Why would you use XFS for those partitions in the first place? It’s not what it was designed for or used in real life and that’s likely reason this wasn’t discovered before. What I’m getting from a lot of those AI-assisted security findings is that they’re not concerned with a real vector of attack before making big claims in the media. You’ll probably be able to vandalise things with this exploit but „root privileges” is pushing it.
XFS is the default filesystem for RHE, and while I believe that /tmp is a tmpfs on RHE and should therefore be safe, it is my understanding that /var/tmp needs to be accessible on boot and is therefore typically on the root FS. EDIT: Can confirm for the RHE server I have access to, that this is the case
Can all be separate partitions on an Enterprise Linux system. Cisa guidelines recommend some and additional mount configs since they have different roles
Those can all be separate partitions on any Linux system. But defaults matter, and if the defaults are insecure then you can expect most systems to be insecure
Why would you use XFS for those partitions in the first place? It’s not what it was designed for or used in real life and that’s likely reason this wasn’t discovered before. What I’m getting from a lot of those AI-assisted security findings is that they’re not concerned with a real vector of attack before making big claims in the media. You’ll probably be able to vandalise things with this exploit but „root privileges” is pushing it.
XFS is the default filesystem for RHE, and while I believe that
/tmpis a tmpfs on RHE and should therefore be safe, it is my understanding that/var/tmpneeds to be accessible on boot and is therefore typically on the root FS. EDIT: Can confirm for the RHE server I have access to, that this is the caseI’m seriously behind times because I’m reading RHEL switched to XFS as a default in 2013 and SUSE did that even earlier :o
I don’t even need an LLM to be confidently wrong, sorry.
/Var /Var/logs /Var/tmp /Tmp / /Home /Boot
Can all be separate partitions on an Enterprise Linux system. Cisa guidelines recommend some and additional mount configs since they have different roles
Those can all be separate partitions on any Linux system. But defaults matter, and if the defaults are insecure then you can expect most systems to be insecure