Day[0] cover image

[binary] TOCTOUs in Intel SMM and Shannon Baseband Bugs

Day[0]

00:00

The Lag in Kernel Security

A GitHub security lab put out three vulnerabilities in MIT's Kerberos V5 library all of which were out of bounds read issues and occurred when parsing and verifying sp-negotokens. The first vulnerability is like the most simple one of them they're all pretty simple. Triggering this condition is somewhat easy as well in order to trigger the failure case you just need to have a zero sized OID or multiple of them in their case in the set. Yeah I don't remember if I said this on the podcast but it feels like these secure elements or whatever are kind of in the same security space as kernels were like 10 or 15 years ago. It's like there's like a

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app