漏洞描述翻译: 包含用于 LXC 的持续集成和镜像构建脚本。在 2026-05-28 发布的 Arch Linux 镜像之前,基于 构建的镜像保留了相同的 本地签名私钥(位于 ),并将其分发到从该镜像创建的每个容器或虚拟机中。如果攻击者控制了 HTTP 软件包镜像源,或者能够拦截镜像流量,他们可以利用这个共享的 签名私钥对修改后的软件包进行签名,使受影响的客户端将其视为可信软件包。安装这些软件包将导致在客户端系统上以 root 权限执行任意代码。此问题已在 2026-05-28 或之后发布的 Arch Linux
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet