Accueil
tag

Linux

Open Build Service, one year later: command execution through Mercurial argument injection
0day - Command execution - openSUSE OBS - CVE-2026-56004

Open Build Service, one year later: command execution through Mercurial argument injection

In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…

Maxime Rinaudo · 6 min de lecture
CVSS 10.0
Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service
0day - File read/write - openSUSE OBS - CVE-2024-22033

Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service

Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…

Maxime Rinaudo · 9 min de lecture
CVSS 6.3
Supply Chain Attacks on Linux distributions - Fedora Pagure
0day - RCE - Fedora Pagure - CVE-2024-47516

Supply Chain Attacks on Linux distributions - Fedora Pagure

As discussed in the meta-article, we picked Pagure from the Fedora Apps Directory and already had a technical approach in mind. A software forge is likely to be a good target for an argument injection: we can expect the…

Thomas Chauchefoin · 9 min de lecture
CVSS 9.8
Supply Chain Attacks on Linux distributions - Overview
Research - State of the Art

Supply Chain Attacks on Linux distributions - Overview

Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…

Maxime Rinaudo · 6 min de lecture