Jerry Bell is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Remember how systemd starting as root if the username starts with a digit isn't a bug? Turns out they're technically right. It's not a bug.

It's a bug worthy of a CVE. CVE-2017-1000082, which had to be requested by third parties. Like, I suspect, every systemd CVE ever.

nvd.nist.gov/vuln/detail/CVE-2

Jerry Bell @jerry

@jgoguen amazing. It almost seems like systemd is a directed effort to destabilize Linux