Bonum Certa Men Certa

The Slop-Amplified Fear of Privilege Escalation (Local, Not Remote) in Linux, the Kernel

posted by Roy Schestowitz on May 12, 2026

Don't panic over new Linux exploits: How to check if your PC is affected in under 5 minutes

This article will not belittle security, but it will put things in some much-needed perspective.

Lately there were a couple of bugs found (one prematurely talked about due to carelessness and lack of coordination with self-serving opportunists who profit from a sense of risk) in Linux - the kernel, proper, but not 'core' parts - and both of them got branded, which in the more distant past (pre-IBM) Red Hat complained about. It asserted that logos and catchy names meant lots of media hype would follow, irrespective of the real severity or objective underlying risk/s. One of the brands can cover two separate bugs (but interconnected). To quote one site: "Dirty Frag is a vulnerability chain combining two page-cache write primitives in the Linux kernel: one in the xfrm-ESP (IPsec) subsystem..." (link omitted due to sensationalism)

I used IPsec for a number of years but have not had it installed for over half a decade. As noted in IRC earlier today, there is more impact for some than for others. In many use cases (for servers, desktops, gadgets), this is not relevant. A week ago it already 'leaked' that AFS was impacted and "AFS had a lot of file ACL commands to let any user create an AFS ACL and put 4 group project members in..."

How many people still use AFS and how easy is it to access AFS-linked code?

Quoting the Linux Mint forums: "I guess I'm just wondering *exactly* how vulnerable the normal user is to this exploit? Not saying it's not important, but what is the probability that a single user workstation can be affected by this? The mitigation is fairly simple, so that's a relief."

So now there is a patch and there will be many more patches anyway. Many more. Linux gets patched all the time. How many people should be frantic about it and reboot ASAP? As someone in the forums put it: "Also, please note, to be affected by this vulnerability, you need a malicious local user capable to access your computer. That quite a theoretical possibility for most of us."

We are not downplaying those bugs, but we feel like one of them (the first) was creating lots of hype because it was allegedly a slop-attributed one (allegedly; we cannot know for sure and it is not wise to guess); we were all along being privately practical about this and rebooted when the patch became available. To be clear, local privilege escalation bugs will never be a huge deal like authentication bypass over SSH.

The pair of bugs (above) are not as critical as the media wants us to believe. The first is not 10.0 (rating for severity), not even 9.0. It is probably OK to apply that and reboot, but on many systems it is not imperative. As I explained earlier today to a peer, it very unlikely that a new PM (Perl Module) in Debian will contain an exploit for this (which can moreover be potently planted, then subsequently leveraged). It's also unlikely that any of the local users on our systems will get all nasty (or that Rianne will decide to become root; which she can regardless). And so in "realworld" terms, we prefer to put it in perspective and combat some of the media hype, which is heavy on brands and buzzwords (a lot talks about "AI").

If remote exploitation is very unlikely, and if the local users are trusted (or have physical access to the system), what is the complete risk model?

If someone trusted ends up putting bad/malicious files on the system (and it is not possible to run them without root), either maliciously or ignorantly, then the true damage is contained. In our case, we need not worry about the upstream doing so because we don't use Microsoft NPM or something like that; that's because the system is managed via Debian repos and we don't use some bloated CMS crapwares (they often rely on PHP crapware or user-side uploaders for various users, which we lack; that's how malicious files often get planted/placed onto systems).

"I have not been able to cut through the hype to find the nature of that particular patch," an associate said.

For nearly a week now people wait to find out what this was all about. Uncertainly contributed to the panic.

Weeks ago Anthropic (evil company that coerces institutions into doing marketing for it) said a model was too dangerous to release. Then it leaked. And nothing happened.

The same goes for this latest bug, which has a brand and a logo (Tux, the Linux mascot having just turned 30, holding a grenade).

Did this live up to the hype? It relates to kernel subsystems like VPN (which not many people use at all) and for most people, with typical use cases, this does not pose a risk. They don't have "evil maid" accounts and they use only simple software. Their VPN - if any - does not live in the kernel or hijacks the network stack.

Since a lot of today's news sites are weak on research and some became slopfarms (just parroting those poorly-researched utterances about "Linux") we are meant to assume this is no better and no worse than Microsoft intentionally putting back doors in everything, even encryption.

Other Recent Techrights' Posts

European Patent Office (EPO) Series: London Calling...
EPO Vice-President in charge of the "Patent Granting Process" is likely to have been a pay-off for the support which the UK gave to Campinos in 2017
Faking Productivity With Slop and Wasting Money on Faking 'Productivity': A Microsoft Story
If the quality of everything at Microsoft goes down
Wikipedia - Like Some Free Software Projects Infiltrated and Bribed - Bans Its Own Founder
Over the years we've named (not shamed) some projects and organisations that got corrupted by money and ended up banning their own founders
The “Aktion T4” at the European Patent Office (EPO) Saves Money for the President's Own Purse
Call for parents of children with special needs
SLAPP Censorship - Part 116 Out of 200: 5 Years of Multiparty Lawfare Against Techrights, Funded by Americans and Also by Third Parties (Including Microsoft Salaries)
The public and our government will be informed in full
 
