Bonum Certa Men Certa

The Slop-Amplified Fear of Privilege Escalation (Local, Not Remote) in Linux, the Kernel

posted by Roy Schestowitz on May 12, 2026

Don't panic over new Linux exploits: How to check if your PC is affected in under 5 minutes

This article will not belittle security, but it will put things in some much-needed perspective.

Lately there were a couple of bugs found (one prematurely talked about due to carelessness and lack of coordination with self-serving opportunists who profit from a sense of risk) in Linux - the kernel, proper, but not 'core' parts - and both of them got branded, which in the more distant past (pre-IBM) Red Hat complained about. It asserted that logos and catchy names meant lots of media hype would follow, irrespective of the real severity or objective underlying risk/s. One of the brands can cover two separate bugs (but interconnected). To quote one site: "Dirty Frag is a vulnerability chain combining two page-cache write primitives in the Linux kernel: one in the xfrm-ESP (IPsec) subsystem..." (link omitted due to sensationalism)

I used IPsec for a number of years but have not had it installed for over half a decade. As noted in IRC earlier today, there is more impact for some than for others. In many use cases (for servers, desktops, gadgets), this is not relevant. A week ago it already 'leaked' that AFS was impacted and "AFS had a lot of file ACL commands to let any user create an AFS ACL and put 4 group project members in..."

How many people still use AFS and how easy is it to access AFS-linked code?

Quoting the Linux Mint forums: "I guess I'm just wondering *exactly* how vulnerable the normal user is to this exploit? Not saying it's not important, but what is the probability that a single user workstation can be affected by this? The mitigation is fairly simple, so that's a relief."

So now there is a patch and there will be many more patches anyway. Many more. Linux gets patched all the time. How many people should be frantic about it and reboot ASAP? As someone in the forums put it: "Also, please note, to be affected by this vulnerability, you need a malicious local user capable to access your computer. That quite a theoretical possibility for most of us."

We are not downplaying those bugs, but we feel like one of them (the first) was creating lots of hype because it was allegedly a slop-attributed one (allegedly; we cannot know for sure and it is not wise to guess); we were all along being privately practical about this and rebooted when the patch became available. To be clear, local privilege escalation bugs will never be a huge deal like authentication bypass over SSH.

The pair of bugs (above) are not as critical as the media wants us to believe. The first is not 10.0 (rating for severity), not even 9.0. It is probably OK to apply that and reboot, but on many systems it is not imperative. As I explained earlier today to a peer, it very unlikely that a new PM (Perl Module) in Debian will contain an exploit for this (which can moreover be potently planted, then subsequently leveraged). It's also unlikely that any of the local users on our systems will get all nasty (or that Rianne will decide to become root; which she can regardless). And so in "realworld" terms, we prefer to put it in perspective and combat some of the media hype, which is heavy on brands and buzzwords (a lot talks about "AI").

If remote exploitation is very unlikely, and if the local users are trusted (or have physical access to the system), what is the complete risk model?

If someone trusted ends up putting bad/malicious files on the system (and it is not possible to run them without root), either maliciously or ignorantly, then the true damage is contained. In our case, we need not worry about the upstream doing so because we don't use Microsoft NPM or something like that; that's because the system is managed via Debian repos and we don't use some bloated CMS crapwares (they often rely on PHP crapware or user-side uploaders for various users, which we lack; that's how malicious files often get planted/placed onto systems).

"I have not been able to cut through the hype to find the nature of that particular patch," an associate said.

For nearly a week now people wait to find out what this was all about. Uncertainly contributed to the panic.

Weeks ago Anthropic (evil company that coerces institutions into doing marketing for it) said a model was too dangerous to release. Then it leaked. And nothing happened.

The same goes for this latest bug, which has a brand and a logo (Tux, the Linux mascot having just turned 30, holding a grenade).

Did this live up to the hype? It relates to kernel subsystems like VPN (which not many people use at all) and for most people, with typical use cases, this does not pose a risk. They don't have "evil maid" accounts and they use only simple software. Their VPN - if any - does not live in the kernel or hijacks the network stack.

Since a lot of today's news sites are weak on research and some became slopfarms (just parroting those poorly-researched utterances about "Linux") we are meant to assume this is no better and no worse than Microsoft intentionally putting back doors in everything, even encryption. █

Other Recent Techrights' Posts

SLAPP Censorship - Part 199 Out of 200: An American Burden on the British Legal System
A year ago (October 2025) the head of media (Jointly in Charge of the Media and Communications List), the judge in the Garrett case, said that this case was a waste of the court's money
Criminalising Opposition to Fraud
slop causes social issues
 
