The Pirate Post ha ricondiviso questo.

Weil ich schnell den Überblick verliere, wenn es um Ländergesetze geht, habe ich abgefragt, welche Länder absehbar ihr #PsychKG ändern wollen. Das Ergebnis: ziemlich viele und in einigen sind die Änderungen schon in Arbeit.

Mich interessiert vor allem, ob es potenziell neue Datenaustauschregeln gibt. Aber vielleicht ist die Übersicht auch für Leute spannend, die sich mit Zwang in der #Psychiatrie, #SpDI und anderem beschäftigen.

netzpolitik.org/2026/datenaust…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Il dettaglio italiano della votazione odierna sulla Proposta di rifiuto di Chat Control.

Dovremo ricordarci sempre di tutte le persone che ci rappresentano a favore di questa porcheria (quindi contrarie al rifiuto)

dariofadda.it/chat-control/202…

#stopchatcontrol

in reply to N_{Dario Fadda}

È online il progetto italiano di protesta civica digitale stopchatcontrol.it - documentazione ufficiale e percezione del pericolo per informare, informarsi come cittadino e votare consapevolmente quando servirà.

Seguiamo tutte le tappe perché l’attività non è terminata con queste proroga “ordinaria” c’è ancora tanto da combattere e la partita è ancora lunga anche per il ChatControl2.0.

Nella sezione Partecipa, ho messo a disposizione anche un forum per eventuali discussioni

The Pirate Post ha ricondiviso questo.

Eigentlich hat das EU-Parlament wiederholt die anlasslose Überwachung im Internet abgelehnt. Mit einem außergewöhnlichen Manöver gelang es der konservativen Parlamentspräsidentin Metsola, eine umstrittene Ausnahmeregelung dennoch durchzuboxen. netzpolitik.org/2026/eu-parlam…
The Pirate Post ha ricondiviso questo.

Le Parlement vient d'adopter définitivement le projet de loi « SURE ». Ce texte élargit le fichage et autorise la police à exploiter la généalogie génétique issus de tests ADN récréatifs. Relisez notre article sur le sujet pour en savoir plus : laquadrature.net/2026/05/20/pr…

reshared this

The Pirate Post ha ricondiviso questo.

Chat Control 1.0 has passed, a shameful affair, literally every scientist or expert can explain why this is a bad idea. The next step is clear , everybody should move to E2EE applications where possible. Also check if the provider uses opensource, is transparant.
#chatcontrol #eu #privacy

Il Parlamento europeo dà il via libera a Chat Control 1.0 – Breyer: “I nostri figli ne risentiranno”


Oggi il Parlamento europeo ha approvato la scansione di massa senza sospetto delle comunicazioni private (“Chat Control 1.0”), una misura che aveva respinto due volte a marzo. Sebbene la maggioranza dei deputati europei votanti si fosse effettivamente opposta al regolamento ( 314 contrari, 276 favorevoli, 17 astensioni ), la mozione di rigetto non ha ottenuto la maggioranza assoluta di 361 voti…

Source

reshared this

The Pirate Post ha ricondiviso questo.

#Alterskontrollen sind ja nur eine von 56 Empfehlungen der Expert*innen für digitalen Kinder- und Jugendschutz. Vieles geht um Hilfe vor Ort, und die ist teuer. Können die Kommunen mit den Empfehlungen etwas anfangen? Der Medienzirkus ist längst weitergezogen – ich habe mich umgehört.

netzpolitik.org/2026/junge-men…

The Pirate Post ha ricondiviso questo.

56 Empfehlungen haben Fachleute für Kinder- und Jugendschutz im Netz vorgelegt. Sie fordern ein Sofortprogramm. Die Kommunen loben die Ideen, aber fragen sich, wer das bezahlen soll. Das Familienministerium will noch nicht über Geld sprechen.

netzpolitik.org/2026/junge-men…

The Pirate Post ha ricondiviso questo.

In queste ore non stiamo vivendo un bel momento per i diritti civili, Internet e le libertà digitali.

Spero di sbagliarmi

#StopChatControl

The Pirate Post ha ricondiviso questo.

