Skip to content

Upgrade onioncircuits to 0.8.2 to fix LPE to arbitrary code exec in its privileged network namespace

It fixes a case of the python3 -I bug that we missed when we meant to fix #20702 (closed). (I expected this to already be in Tails, but the latest stable build only has 0.8.1-2).

User impact

intrigeri expects the impact to be similar to #20709 (closed).

Practical exploitation path

Like #20702 (closed), this can be exploited by any attacker who can write to /home/amnesia/.local/lib/.

Edited by intrigeri
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information