CodeRabbit's new Slack Agent lets you manage your team's agentic workflow right in Slack - https://coderabbit.link/fireship-agent A 100% reliable logic flaw was discovered in the Linux kernel and an AI tool wrote an exploit for it that affects every Linux machine updated since 2017. Let's look at the technical details behind the vulnerability and what to do if you're affected... #coding #programming #linux #python Want more Fireship? 🗞️ Newsletter: https://bytes.dev 🧠 Courses: https://fireship.dev
ADVERTISEMENT
I wish the title were true. For example no Android device is affected, while it would have actually been useful in order to finally gain back root access on OUR devices...
“My private equity, illuminati overseers” that was good, much respect
Thanks fireship. I did not understand this vuln in first place now I do not understand in 2nd place as well😢 Update: Thanks for so many likes🙏
You forgot to mention how those security researchers failed to notify the distro teams and just disclosed the exploit without waiting for the patches to roll out while coincidentally launching their slop security product on the same day.
I am sad this wasn't about Horse Tinder.
This is the year of FreeBSD desktop
It wasn't just that AI scan that found it. It was someone who gave them the attack surface, and they had the AI focus on that particular one thing.
Using “My private equity, illuminati overseers” as a joke is exactly what private equity, illuminati overseers would do to make people doubt of their existence.
TempleOS: remains unaffected because all of the hackers are too scared to walk by the incredibly scary guy foaming at the mouth to gain physical access 😭
Ubuntu tried to patch it and then 313 Team kicked them while they’re down
I appreciate Fireship adding the detail that the agent that found this wasn't just told to "find exploits". The researches had already found a potential issue in the splice function and gave the agent specific instructions on where to look for potential vulnerabilities. That's a more realistic use case for AI/LLM tech than most people realize.
"If I had a dime every time Fireship acknowledged that it's owned by private equity I would have 2 dimes which is not much but is odd it happened 2 times"
CIA: *slams desk*
3:43 this prompt is so specific. This should be composed by a real security engineer
2:43 Confirmed first sighting of the AI voice making a mistake saying AGL instead of ALG this is national news
2:43 "AGL" vs "ALG". Hmmm, maybe not AI afterall.
So basically they told AI the vulnerability and used it as a search tool
Can’t even imagine the amount of gapping security holes an AI could find on the latest Windows kernel if the source code were to leak.
Not every Linux distro was affected, Fedora and other distros close to upstream were already patched by the time the exploit was published.
Funny how claude mythos didnt already find this 🤔🤔