🇩🇪EU-Parlament lässt #Chatkontrolle 1.0 trotz Mehrheits‑Nein (314:276) passieren – Massenscans privater Chats bis 2028 erlaubt. Betroffene warnen. Meine Einordnung und warum das der falsche Weg ist 👇
patrick-breyer.de/eu-parlament…
#Demokratiefail
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

❗ Sul mio sito ho esposto una dashboard che evidenzia i risultati della votazione del 7 luglio 2026 in parlamento europeo sul tema #ChatControl.

Un tema che tocca profondamente le libertà digitali e distorce il senso di esistenza di Internet, per tante ragioni e nessuna di queste serve per combattere la pedo-pornografia.

Ecco come è andata per i partiti italiani sul tema Chat Control

Qui la dashboard completa:

dariofadda.it/chat-control/202…

#StopChatControl

in reply to alephoto85

@alephoto85 Perchè il sito fightchatcontrol.eu/ non fa una estrazione dei dati da ogni votazione, esprime solo l'intenzione del singolo.

Quest'analisi riprende invece i dati della votazione del 7 luglio e l'intenzione e di ripeterla anche per quella che avverrà oggi

Oblomov reshared this.

in reply to Oblomov

puoi vedere tutto sia sul sito di @nuke che sul sito fightchatcontrol.eu/ (qui trovi anche i dati degli altri paesi, non solo italianз).
Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

🇺🇸🇪🇺 "Max #Schrems will erneut gegen das Datenschutzabkommen zwischen der #EU und den #USA klagen. Ziel sei es, dass der Europäische Gerichtshof das Abkommen für nichtig erklärt. Grund sei eine Entscheidung des US Supreme Court von Ende Juni."
help.orf.at/stories/3236350/
Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇺 Your #privacy & #freedoms are at risk.
📢 Send a clear message:
❌ NO to #MassSurveillance 👀
✅ YES to #DigitalPrivacy🔒
🔔 Take Action Now:
👉 FightChatControl.eu

@chatcontrol
@echo_pbreyer

#ChatControl #ChatKontrolle #CSAM #FightChatControl #StopChatControl⁩ #DigitalRights #HumanRights #Freedom #FreedomOfSpeech #SpeechFreedom

in reply to ViaCampesinaBE ⁂⏚

The media in this post is not displayed to visitors. To view it, please go to the original post.

🇪🇺 Your #privacy & #freedoms are at risk.
📢 Send a clear message:
❌ NO to #MassSurveillance 👀
✅ YES to #DigitalPrivacy🔒
🔔 Take Action Now:
👉 FightChatControl.eu

@echo_pbreyer

#ChatControl #ChatKontrolle #CSAM #FightChatControl #StopChatControl⁩ #DigitalRights #HumanRights #Freedom #FreedomOfSpeech #SpeechFreedom

reshared this

The Pirate Post ha ricondiviso questo.

Every time the degenerate governments in the US opened some website for snitching on other people, there were comments about automated solutions to spam those systems with gibberish. I know because I myself made such comments more than once.

Now the shoe is on the other foot. Europeans should start running those same systems 24/7 to frustrate #ChatControl implementations.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

To any EU citizens seeing this, please do so! It's annoying that these politicians are adamant about this bill even after the parliament has voted no multiple times. #privacy #chatcontrol #surveillance

@chatcontrol mastodon.social/@chatcontrol/1…


🚨 In six hours, the European Parliament holds the final vote on reinstating Chat Control 1.0! We need 361 votes to stop it! Contact your MEPs NOW and demand they protect your right to privacy via fightchatcontrol.eu/

The Pirate Post ha ricondiviso questo.

Today is another vote for #chatcontrol 1.0.
I hope this will not get through. If you haven't already done, please contact your MEP's with fightchatcontrol.eu.

Use your democratic voice, as long as we have this option. Have a nice day! 😀

#privacy #datenschutz #euparliament

Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

sending the default email is done in 3 minutes. Best time investment you can make today

I repeat: this is *not* the open science we want

#chatcontrol


🚨 🚨 In four hours, the European Parliament is voting on reinstating Chat Control 1.0. We need 361 MEPs to stand their ground as they did once already. Take action now via fightchatcontrol.eu/

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Today, our 5 MEPs are voting (again!) against the "Chat Control" proposal. We need to pressure all the MEPs to do the same. You can do this in a few clicks here:

fightchatcontrol.eu

#ChatControl #ChatKontrolle #Chat #FightChatControl #EUpol #ChildAbuse #Encryption #ChildSafety #DataPrivacy #DigitalRights #EuropeanParliament

The Pirate Post ha ricondiviso questo.

