Damus
GrapheneOS · 6w
The site for Copy Fail says it impacts every mainstream Linux distribution but that's not really the case. Mainstream mobile Linux is based on AOSP and doesn't have nearly as much kernel attack surfac...
GrapheneOS profile picture
We'll be moving this kind of content to our forum soon where we can write more about it and use proper formatting including headers and relevant inline images. We haven't moved to the new approach yet but we've also published this thread on our forum too:

https://discuss.grapheneos.org/d/35110-grapheneos-is-protected-against-copy-fail-and-similar-vulnerabilities-by-selinux
2
Tom · 6w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqtva8g98fx0fks0pt38vr75tv02t30qd5ev7n5v7fcpl6t44hf7kqzp8d0p Will you post links to those forum announcements here? I don't see a way to subscribe to the announcements forum, and I can't find an RSS/Atom feed for it.
GrapheneOS · 6w
AOSP also doesn't permit setuid or setgid binaries which was the chosen attack vector for exploiting it in the proof of concept exploit. It similarly doesn't permit io_uring, user namespaces and a lot of other functionality outside of a few core processes for security reasons.