frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)

https://ze3tar.github.io/post-zcrx.html
42•MrBruh•1h ago

Comments

rvz•1h ago
Another one.

Linux is falling apart faster than it can assign these CVEs.

EGreg•53m ago
How's BSD doing? How about Amazon Linux?
cachius•48m ago
And Windows?
mschuster91•16m ago
Pray to God no one ever lets an AI agent run loose on the various leaked Windows source code dumps.

Given Windows' absurd amount of backwards compatibility, chances are pretty high that there are a lot of sleeping dragons buried inside even modern Windows 10/11 kernel and userland that date back to code and issues from the 90s - code where half the people who have worked on it probably not just have departed Microsoft but departed living in the meantime.

yjftsjthsd-h•11m ago
Amazon Linux is a Linux distro? Though, yes, I would like to know how the BSDs are doing.
otterley•8m ago
Yes, it's a fork of Fedora. https://docs.aws.amazon.com/linux/al2023/ug/what-is-amazon-l...
toast0•11m ago
FreeBSD is getting piles of security updates lately too. Not sure about the other BSDs.
maven29•47m ago
perhaps this will lead to better AppArmor and SELinux defaults?
ChocolateGod•45m ago
People will just turn SELinux off rather than have to go through the horrible tooling when it breaks a regular use case.
yjftsjthsd-h•9m ago
I do think SELinux is a good example of how robust software with poor UX/DX gets undermined by that poor UX/DX. Although I do wonder if AI can help with it?
hn92726819•38m ago
Falling apart? You mean getting stronger? Every single one of these is an existing hole being patched. It isn't making new holes
gordonhart•38m ago
Linux is "falling apart" because it's the highest-profile open source project people can point LLM agents at to find CVEs. It'll come out the other end of this hardened by all of the attention it's getting, but the next few months/years will be... bumpy.
staticassertion•1h ago
io-uring is a security nightmare. Constant privescs and a powerful primitive for syscall smuggling. Worth considering disabling it outright (already the case for most containers afaik).
otterley•9m ago
At one point, Google disabled io_uring in its production servers (https://security.googleblog.com/2023/06/learnings-from-kctf-...) - I don't know whether this is still true, though. Perhaps a Google can confirm.
rishabhaiover•51m ago
What is happening? I see multiple outages and CVEs is being reported on HN's front page. I've never seen these many security/incident related posts on HN's front page.
majorchord•49m ago
AI is happening.
cachius•48m ago
In each recent case?
gordonhart•39m ago
AI assistance was explicitly disclosed on yesterday's. Today's has Claude as one of two contributors on this GitHub Pages site at least so it's also very likely.

Agents are capable of finding this kind of stuff now and people are having a field day using them to find high-profile CVEs for fun or profit.

spindump8930•48m ago
Some combination of reporting bias given concerns about LLM security capabilities and actual new vulnerabilities found with LLM assistance. Even if exploits and outages are unrelated to LLMs, I'm certainly thinking about whether claude could build these things (or if actors already have).
gilrain•48m ago
Automated vulnerability discovery via LLM.
john_strinlai•39m ago
i believe a good portion of the cves hitting the front page are moreso because they are ai-related (found partially/in whole by ai) and make for quick upvotes.
NitpickLawyer•35m ago
> What is happening?

Slowly at first, and then suddenly. AI assisted anything follows this trend. As capabilities improve, new avenues become "good enough" to automate. Today is security.

baq•47m ago
What’s our prior for p(doom) today…?
FriedFishes•47m ago
I can't quite make out if this is new or not. The attack vector here seems congruent with a similar exploit from a couple months ago [1]

But still might be an open threat. On the email thread Jens seems to think that this is already patched and in stable, he also points out that for this exploit to work (as written in the article) you already need escalated privileges [2] Catchy title though.

[1] https://snailsploit.com/security-research/general/io-uring-z... [2] https://seclists.org/oss-sec/2026/q2/448

kro•38m ago
CAP_NET/SYS_ADMIN is required for this. So this would be "not as bad" as the others.
stonegray•30m ago
> “and is writable with CAP_SYS_ADMIN”

Am I reading this wrong or is this just a way of executing an arbitrary binary with uid=0 if you have both CAP_NET_ADMIN and CAP_SYS_ADMIN?

If you can write modprobe_path, is it really news that you can find a way to execute code?

pizzalife•13m ago
Right. `CAP_SYS_ADMIN` is for all intents and purposes equivalent to root.