#ChatControl
#StopChatControl

il Parlamento Europeo, sta cercando di fare passare nel disinteresse generale il controllo totale della nostra riservatezza che in nome di un ipocrita sicurezza può essere calpestata. Con questo provvedimento stanno abolendo la nostra libertà digitale, facendola passare per una lotta alla criminalità

ninasec.substack.com/p/lultimo…

Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

🔒 The EU is pushing Chat Control again: scanning your private messages "to keep you safe."

And behind it looms CSAR — which could force apps to scan your chats on your own phone, BEFORE they're encrypted (client-side scanning).

Translation: if someone reads the message before the lock closes, the lock is worthless. There's no backdoor "only for the good guys."

End-to-end encryption is non-negotiable. 🛡️

#ChatControl #Privacy #E2EE #Encryption

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Weniger #Bürokratie - aber zu welchem Preis?

Der Food & Feed Omnibus soll das Lebensmittel-, Futtermittel- und Pestizidrecht vereinfachen. Das ist grundsätzlich richtig. Doch wenn #Pestizidwirkstoffe künftig unbefristet zugelassen werden, gefährdet das Umwelt, Artenvielfalt und Gesundheit. Bürokratieabbau darf nicht zulasten von Umwelt- und Verbraucherschutz gehen. Wir brauchen weniger Pestizide in unserer #Umwelt und auf unseren Tellern.

The Pirate Post ha ricondiviso questo.

Hoje vai passar-se algo de grave no Parlamento Europeu. Como o POLITICO refere, uma jogada de poder da Presidente do Parlamento Europeu, sem precedente, fará o Parlamento votar pela 3º vez em 4 meses algo que antes chumbou. Sim, o #ChatControl 1.0. Sim, outra vez.

politico.eu/article/president-…

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

🚨🚨🚨 In exactly one hour, the voting for Chat Control 1.0 begins. This is your final chance to urgently contact your MEPs via fightchatcontrol.eu/

There are separate votes

1) rejection
2) amendments
3) if none adopted, another rejection vote can be requested

If nothing passes, the text is adopted!

in reply to Fight Chat Control

what a lame excuse as if everyone is a sick CSAM (Child Sexual Abuse Material) suspect. I don't worry about #chatControl. I simply avoid that sick software using a decentral XMPP messenger server in tiny-server.org/ in combination with open source non contaminated #chatcontrol XMPP clients and finalcrypt.org/ on top to OTP encrypt all my files against scanning. What are they gonna do about it 🤣 (there's nothing there, but just to show who's in charge of my privacy) 😎
The Pirate Post ha ricondiviso questo.

🇩🇪"Nach dieser totalitären Überwachungslogik müssten ja selbst unsere Schlafzimmer als potenzielle Missbrauchsgelegenheiten unter Überwachung stehen."
#Chatkontrolle 1.0 ist heute so gefährlich wie bei ihrer Einführung. Meine Plenarrede damals.
peertube.european-pirates.eu/w…
The Pirate Post ha ricondiviso questo.

🚨 URGENTE

L'ultima edizione di #NINAsec arriva come Call to Action, perchè oggi si vota il Chat Control.

La situazione è grave per tutti i diritti di libertà di Internet, facciamo in modo che non si trasformi in un pericoloso sistema di controllo
ninasec.substack.com/p/lultimo…

@politica

Questa voce è stata modificata (2 settimane fa)
in reply to N_{Dario Fadda}

The media in this post is not displayed to visitors. To view it, please go to the original post.

Ecco come è andata per i partiti italiani sul tema Chat Control

Qui la dashboard completa:
dariofadda.it/chat-control/202…

#stopchatcontrol

Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

☕ CYBERBRIEFING — Giovedì 9 luglio 2026

👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
ilpuntocyber.rfeed.it/article.…

#newsletter #cybersecurity
@informatica

The Pirate Post ha ricondiviso questo.

