GitHub - 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
Copy Fail 2: Electric Boogaloo. Contribute to 0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo development by creating an account on GitHub.
Good article, thanks!
thehackernews.com
as the embargo was broken early
The article said it was an unrelated third-party . . . which doesn't make any sense to me. How did this "unrelated third-party" get his (or her) hands on all the info concerning it?Somebody leaked it before it was fixed.
The article said it was an unrelated third-party . . . which doesn't make any sense to me. How did this "unrelated third-party" get his (or her) hands on all the info concerning it?
- 2026-05-07: Submitted detailed information about the vulnerability and the exploit to the linux-distros mailing list. The embargo was set to 5 days [emphasis mine], with an agreement that if a third party publishes the exploit on the internet during the embargo period, the Dirty Frag exploit would be published publicly.
The way in which the exploit has been exposed with less than optimal embargoing and a third-party release is unfortunate. One can hope I guess that responsible behaviour can prevail. The linux community does have a lot of resources to recover from these things, witness the xz issue some time ago. There's a long history of mitigations against vulnerabilities, some of which can be seen in the bottom section of theResponsible recording goes something like this:
lscpu command.In lscpu you only see hardware (CPU) vulnerabilities and mitigations.There's a long history of mitigations against vulnerabilities, some of which can be seen in the bottom section of thelscpucommand.
The way in which the exploit has been exposed with less than optimal embargoing and a third-party release is unfortunate. One can hope I guess that responsible behaviour can prevail.
with said dedicated server. Also, it's quite a lot of fun to manage a server. It's really just a hobby.
I have a home lab also, but unfortunately..
Is it already fixed in debian?