Google Cloud Fraud Defence is just WEI repackaged

https://privatecaptcha.com/blog/google-cloud-fraud-defence-wei/
614•ribtoks•7h ago•297 comments

Discord Incident

https://discordstatus.com
69•moelf•1h ago•31 comments

AI is breaking two vulnerability cultures

https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures
115•speckx•3h ago•55 comments

Man Finds $1M Worth of Yu-Gi-Oh Cards in a Dumpster

https://www.404media.co/man-finds-1-million-worth-of-yu-gi-oh-cards-in-a-dumpster/
49•danso•2d ago•7 comments

Cartoon Network Flash Games

https://www.webdesignmuseum.org/flash-game-exhibitions/cartoon-network-flash-games
213•willmeyers•4h ago•68 comments

You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)

https://ze3tar.github.io/post-zcrx.html
43•MrBruh•1h ago•27 comments

Mux (YC W16) Is Hiring

https://www.mux.com/jobs
1•mmcclure•21m ago

Serving a website on a Raspberry Pi Zero running in RAM

https://btxx.org/posts/memory/
169•xngbuilds•6h ago•69 comments

My first in-prod corrupted hard drive problem

https://blog.pavementlink.ch/2026/05/07/my-first-corrupted-hard-drive-problem/
24•r1chk1t•1h ago•16 comments

An Introduction to Meshtastic

https://meshtastic.org/docs/introduction/
329•ColinWright•10h ago•130 comments

David Attenborough's 100th Birthday

https://www.bbc.com/news/articles/cp3pww9g0p5o
271•defrost•9h ago•40 comments

Looking at the data behind prediction markets

https://asteriskmag.com/issues/14/are-prediction-markets-good-for-anything
7•kqr•1d ago•1 comments

Roadside Attraction

https://theoffingmag.com/essay/roadside-attraction/
10•aways•1h ago•1 comments

Google Broke reCAPTCHA for De-Googled Android Users

https://reclaimthenet.org/google-broke-recaptcha-for-de-googled-android-users
124•anonymousiam•2h ago•36 comments

A web page that shows you everything the browser told it without asking

https://sinceyouarrived.world/taken
485•mwheelz•8h ago•237 comments

PC Engine CPU

https://jsgroth.dev/blog/posts/pc-engine-cpu/
106•ibobev•7h ago•45 comments

Rumors of my death are slightly exaggerated

1333•CliffStoll•2d ago•212 comments

Cloudflare to cut about 20% of its workforce

https://www.reuters.com/business/world-at-work/cloudflare-cut-over-1100-jobs-2026-05-07/
1255•PriorityLeft•1d ago•889 comments

Mojo 1.0 Beta

https://mojolang.org/
233•sbt567•18h ago•158 comments

Show HN: GETadb.com – every GET request creates a DB

https://www.getadb.com/
16•nezaj•5h ago•12 comments

Apple, Intel have reached preliminary chip-making deal

https://www.reuters.com/business/apple-intel-have-reached-preliminary-chip-making-deal-wsj-report...
157•scrlk•3h ago•99 comments

Poland is now among the 20 largest economies

https://apnews.com/article/poland-economy-growth-g20-gdp-26fe06e120398410f8d773ba5661e7aa
817•surprisetalk•8h ago•692 comments

How do I deal with memory leaks? (2022)

https://www.stroustrup.com/bs_faq2.html#memory-leaks
68•theanonymousone•4h ago•48 comments

Canvas online again as ShinyHunters threatens to leak schools’ data

https://www.theverge.com/tech/926458/canvas-shinyhunters-breach
890•stefanpie•23h ago•592 comments

US Government releases first batch of UAP documents and videos

https://www.war.gov/UFO/
182•david-gpu•9h ago•286 comments

Maybe you shouldn't install new software for a bit

https://xeiaso.net/blog/2026/abstain-from-install/
799•psxuaw•22h ago•423 comments

Podman rootless containers and the Copy Fail exploit

https://garrido.io/notes/podman-rootless-containers-copy-fail/
105•ggpsv•8h ago•20 comments

Show HN: Git for AI Agents

https://github.com/regent-vcs/re_gent
81•doshay•7h ago•43 comments

Ask HN: We just had an actual UUID v4 collision...

240•mittermayr•13h ago•217 comments

Dirtyfrag: Universal Linux LPE

https://www.openwall.com/lists/oss-security/2026/05/07/8
783•flipped•1d ago•310 comments