About Linux Sudo Access Exploit

3 days ago a new exploit was shared by copy.fail that effects all the linux distros after 2017.

This script makes sudo command or knowing the password unnecessary by manipulating kernel socket.

Source code (732 byte python script, it requires only an unprivileged local user account and standard library, no network access, no kernel debugging features, not even pre-installed primitives.):

I tested it with the command shown on my Linux 6.17.0-22 and it directly elevated to sudo access without password.

Details:

@AZorin @zorink Is there any plan for a patch update to make Zorin more secure?

2 Likes

Take a look here at post #4, an update came:

Did you try it after that update?

1 Like


Since Ubuntu is down at the most important time, I cannot upgrade from 6.17 to a newer version. Also upgrading my kernel crashed my system twice until now on zorin os. (I had to downgrade from nvidia v. 580 to 535)

2 Likes

It isn't a kernel upgrade. But yes, at the moment there seem to be problems with the servers. I got the update yesterday and have the file now on my Zorin 17 Lite system (at etc/modprobe.d/disable-algif_aead.conf)

3 Likes

Maybe try it again now with the Terminal. I see at the Moment that only the Launchpad Sources are not available but the Ubuntu Archive Sources seems to work now. So, you would get Updates from the Launchpad Sources which would mean Updates from the zorin OS Sources but at least Ubuntu Updates could work.

It's the same error unfortunately

Well, when You want at least close the CopyFail Thing manually, You could do that. You would have to create a File called disable-algif_aead.conf in /etc/modprobe.d/

It should look like here shown:

3 Likes

Today finally canonical servers worked so I made the upgrade.
But it changed my default windowing from X to Wayland. Why?
I realized the change when flameshot didn't work and screen flashed and windows had white border and so many weird things...
When I logged out, I saw that now it says this


(Before: There were "Zorin Desktop" and "Zorin Desktop on Wayland" options since I installed Zorin with Nvidia Drivers, and Zorin Desktop was the X11/Xorg one. Now it's the opposite)
So I had to change to Xorg again.

Hi. Because Zorin updates come from the affected ppa.launchpad.net, the servers will have triggered system-wide updates. That is why your cog settings have changed.

Other distributions (except KDE) usually have X11 (xorg) the default (or did). Personally it would be great if Wayland were dropped in favour of XLibre. Thankfully the two distributions I use, 1 has already adopted XLibre, the other is going to.

2 Likes