this post was submitted on 02 Jun 2025
23 points (87.1% liked)

Cybersecurity

7420 readers
105 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 5 comments
sorted by: hot top controversial new old
[–] [email protected] 13 points 6 days ago (1 children)

@kid

Much ado about nothing.

An attacker needs at least physical access to the device. Wow, what a danger.

cf. "The 10 Immutable Laws Of Security"
"Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore."
https://uptakedigital.zendesk.com/hc/en-us/articles/115000412533-10-Immutable-Laws-Of-Security-Version-2-0

[–] [email protected] 1 points 5 days ago

It is an issue in a managed environment such as on corporation or school PCs.

[–] kid 9 points 6 days ago

The first vulnerability, CVE-2025-5054, affects Ubuntu’s Apport crash reporting system, while the second, CVE-2025-4598, impacts systemd-coredump, the default core dump handler used across Red Hat Enterprise Linux 9 and 10, as well as Fedora distributions.

[–] [email protected] 8 points 6 days ago

Skimming through the Qualsys report it seems that the attacker would already need access to the device first, to be able to crash the processes and then collect the hashes, so I'd say this vulnerability appears to need chaining with other(s)?

[–] [email protected] 3 points 6 days ago

They aren't critical.