Sequoia: A Local Privilege Escalation Vulnerability in Linux's Filesystem Layer - . Wheel - PSW #707 episode artwork

EPISODE · Aug 20, 2021 · 45 MIN

Sequoia: A Local Privilege Escalation Vulnerability in Linux's Filesystem Layer - . Wheel - PSW #707

from Paul's Security Weekly (Video)

The Qualys Research Team discovered a size_t-to-int type conversion vulnerability in the Linux Kernel's filesystem layer affecting most Linux operating systems. Any unprivileged user can gain root privileges on a vulnerable host by exploiting this vulnerability in a default configuration. Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host. Qualys security researchers have been able to independently verify the vulnerability, develop an exploit, and obtain full root privileges on default installations of Ubuntu 20.04, Ubuntu 20.10, Ubuntu 21.04, Debian 11, and Fedora 34 Workstation. Other Linux distributions are likely vulnerable and probably exploitable. Segment Resources: https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909   Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw707

NOW PLAYING

Sequoia: A Local Privilege Escalation Vulnerability in Linux's Filesystem Layer - . Wheel - PSW #707

0:00 45:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Paul's Security Weekly (Video)?

This episode is 45 minutes long.

When was this Paul's Security Weekly (Video) episode published?

This episode was published on August 20, 2021.

What is this episode about?

The Qualys Research Team discovered a size_t-to-int type conversion vulnerability in the Linux Kernel's filesystem layer affecting most Linux operating systems. Any unprivileged user can gain root privileges on a vulnerable host by exploiting this...

Can I download this Paul's Security Weekly (Video) episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!