No Image

USN-5339-1: Linux kernel vulnerabilities

2022-03-22 KENNETH 0

USN-5339-1: Linux kernel vulnerabilities Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) It was discovered that an out-of-bounds (OOB) memory access flaw existed in the f2fs module of the Linux kernel. A local attacker could use this issue to cause a denial of service (system crash). (CVE-2021-3506) Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver in the Linux kernel did not properly handle some error conditions. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-43976) It was discovered that the ARM Trusted Execution Environment (TEE) subsystem in the Linux kernel contained a race condition leading to a use- after-free vulnerability. A local attacker [ more… ]

No Image

USN-5338-1: Linux kernel vulnerabilities

2022-03-22 KENNETH 0

USN-5338-1: Linux kernel vulnerabilities Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Jürgen Groß discovered that the Xen subsystem within the Linux kernel did not adequately limit the number of events driver domains (unprivileged PV backends) could send to other guest VMs. An attacker in a driver domain could use this to cause a denial of service in other guest VMs. (CVE-2021-28711, CVE-2021-28712, CVE-2021-28713) Jürgen Groß discovered that the Xen network backend driver in the Linux kernel did not adequately limit the amount of queued packets when a guest did not process them. An attacker in a guest VM can use this to cause a denial of service (excessive kernel memory consumption) [ more… ]

No Image

USN-5337-1: Linux kernel vulnerabilities

2022-03-22 KENNETH 0

USN-5337-1: Linux kernel vulnerabilities It was discovered that the BPF verifier in the Linux kernel did not properly restrict pointer types in certain situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-23222) Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Jürgen Groß discovered that the Xen subsystem within the Linux kernel did not adequately limit the number of events driver domains (unprivileged PV backends) could send to other guest VMs. An attacker in a driver domain could use this to cause a denial of service in other guest VMs. (CVE-2021-28711, CVE-2021-28712, CVE-2021-28713) Jürgen Groß discovered that the Xen network backend [ more… ]

NGINX Tutorial: Protect Kubernetes APIs with Rate Limiting

2022-03-22 KENNETH 0

NGINX Tutorial: Protect Kubernetes APIs with Rate Limiting Note: This tutorial is part of Microservices March 2022: Kubernetes Networking. Reduce Kubernetes Latency with Autoscaling Protect Kubernetes APIs with Rate Limiting (this post) Protect Kubernetes Apps from SQL Injection (coming soon) Improve Uptime and Resilience with a Canary Deployment (coming soon) Your organization just launched its first app and API in Kubernetes. You’ve been told to expect high traffic volumes (and already implemented autoscaling to ensure NGINX Ingress Controller can quickly route the traffic), but there are concerns that the API may be targeted by a malicious attack. If the API receives a high volume of HTTP requests – a possibility with brute‑force password guessing or DDoS attacks – then both the API and app could be overwhelmed and might even crash. But you’re in luck! The traffic control technique “rate limiting” is [ more… ]

[도서] 나의 첫 로블록스 게임 프로그래밍

2022-03-22 KENNETH 0

[도서] 나의 첫 로블록스 게임 프로그래밍 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]나의 첫 로블록스 게임 프로그래밍 김경흥 저 | 비제이퍼블릭(BJ퍼블릭) | 2022년 03월 판매가 22,500원 (10%할인) | YES포인트 1,250원(5%지급) 누구보다 빠르게 메타버스를 체험하는 가장 쉬운 방법! 이 책과 함께 로블록스 게임의 세계에 빠져 볼까요? 수많은 게임 플랫폼 중에서도 로블록스는 특별하다. 다른 게임 제작 툴과 비교했을 때, 쉽고 편리하게 Source: [도서] 나의 첫 로블록스 게임 프로그래밍