-
On Tuesday April 18, 2023, Oracle Pre-Release April Critical Patch Update.
Preface: The blockchain technology can ensure the security and integrity of data. By combining AI and blockchain, it is possible to create more powerful systems. Background: When taking about Blockchain, we simply will think about ctyptocurrecy. As a matter of fact, Blockchain technology influenced far-reaching in the world of science and technology.Oracles provide a way…
-
CVE-2023-26083 – expose sensitive kernel metadata (16-04-2023)
Preface: The kernel doesn’t have libc or system calls if you’re not running in user mode. Background: Open Source Mali Midgard GPU Kernel Drivers – The Android and Linux version of the Mali GPUs Device Driver provide low-level access to the Mali-T6xx, Mali-T7xx and Mali-T8xx series GPUs.Under normal circumstances once kernel driver and user-space libraries…
-
CVE-2023-27267 : Issue of concern – April 11, 2023 SAP released the latest security patch date (14th Apr 2023)
Preface: According to the CVSS 3.1 standard, if the score reaches 9.0, it is considered high risk. I beleived that the design limitation of CVE-2023-27267 also concern by vendor. From a security point of view, how does an attacker trigger this design weakness? Let’s start a short journey based on speculation. See whether it give…
-
CVE-2023-0208 – update for NVIDIA® Data Center GPU Manager (DCGM) (13th Apr 2023)
Preface: The easter hoilday in 2nd week of April. So this news may have late. On 03/31/2023 03:00 PM, NVIDIA has released a software update for NVIDIA® Data Center GPU Manager (DCGM). The update addresses security issues that may lead to denial of service and data tampering.Be my guest, see wether you will be interested?…
-
About CVE-2023-28205 and CVE-2023-28206: Hunter, hunting apple design weakness (12th Apr 2023)
Preface: memcpy() function is is used to copy a specified number of bytes from one memory to another. memmove() function is used to copy a specified number of bytes from one memory to another or to overlap on same memory. Background: WebKit is the part of Apple’s browser engine that sits underneath absolutely all web…
-
About CVE-2023-27727 (11th April 2023)
Preface: In computing, a segmentation fault (often shortened to segfault) or access violation is a fault, or failure condition, raised by hardware with memory protection, notifying an operating system (OS) the software has attempted to access a restricted area of memory (a memory access violation). Background: NJS is a subset of the JavaScript language that…
-
About CVE-2023-0461 – When you take this way, you should be aware of it. (6th April 2023)
Preface: Combining kTLS and sendfile() means data is encrypted directly in kernel space, before being passed to the network stack for transmission. Background: improving web server on freebsd Linux performance with kernel tls (ktls).Kernel TLS operation – Linux kernel provides TLS connection offload infrastructure. Once a TCP connection is in ESTABLISHED state user space can…
-
Whether we can open the mask – About CVE-2023-21085 & CVE-2023-21096 (5th April 2023)
Preface: Vendor did not describe in details, see whether this is the vulnerability they found? Background: The Android Runtime (ART) and managed core library (libcore) were part of the Runtime module effort in Android 10 along with the native runtime (Bionic) and ICU.In Android 11, ART and libcore are packaged as non-updateable APEX. Bionic and…
-
New Design vs Old Style Attacks (5th April 2023)
Preface: On Dec 2022, Microsoft has warned that malicious hackers were able to get the software giant to digitally sign their code so it could be used in attacks, such as the deployment of ransomware. Background: The newest update to AMD’s P-State EPP Linux driver hit today, offering better Ryzen & EPYC performance & better…
-
About Kubernetes Hardening Guide (3rd Apr 2023)
Prefect: The Lord taught Enoch that those who build their lives upon the Savior would never fall.Don’t mind about it was really had Lord or advanced civilization, human being go to digitization. In bible it mention about Lucifer. It is similar to cyber threat actor. Background: Technology trends from on-premises to cloud. Cloud-based attack most…