Debian SE Linux and ssh-keysign-pwn (opens in new tab)
I just tested out the ssh-keysign-pwn exploit [1] on Debian kernel 6.12.74+deb13+1-amd64 which was released before these exploits. When sshkeysign_pwn is run as user_t the following is logged in the audit log and it fails to exploit anything: type=SYSCALL msg=audit(1778831599.951:22353257): arch=c000003e syscall=438 success=no exit=-1 a0=3 a1=c a2=0 a3=1b8020 items=0 ppid=5632 pid=6654 auid=1000 uid=1000 gid=1000 euid=1000 […]
Read the original article