Hacker News new | ask | show | jobs
by 0x0 3341 days ago
It looks like this also affects systems where the feature is not enabled, but for "local" attackers. Does that mean exec as "www-data" or "nobody" accounts (what about VMs?). Making every little wordpress plugin vulnerability into a CPU-rooting hack?
1 comments

From what we can see so far, potentially more the latter than the former.