Damit die Polizei Daten über psychisch Erkrankte von Kliniken bekommen kann, haben einige Bundesländer neue Regeln erarbeitet. Eine Umfrage zeigt: Weitere könnten bald nachziehen. #psychkg

netzpolitik.org/2026/datenaust…

in reply to netzpolitik.org

@annskaja

Danke für den Artikel. Aktuell wird in NRW, Kreis Lippe ein QS Verfahren bis 2030 in der therapeutischen Sitzung getestet, bei dem Fragebögen von Ärzten und Patienten pseudonymisiert zentral gespeichert werden. 2031 soll das dann Bundesweit ausgeweitet werden. In Kombination dessen, dass die Polizei Zugriff auf Daten will, habe ich akute Befürchtung und kein Vertrauen in den Staat, dass ich jetzt schon, Therapien in meiner Gegend nicht wahrnehmen kann.

The government wants to scare Americans out of sharing the news


Federal officials have repeatedly claimed that criticizing immigration officials or identifying officers is unlawful and dangerous, despite clear First Amendment protections for both. Now, the government appears to be taking a disturbing new step: investigating Americans for posting information on social media that originally appeared in news reports.

This tactic allows the government to kill two birds with one stone: censoring individual critics and limiting the reach of the press. If the government can deter people from sharing news reports through threats of investigation or prosecution, it can undermine the public impact of journalism without ever censoring a newsroom directly.

Local news outlet Syracuse.com reported last month that federal agents tracked down a New York woman to demand she remove a social media post that they claimed threatened Immigration and Customs Enforcement personnel. Agents confronted the woman, Paigelynne Gonyea, where she worked at a polling place and demanded she sign a form letter stating she could be criminally prosecuted for threatening a federal officer.

Gonyea told Syracuse.com that she believed agents were referring to a January Instagram post “where she named the ICE agent who shot protester Renee Good.” In the post, Gonyea shared a picture of the agent, Jonathan Ross, that The Minnesota Star Tribune used in its news report first identifying him as the shooter.

Gonyea wrote, “BREAKING: The ICE agent who shot and killed Renee Good in broad daylight has been identified as Jonathan Ross by the Minnesota Star Tribune. I think today is a great day for Jonathan to be indicted!”

The Department of Homeland Security later told The Associated Press that Gonyea also posted Ross’ home address, and a spokeswoman shared with the AP reporter a different, redacted social media post purporting to come from Gonyea’s account. But Gonyea denied posting Ross’ address, and DHS has not made the alleged post publicly available. Gonyea also told NPR that agents who came to the polling station had a copy of her Instagram post with the photo of Ross, which does not include his address.

Freedom of the Press Foundation (FPF) has filed a Freedom of Information Act request with ICE’s Office of Professional Responsibility, which investigated Gonyea and other incidents it claims amounted to illegal “doxxing” of ICE agents. We’re seeking records about whether the investigations of Gonyea and others are based on people reposting information from news outlets, or have otherwise targeted journalism.

These records should be made public, especially because the agents’ legal warnings to Gonyea closely track similar threats the federal government has made to journalists. Administration officials have repeatedly claimed that journalists who photograph or name ICE officers are doxxing officers, inciting violence, or even committing violence. The First Amendment, however, protects publishing truthful, lawfully obtained information and photographing officers in public, whether it’s done by journalists or others.

In addition, if Gonyea is right that agents confronted her over an Instagram post repeating information from the Tribune, then the government’s actions may reveal a new way it’s trying to suppress reporting. DHS may not be able to censor reporting by chilling journalists, but it can suppress the news if it can scare people out of reposting it.

DHS may not be able to censor reporting by chilling journalists, but it can suppress the news if it can scare people out of reposting it.

Another of the administration’s favorite tricks, intimidating journalists’ sources, stops newsgathering before it starts. But when a story slips through the cracks, bullying those who share it offers a censorship backup plan.

This strategy also allows DHS to avoid directly confronting news outlets and journalists, who are better positioned to fight back against unconstitutional censorship orders or other First Amendment violations. Regular people are more likely to be dissuaded by the threat of criminal prosecution and less likely to bring court cases that can result in precedent that checks government power.

