Tailscale SSH 把 `-i` 當帳號就開出 root shell:TS-2026-009 讓 getent 的 --no-idn 攤開整份 passwd
TS-2026-009 揭露 Tailscale SSH 在 Linux 上把使用者名稱直接餵給 getent(1),用 `-i` 當帳號就會被解析成 --no...
4 篇文章
TS-2026-009 揭露 Tailscale SSH 在 Linux 上把使用者名稱直接餵給 getent(1),用 `-i` 當帳號就會被解析成 --no...
Gitea 官方 Docker 映像檔內建的 app.ini 把 REVERSE_PROXY_TRUSTED_PROXIES 寫死成萬用字元,只要管理員開啟 r...
GhostLock(CVE-2026-43499)是 rt_mutex 的 use-after-free,2011 年寫進 2.6.39、直到 Linux 7....
Linux kernel 的 algif_aead 有一條九年前寫下的 splice 優化路徑,讓非特權使用者能對 page cache 做出可控寫入。CVE-...