While Thousands at IBM Lose Their Jobs ("Silent Layoffs") IBM's CEO Goes Begging the Dictator for Bailouts, Based on Deliberate Lies About "Quantum"
Many who claim to be retiring are only in their 40s and 50s. They're too proud to publicly admit what IBM did to them.
IBM Sends Workers 'Packing', Sometimes With the "Low Performer" Label That Imperils Their Future
To many people out there, IBM correlates with deceit
Links 24/06/2026: Four-Day Workweeks, GM Cut 1,000 Workers at Its EV Plant, 21,000+ Oracle Layoffs
Links for the day
A Step in the Right Direction (EU) in the Fight Against LLM Slop From GAFAM (US)
We've already mentioned this in Daily Links, but let's discuss this a little further
SLAPP Censorship - Part 117 Out of 200: Libel Tourism or Defamation Forum-Shopping in the United Kingdom Condemned by the European Union (EU)
Last week we reminded readers that the EU had criticised UK defamation law
Demonstration Next Week at the European Patent Office (EPO), Administrative Council Seen as Complicit
Corruption in Europe hurts all of us
IBM is Now Hinged on False Accounting and False Promises
This is the legacy of the current CEO
"PARTNER CONTENT" or 'Content Farms' That Promote Slop and Misinformation (The Register MS)
The Register MS represents a big part of the problem we all face
Turn Off the Slop, It's Wasting Energy and Destroying the Planet (the Only Planet We Have)
Right now we see lots of headlines about energy shortages and drained-up reserves
Lessons From Almost 30 Years of Site-Building Activities
We still strive to become faster and lighter
Do Not Outsource (the Seductive Mirage)
Abandoning so-called 'conventional wisdom'
Media Complicit in IBM Fraud Meant to Prop Up the Share Price Based on Lies, Fabrications
Even IBM insiders are fuming at this
In Some Countries, Windows Has Lost Its Monopoly
Windows fell to an all-time low globally this month
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 23, 2026
IRC logs for Tuesday, June 23, 2026
Gemini Links 24/06/2026: Motivation, PostScript Printer, and Why Hyperscalers and the Smolnet are Compatible
Links for the day
The Media's "Satya Says" Syndrome Distracts From Grim Reality
how insiders see Microsoft slop
Oracle's Collapse Has Nothing to do With Slop, It's About Its Debt Exploding by Almost 50% in Just 12 Months
How are people meant to trust the media?
Now... a Word From Our Sponsor
Powerade
Links 23/06/2026: Microsoft Studio Closures and Journalism Subjected to Further Cuts
Links for the day
Gemini Links 23/06/2026: Gardens, Basketball, Blocking Hyperscaler, and New Commodore Phone
Links for the day
Links 23/06/2026: Apple Price Hikes and Technical Debt in Slop
Links for the day
After IBM's Shares Collapsed the CEO is Trying the "Quantum" Trick Again, Bolstered by a Demented Dictator in the White House
from what we can gather IBM's CEO is trying to get the US government to participate in the scam
Greece Ought to Curb the Threat of Social Control Media
its national discourse seems to be run by an American company called Facebook
State of the GNU/Linux Desktop (and Laptop)
The time to advocate GNU/Linux is now
The 'XBox Narrative' Distracts From Destructive Cuts Across the Whole of Microsoft
Microsoft is preparing to lay off a likely record-breaking number of people [...] this isn't just an XBox problem
SLAPP Censorship - Part 115 Out of 200: Spending the Next Decade Writing About SLAPPs and Trying to Fix the System
It's the same industry that got paid by corrupt EPO officials to try to cover up the corruption
Microsoft's Stock Fell Nearly $200, But the Real Problems Are Just About to Begin
if they dump slop, what will they tell shareholders?
The Cyber Show on Starmer and Software Freedom
The Cyber Show's Andy has just explained why our departing national leader wasn't all bad
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, June 22, 2026
IRC logs for Monday, June 22, 2026
Gemini Links 23/06/2026: Girlrotting, Homeworlds at BGA, Slop Ruins Sites
Links for the day
A Lifetime of Whistleblowing
Ellsberg did not have an easy life, but it was a rewarding life with a rich legacy focusing on justice
European Patent Office (EPO) Series: A Man With Many Missions...
Campinos – accompanied by Gilles Requena and Patrice Pellegrino
Links 22/06/2026: Ubisoft Co-founder Dies, Americans Have Turned Against Slop
Links for the day
Links 22/06/2026: "The Sycophancy Machine" and "Port 22 Open for 54 Days"
Links for the day
When People Who Make the Most Money Are the Best "Boot Lickers" (Sucking Up to Jeffrey Epstein's Circle and the Dictator)
Sucking up to rich people may pay off
The Aim is Not Fame
Reposted from schestowitz.com
"Internally Important, Externally Irrelevant": IBM in a Nutshell
Right now its debt spins out of control and its stock spirals down the drain
SLAPP Censorship - Part 114 Out of 200: Thousands of Long Articles to Come, Properly Covering the SLAPP Industry in the UK and Its Modus Operandi
"Stowell described SLAPPs as ‘a stain on our legal system’."
Finding a Way to Get Paid to Improve LibreJS
So now we have more people resurrecting LibreJS and improving it
Microsoft Can't Even Wait Until July, Shutdowns and Layoffs Already Happening
Mashable speak of "a grim picture for the state of Xbox."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 21, 2026
IRC logs for Sunday, June 21, 2026
Gemini Links 22/06/2026: Appreciating Simple Things, Perfect Summer Evening, IRIX, Vim and so
Links for the day