This undermines journalism’s ability to hold power accountable. Freedom of the press means little if no one can talk about a news story because they’re scared they’ll go to jail.

We must also remain vigilant against other ways that the government may be going around journalists and outlets to suppress news published online. Gonyea’s experience raises the disturbing possibility that the government could be pressuring tech platforms to remove posts by people that reference news reports about ICE by claiming that they’re illegal.

The Department of Justice has already coerced Facebook into removing at least one group that allowed people to report sightings of federal agents, arguing that it was inciting violence. It also pressured Apple and Google into removing ICE tracking apps based on similarly spurious claims.

We don’t know whether this has happened in cases involving other types of online content, including with demands to remove posts that simply repeat information from news reports, because these requests are often invisible to the public.

News outlets may raise alarms when platforms remove their reporting, but individual users are less likely to publicly object if their posts citing a news story are removed. Platforms’ transparency reports are too vague and high level to shed light on these demands. FOIA requests about the government’s demands for platforms can help, but often only if you have the ability to sue.

Whether the government quietly coerces platforms into removing individual posts about the news or loudly pressures individual Americans into taking them down themselves, the effect is the same: The public’s ability to see, share, and discuss reporting that holds officials accountable is limited.

These tactics must be recognized as a threat to press freedom, even if they don’t directly involve a newsroom. Freedom of the press can’t end when the news story is published. Defending a free press means defending everyone’s right to participate in the public conversation that allows that journalism to spread.


freedom.press/issues/the-gover…

Elezioni e Politica 2026 reshared this.

The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Faudra-t-il bientôt présenter ses papiers pour accéder à un réseau social ? C'est ce que voudrait le gouvernement et la macroniste Laure Miller, avec une proposition de loi visant à interdire aux moins de 15 ans l'accès aux réseaux sociaux. Problème : pour interdire aux jeunes d'accéder à un réseau social, il faut vérifier l'âge de tout le monde. Et pour vérifier l'âge des personnes, il faut contrôler leur identité. On vous explique les enjeux de ce texte.

video.lqdn.fr/w/2iFcH8yVxZcSrp…

in reply to La Quadrature du Net

Nos équipes techniques restent pleinement mobilisées sur ce sujet et poursuivent leurs travaux afin d’identifier, dans ce cadre, des solutions permettant de mieux concilier les exigences d’accessibilité et de sécurité.
Dans l’intervalle, il est possible, si vous le souhaitez, de recourir à l’assistance d’une personne de confiance pour vous accompagner dans certaines démarches.
----
n/n
The Pirate Post ha ricondiviso questo.

Morgen wird inhaltlich abgestimmt, ob die #Chatkontrolle 1.0 doch neu eingesetzt wird.
Ihr überlegt, welchen Abgeordneten aus DE ihr heute schreiben solltet?
Meiner Meinung nach unbedingt folgende fünf SPD-Abgeordnete: Katarina Barley, Tobias Cremer, Bernd Lange, Maria Noichl und Sabrina Repp.

Bittet sie darum morgen abzustimmen:
* für Ablehnung des Standpunkts des Rates (Massenüberwachung)
* für Rückkehr zur beschlossenen Position des Parlaments (zielgerichtete Maßnahmen)

Warum & wer noch? 🧵


Abstimmungsergebnis zum Verfahren im Detail:

europarl.europa.eu/doceo/docum…

Für das außerordentliche Verfahren: Fast alle von EVP, Mehrheit von S&D, Teile Renew, Teile EKR (rechts), Teile PfE (noch rechter)

Dagegen: Mitglieder aus allen Gruppen. Grüne / Linke stabil. Insgesamt eine Mehrheit aus DE dagegen, das hat aber nicht gereicht.

Hier auch noch mal in zugänglicher:
howtheyvote.eu/votes/195338

Jetzt am Donnerstag die neue Abstimmung über das eigentliche Gesetz.
#Chatkontrolle #ChatkontrolleStoppen

@pneutig@eupolicy.social:

Es gibt eine knappe Mehrheit dafür den Eilantrag zur Neueinsetzung der #Chatkontrolle 1.0 zuzulassen.
331 dafür.
304 dagegen.
11 Enthaltungen.

