frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
22•ggpsv•1h ago

Comments

raesene9•1h ago
This is kind of an odd article to me. The point that podman may provide better isolation that Docker is made, but copy fail part focuses on the sample exploit (that overwrote su) which is not super applicable to containerised environments, and not the general effect of exploiting the vulnerability, which is to allow the user to overwrite a file that they should only have read-only access to.

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kuber... - This PoC has a good example of how Copy Fail might have an impact in a container based environment, it's exploiting the shared layers in a pair of container images, to overwrite a file in one image based on the running of an exploit in another.

Whilst I've not directly tested podman for that kind of attack, I'd be a bit surprised if it stopped it, given how this vuln works.

freedomben•25m ago
Thanks for the link. I tried the copyfail PoC in rootless podman yesterday and it didn't work, but I hadn't dug into it yet. This is great info.
raesene9•17m ago
I've had claude knock up a basic podman PoC, that seems to work ok https://github.com/raesene/vuln_pocs/tree/main/CVE-2026-3143... . It just uses a read-only mount and then demonstrates overwriting that read-only file.

Key point for testing exploitability is kernel version, package versions (in case they ship a patch) and loaded kernel modules. Some stripped down environments don't have the relevant modules available.

Poland is now among the 20 largest economies. How it happened

https://apnews.com/article/poland-economy-growth-g20-gdp-26fe06e120398410f8d773ba5661e7aa
444•surprisetalk•2h ago•362 comments

An Introduction to Meshtastic

https://meshtastic.org/docs/introduction/
148•ColinWright•3h ago•57 comments

PC Engine CPU

https://jsgroth.dev/blog/posts/pc-engine-cpu/
24•ibobev•1h ago•2 comments

Cloudflare to cut about 20% workforce

https://www.reuters.com/business/world-at-work/cloudflare-cut-over-1100-jobs-2026-05-07/
1060•PriorityLeft•18h ago•718 comments

Canvas is down as ShinyHunters threatens to leak schools’ data

https://www.theverge.com/tech/926458/canvas-shinyhunters-breach
831•stefanpie•16h ago•546 comments

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
23•ggpsv•1h ago•3 comments

GeoJSON

https://geojson.org/
80•tosh•5h ago•36 comments

Maybe you shouldn't install new software for a bit

https://xeiaso.net/blog/2026/abstain-from-install/
698•psxuaw•16h ago•373 comments

A web page that shows you everything the browser told it without asking

https://sinceyouarrived.world/taken
32•mwheelz•2h ago•19 comments

ClojureScript Gets Async/Await

https://clojurescript.org/news/2026-05-07-release
196•Borkdude•8h ago•45 comments

Tesla is recalling its cheaper Cybertruck because the wheels might fall off

https://www.theverge.com/transportation/926741/tesla-cybertruck-cheaper-recall
86•droidjj•1h ago•69 comments

Rumors of my death are slightly exaggerated

691•CliffStoll•1d ago•95 comments

Dirtyfrag: Universal Linux LPE

https://www.openwall.com/lists/oss-security/2026/05/07/8
726•flipped•19h ago•300 comments

Dithering with CSS

https://ikesau.co/blog/dithering-with-css/
80•speckx•3d ago•22 comments

The map that keeps Burning Man honest

https://www.not-ship.com/burning-man-moop/
702•speckx•1d ago•332 comments

Show HN: Git for AI Agents

https://github.com/regent-vcs/re_gent
5•doshay•1h ago•0 comments

Pinocchio is weirder than you remembered

https://storica.club/blog/pinocchio-in-italian/
233•cemsakarya•2d ago•97 comments

Hackers breach JDownloader's website to serve malware-laced downloads

https://www.neowin.net/news/if-you-downloaded-this-popular-software-recently-you-might-have-insta...
61•bundie•2h ago•19 comments

Agents need control flow, not more prompts

https://bsuh.bearblog.dev/agents-need-control-flow/
535•bsuh•22h ago•263 comments

QBE – Compiler Back End

https://c9x.me/compile/
43•smartmic•8h ago•5 comments

Nintendo announces price increases for Nintendo Switch 2

https://www.nintendo.co.jp/corporate/release/en/2026/260508.html
190•razorbeamz•8h ago•167 comments

A polynomial autoencoder beats PCA on transformer embeddings

https://ivanpleshkov.dev/blog/polynomial-autoencoder/
75•timvisee•3d ago•18 comments

GPT-5.5 Price Increase: What It Costs

https://openrouter.ai/announcements/gpt55-cost-analysis
138•gmays•14h ago•31 comments

Brazil's Pix payment system faces pressure from Visa and Mastercard

https://www.elciudadano.com/en/brazils-pix-payment-system-faces-pressure-from-visa-and-mastercard...
314•wslh•21h ago•259 comments

Singapore introduces caning for boys who bully others at school

https://www.theguardian.com/world/2026/may/06/singapore-caning-school-bullies
270•rustoo•2d ago•396 comments

DeepSeek 4 Flash local inference engine for Metal

https://github.com/antirez/ds4
450•tamnd•23h ago•129 comments

Four stable kernels with partial fixes for Dirty Frag

https://lwn.net/Articles/1071775/
10•Brajeshwar•59m ago•0 comments

Hardening Firefox with Claude Mythos Preview

https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
289•HieronymusBosch•23h ago•124 comments

Natural Language Autoencoders: Turning Claude's Thoughts into Text

https://www.anthropic.com/research/natural-language-autoencoders
336•instagraham•21h ago•101 comments

AlphaEvolve: Gemini-powered coding agent scaling impact across fields

https://deepmind.google/blog/alphaevolve-impact/
316•berlianta•1d ago•136 comments