tags: #linux #expert #stay-safe
(This blogpost is not written in my usual style; it’s more of “get something out quick so I can send to my friends” thing)
TLDR:
attacks have been shown that (a) read ssh host keys and (b) read /etc/shadow
requires local user who can run arbitrary code
scenarios:
yescrypt for the
hashing
/etc/shadow entry should start with
$y$$y$ and change only those, then check to make sure)immediate steps to mitigate, if you think you are at risk:
(NOTE: Chrome’s sandboxing may be affected by this; I lack the motivation to follow up, because I use Chrome only to access Microsoft Teams, and even that very rarely).
cat /proc/sys/kernel/yama/ptrace_scope
# will likely show "1"
sysctl kernel.yama.ptrace_scope=2
# immediate fix
cat /proc/sys/kernel/yama/ptrace_scope
# should show 2
echo kernel.yama.ptrace_scope=2 > /etc/sysctl.d/ptrace-vuln.conf
# longer term fix
Source: https://www.openwall.com/lists/oss-security/2026/05/15/8