<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linux on GMO Flatt Security Research</title>
    <link>https://flatt.tech/research/tags/linux/</link>
    <description>Recent content in Linux on GMO Flatt Security Research</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 21 Jun 2021 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://flatt.tech/research/tags/linux/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2020–15702 Race Condition vulnerability in handling of PID by apport</title>
      <link>https://flatt.tech/research/posts/race-condition-vulnerability-in-handling-of-pid-by-apport/</link>
      <pubDate>Mon, 21 Jun 2021 00:00:00 +0000</pubDate>
      <guid>https://flatt.tech/research/posts/race-condition-vulnerability-in-handling-of-pid-by-apport/</guid>
      <description>&lt;p&gt;Note) It’s just an English version of &lt;a href=&#34;https://flattsecurity.hatenablog.com/entry/2020/09/15/190029&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;previous post&lt;/a&gt;&#xA;.&lt;/p&gt;&#xA;&lt;p&gt;Hello, I’m Shiga( &lt;a href=&#34;https://twitter.com/Ga_ryo_&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;@Ga_ryo_&lt;/a&gt;&#xA; ), a security engineer at Flatt Security Inc.&lt;/p&gt;&#xA;&lt;p&gt;In this article, I would like to give you a technical description of &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2020-15702&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CVE-2020–15702&lt;/a&gt;&#xA; which is published recently. I discovered this vulnerability and reported it to the vendor via the &lt;a href=&#34;https://www.zerodayinitiative.com/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Zero Day Initiative&lt;/a&gt;&#xA;. This article is not intended to inform you of the dangers of vulnerabilities, but to share tips from a technical point of view.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring</title>
      <link>https://flatt.tech/research/posts/a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring/</link>
      <pubDate>Mon, 21 Jun 2021 00:00:00 +0000</pubDate>
      <guid>https://flatt.tech/research/posts/a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring/</guid>
      <description>&lt;p&gt;Hello, I’m Shiga( &lt;a href=&#34;https://twitter.com/Ga_ryo_&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;@Ga_ryo_&lt;/a&gt;&#xA; ), a security engineer at Flatt Security Inc.&lt;/p&gt;&#xA;&lt;p&gt;In this article, I would like to give you a technical description of CVE-2021–20226( &lt;a href=&#34;https://www.zerodayinitiative.com/advisories/ZDI-21-001/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;ZDI-2021–001&lt;/a&gt;&#xA; ) which is published before. I discovered this vulnerability and reported it to the vendor via the Zero Day Initiative. This article is not intended to inform you of the dangers of vulnerabilities, but to share tips from a technical point of view.&lt;/p&gt;&#xA;&lt;p&gt;An overview of the vulnerabilities and attack methods can be found at the links below. This blog will explain in a little more detail.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
