Linux vulnerability – Nimbuspwn UPDATED 28 April 2022

This post was first made on 27 April 2022

Here is an article from Microsoft examining an issue with Linux, where user privileges can be elevated by stringing together a number of vulnerabilities.

Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn – Microsoft Security Blog

If you use Linux you had better check on this – I have checked my Linux server.

Update 28 April 2022

Here is another way of looking at the same issue.

Microsoft points out privilege-escalation flaws in Linux • The Register

I think the point this article is making, is not the one it is hoping to make. As the article states “when countless privilege-elevation holes are fixed in the Windows operating system each month“, as though this is a bad thing. It is not – it is a good thing, things are fixed and secured because Microsoft alone is responsible for it’s software. This, the open source nature of Linux has no chance of emulating – even though businesses such as Microsoft and Google are reliant on Linux machines.

Clive Catton MSc (Cyber Security) – by-line and other articles

Further Reading

Microsoft finds Linux desktop flaw that gives root to untrusted users | Ars Technica