Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)
V4bel published an analysis of a race condition vulnerability in the TCP-AO subsystem caused by incorrect usage of the kernel RCU mechanism.
The researcher managed to trigger it reliably using the ExpRace technique.
Article: https://blog.theori.io/deep-dive-into-rcu-race-condition-analysis-of-tcp-ao-uaf-cve-2024-27394-f40508b84c42
ExpRace: https://www.usenix.org/conference/usenixsecurity21/presentation/lee-yoochan
Two years ago, Joe Biden said the COVID pandemic was over. Since then, 200,000 people have died from COVID. Many more are suffering from Long COVID.
Wear masks.
Tell the US Senate Judiciary Committee that you Object to the PREVAIL Bill TODAY!
PREVAIL will shield patent trolls from legitimate challenges to weak patents. It only takes a minute, you may use our template: https://hubs.la/Q02QLBL20
#sched_ext, which allows scheduling policies to be implemented as #BPF programs, has been merged for #Linux 6.12:
https://git.kernel.org/torvalds/c/88264981f2082248e892a706b2c5004650faac54
See https://lwn.net/Articles/922405/ for a description of what it does and https://lwn.net/Articles/972710/ for the controversy it caused that is the reason why it took so long to land in mainline.