September 24th, 2024

Unauthenticated RCE vs. all GNU/Linux systems, CVSS 9.9

A critical security vulnerability with a severity score of 9.9 affects GNU/Linux systems, lacking a CVE and fix. Discussions continue, prompting Margaritelli to publish a detailed write-up on the issue.

Read original articleLink Icon
Unauthenticated RCE vs. all GNU/Linux systems, CVSS 9.9

A recent thread by Simone Margaritelli discusses a critical security vulnerability affecting various GNU/Linux systems, which has been under scrutiny for over three weeks. The vulnerability, classified with a severity score of 9.9, has not yet been assigned a CVE identifier, and no effective fix has been developed. Despite the ongoing discussions among developers regarding the security implications, Margaritelli expresses frustration over the lack of acknowledgment and responsiveness from the developers involved. He emphasizes the importance of responsible disclosure and criticizes the defensive attitudes of some developers who refuse to accept the flaws in their code. Margaritelli plans to publish a detailed write-up that will not only cover the technical aspects of the vulnerability but also serve as a case study on poor handling of security disclosures. He acknowledges the efforts of Canonical and others who have attempted to mediate the situation, while also highlighting the need for more accountability in software development.

- A critical vulnerability affecting GNU/Linux systems has been disclosed, with a severity score of 9.9.

- No CVE has been assigned, and there is currently no working fix for the vulnerability.

- Developers are debating the security impact of the issues, causing frustration for those reporting them.

- Margaritelli plans to publish a write-up detailing the vulnerability and the handling of its disclosure.

- The thread emphasizes the need for accountability and responsible practices in software development.

Link Icon 3 comments
By @udev4096 - 4 months
So far, the suggested hint is towards cups[0] which is a printing system for unix. I am not sure if it's even installed on all the distros by default

[0] - https://en.wikipedia.org/wiki/CUPS

By @imrejonk - 4 months
I wonder if this "all GNU/Linux systems" is correct, or if we'll see some nuance added in a couple of hours/days. I'd be a monstrous patch day if this RCE really impacts all GNU/Linux systems.