ZeroHour
oss-securitypublished ()ingested 1

Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey

mediumVulnerabilityimportance 40
AI summary · glm-5.3-flash

A hardcoded default SuperKey in FolkPatch, an APatch-based kernel patching tool, enables local privilege escalation limited to FolkPatch's downstream code.

A disclosure posted to the oss-security mailing list describes a local privilege escalation (LPE) in FolkPatch caused by a hardcoded default SuperKey. FolkPatch is a downstream project based on APatch that utilizes its own custom KernelPatch. According to the post, the vulnerability is specific to FolkPatch's downstream modifications rather than upstream APatch or KernelPatch code.

  • Hardcoded default SuperKey enables local privilege escalation
  • FolkPatch is a downstream modification of APatch with a custom KernelPatch
  • Flaw does not affect upstream APatch/KernelPatch code
Full article

Posted by 12345678 on Sep 12 Dear oss-security mailing list subscribers, https://github.com/LyraVoid/FolkPatch), https://github.com/bmax121/APatch) that utilizes its own custom https://github.com/LyraVoid/KernelPatch). The vulnerability is specific to FolkPatch's downstream modifications rather than upstream...

This source does not provide full text. Read it at seclists.org.