US Government Sites Can Now Totally Ignore Mozilla Firefox Users or Users of Firefox Derivatives
Firefox, now at 1.1% in the US (based on American government sites), has sunken to the point of no return
Things Not to Measure in Quantity Alone
More patents do not beget greater innovation
Even Microsoft Boosters Start to Doubt XBox Will Exist (It's Being Phased Out, Just Not "Officially")
This is how to phase out a business unit without officially saying so (as it might alarm investors)
Omarchy is Built on the Idea That Slop is Desirable (It's Not)
They call bots and plagiarism "agents" and "training"
IBM is Shrinking Very Fast (Silent, Unannounced Layoffs)
IBM and Microsoft both avoid WARN notices by compelling staff to leave or silently removing them with some NDA
In Some Parts of Microsoft 50% of All Staff Subjected to Layoffs, Media Pretends Only 0.1% of Staff Are Removed
This really says a lot about the state of today's so-called 'media'
EPO Management Wants Everything to be Done in Microsoft Spyware
In reality, this management should be ousted for normalising cocaine at the Office
The Register MS Does Not Properly Flag Its SPAM About Slop
Signs of desperation
Gemini Links 25/09/2026: Ljubljana, Tanana River, and Curse of Slack
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 24, 2026
IRC logs for Thursday, September 24, 2026
Supporters of winding-up process staking claims against Reform UK Party (CR-2026-007405)
Reprinted with permission from Daniel Pocock
Winding-up petition leaked before service on Reform UK Party Limited / Nigel Farage
Reprinted with permission from Daniel Pocock
Gemini Links 24/09/2026: Laziness, Outdoor Seating, "AngelNova’s Interview Malware and Its North Korea Connection"
Links for the day
Links 24/09/2026: Slop "Linked to Disturbing Culture of Sexual Assault"; "Zelensky Warns Russia’s War Will Expand if It Is Not Ended Soon"
Links for the day
Winding-up petition served on Reform UK Party Limited (Nigel Farage)
Reprinted with permission from Daniel Pocock
Appliances Should be Dumb
Any "Smart Home Appliance" is basically a thing that does not last long, does not work as advertised, and is generally unfit for purpose
SLAPP Censorship - Part 198 Out of 200: It Sounds Like Garrett is Now Sending People to Silence Critics (Including His Own Spouse)
This week Garrett is having a somewhat karmic experience
Links 24/09/2026: Slop Contaminating KDE, Slop-Focused Data Centres Have Severe Environmental Impact
Links for the day
SLAPP Censorship - Part 197 Out of 200: Garrett Became So Poor That He Wants Others (in Another Continent) to Pay for His Own Legal Work Being Faulty
They lie to courts
The Register MS Has Become a Slopfest
This is the behaviour of a perishing publisher
Gemini Links 24/09/2026: Requiem for a Season, Philosophy, Rube-Goldberg Machine, ROOPHLOCH 2026, and Git over Gemini
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 23, 2026
IRC logs for Wednesday, September 23, 2026
IBM Grapevine: Development Outsourced to LLM Slop and It Results in Many Bugs
IBM is circling down the drain and every insider knows it
Microsoft Gives Many People the 'Booty' This Week, Not Counting PIPs (Silent Layoffs and 'Voluntary' Layoffs)
Microsoft PIPs allegedly target "20-25% in some teams."
Nearly 1,000 People at EPO 'Met' to Plan Further Strikes and Impending Action to Dethrone Corrupt Leadership
Exploring the purchasing "power" of EPO leadership (buying elections while doing cocaine in public)
Links 23/09/2026: Pax Silica Hub Ruins a Country for a Pyramid Scheme (Slop), Convicted Felon's Press Block Resembles Iran, Russia, China
Links for the day
Gemini Links 23/09/2026: Stuck, Gambling, Fury Road, IPFS, and More
Links for the day
The Register Got Paid Today to Spew Out "AI" Almost 50 Times (Keeping the Pyramid Scheme Buzzing in Headlines)
paid-for spam
SLAPP Censorship - Part 196 Out of 200: Sending Someone to Our Doorstep to Ship Approximately 5 KG of Legal Papers (Instead of to Our Representatives)
it is not about law, this is lawfare
IBM's Anderon Already Smells Like a Fraud and IBM Insiders Heckle the Lies From the Management
Sabine Hossenfelder recently made some videos which explain in simple terms why IBM is lying and has already lied about this for years
Links 23/09/2026: Mass-Surveillance by Clownflare and "Data Centre" Crunch Commences
Links for the day
Same Name/Brand, Not the Same Project/Product
What is Linux becoming?
Germany, Like Switzerland, Will Dump Microsoft's Proprietary Software and Disservices, Then Dump Windows for GNU/Linux
This impacts not only the Windows revenue; this corrodes any "rents" Microsoft was getting from "subscriptions"
3 Years Divorced From Americans
Next year we plan to pursue the UK's Court of Appeal
The Register MS Uses Slop About Slop (in Images)
Months ago we caught The Register MS using slop for text as well
There Are Likely Over a Thousand Internet Relay Chat (IRC) Networks Online, Net Gain of 16 Seen This Month by Andreas Gelhausen's netsplit.de
It's good that they're still tracking that sort of stuff
SLAPP Censorship - Part 195 Out of 200: Two Years Since Garrett, Graveley and Lozza Worked in Parallel to Censor Techrights
It began in September 2024, shortly after we had sued Garrett
Linux Kernel Becoming a Slopfest - Part 8 - In Conclusion
this can invite more SCO-like problems in the future
Microsoft Shuts Down More Studios, Morale Low, More Mass Layoffs Ahead of Reports
They pretend it's not happening or that it's a lot smaller than it actually is
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 22, 2026
IRC logs for Tuesday, September 22, 2026
Gemini Links 23/09/2026: Ljubljana, Poetry, and FORTRAN
Links for the day