kernel socket.

Source code (732 byte python script, it requires only an unprivileged local user account and standard library, no network access, no kernel debugging features, not even pre-installed primitives.):

I tested it with the command shown on my Linux 6.17.0-22 and it directly elevated to sudo access without password.

Details:

@AZorin @zorink Is there any plan for a patch update to make Zorin more secure?

Take a look here at post #4, an update came:

Did you try it after that update?


Since Ubuntu is down at the most important time, I cannot upgrade from 6.17 to a newer version. Also upgrading my kernel crashed my system twice until now on zorin os. (I had to downgrade from nvidia v. 580 to 535)

It isn't a kernel upgrade. But yes, at the moment there seem to be problems with the servers. I got the update yesterday and have the file now on my Zorin 17 Lite system (at etc/modprobe.d/disable-algif_aead.conf)

1 Like