← Back to context

Comment by IshKebab

5 hours ago

They're not dime a dozen exactly but LPE bugs in Linux (and common Linux distros) are easily common enough that nobody sane relies on user isolation as a serious security boundary.

Clouds use VMs as the security barrier, which is also not always 100% perfect, but is much better.

It could be useful as part of an exploit chain but generally once you've got to local code execution it's not going to be difficult to get further.

A "special" bug would be something that defeats a security barrier that people actually use, e.g. something that works remotely, or as you say - a hypervisor hack.