ZeroHour

Search: “oss-security mailing list”

16 stories

Re: rosbridge_library Protocol.incoming() quadratic CPU cost in JSON fallback

Alan Coopersmith's mailing list reply merely points to the public oss-security posting of the rosbridge_library disclosure.

A follow-up reply on oss-security by Alan Coopersmith notes that the rosbridge_library Protocol.incoming() quadratic CPU cost issue was disclosed publicly on the oss-security mailing list. The reply contains no additional technical detail beyond linking the original disclosure.

oss-securityupdated · 1d agofirst · 1d agoVulnerability 3 sources

Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey

A hardcoded default SuperKey in FolkPatch, an APatch-based kernel patching tool, enables local privilege escalation limited to FolkPatch's downstream code.

A disclosure posted to the oss-security mailing list describes a local privilege escalation (LPE) in FolkPatch caused by a hardcoded default SuperKey. FolkPatch is a downstream project based on APatch that utilizes its own custom KernelPatch. According to the post, the vulnerability is specific to FolkPatch's downstream modifications rather than upstream APatch or KernelPatch code.

oss-security · 3d agoVulnerability1