Das ist nicht gut. Jetzt wird am Donnerstag abgestimmt, ob das Gesetz auch inhaltlich durch kommt. Nur mit einer absoluten Mehrheit können die Abgeordneten das dort noch aufhalten. 🚨
#ChatkontrolleStoppen



Questa voce è stata modificata (2 settimane fa)
The Pirate Post ha ricondiviso questo.

"Die Digitalorganisation D64 hat unterdessen eine Aktion „Rettet das Informationsfreiheitsgesetz!“ gestartet. In der Graswurzel-Kampagne stellt D64 Musteranträge für Parteimitglieder von Union und SPD bereit, damit sich dort unterschiedliche Parteigliederungen für das Informationsfreiheitsgesetz und gegen die geplanten Änderungen aussprechen können."

via @netzpolitik_feed

netzpolitik.org/2026/gegenwind…

The Pirate Post ha ricondiviso questo.

"Das ZDF soll uneingeschränkt die kritische Berichterstattung gewährleisten" sollte an sich keine kontroverse Forderung sein.

Unser Co-Vorsitzender @erik beschäftigt sich in seiner Kolumne "Neues aus dem Fernsehrat" bei @netzpolitik_feed mit der Frage, ob Sanktionslisten auch Auswirkungen auf die Berichterstattung des ZDF haben könnten, und stellt einige Forderungen auf. Welche das sind, lest ihr hier:

netzpolitik.org/2026/neues-aus…

The Pirate Post ha ricondiviso questo.

🇩🇪 #Piraten-Europaabgeordnete Marketa Gregorova gestern mit Klartext zur Parlamentspräsidentin: "Sie missachten die Regeln und versuchen die #Chatkontrolle durch die Hintertür zurückzubringen. Kolleginnen und Kollegen, bleibt standhaft und stimmt wieder dagegen!"
youtube.com/watch?v=x_CncrZtDr…
Questa voce è stata modificata (2 settimane fa)
in reply to Patrick Breyer

🇪🇺 #Pirates MEP Marketa Gregorova told EP President Metsola yesterday: "You did not abide by the rules and asked to revive #ChatControl after the plenary rejected it. This is a farce! Colleagues, stand your ground and vote Chat Control down again!"
youtube.com/watch?v=x_CncrZtDr…

reshared this

The Pirate Post ha ricondiviso questo.

Die Pläne des Koalitionsausschusses, die Informationsfreiheit faktisch abzuschaffen, geraten immer mehr ins Wanken. Nach großen Teilen der Zivilgesellschaft und den zuständigen Behörden stellt sich nun auch SPD-Bundestagsfraktion dagegen. #IFG

netzpolitik.org/2026/gegenwind…

#ifg
in reply to netzpolitik.org

#spd #digitalisierung #konsequentInkonsequent #koalition
Au weia. Wer von der SPD ist eigentlich im Koalitionsausschuss und weiß, von was er/sie spricht, wenn es um die Rechte der Bürgerinnen geht?
Hat da jemand was geraucht oder absichtlich in das Papier geschmuggelt? So wie damals beim Shanghaier Kugelfischabkommen bei den Koalitionsverhandlungen zwischen SPD und Grünen in Hessen 1984? de.wikipedia.org/wiki/Shanghai…
The Pirate Post ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Bad Epoll (CVE-2026-46242): la race condition nel kernel Linux che regala root a chiunque
#tech
spcnet.it/bad-epoll-cve-2026-4…
@informatica


Bad Epoll (CVE-2026-46242): la race condition nel kernel Linux che regala root a chiunque


Una race condition di sei istruzioni che porta a root


Il 4 luglio 2026 è stata resa pubblica una nuova vulnerabilità di privilege escalation nel kernel Linux, battezzata Bad Epoll e catalogata come CVE-2026-46242. Il difetto permette a un utente locale non privilegiato di ottenere i permessi di root su qualsiasi sistema Linux con kernel 6.4 o successivo, incluse le distribuzioni server più diffuse e i dispositivi Android, dove epoll è un componente del kernel che non può essere disattivato senza rompere il funzionamento del sistema operativo e del browser.

Per chi gestisce infrastrutture Linux in produzione, questo è il tipo di bug che merita attenzione immediata: non richiede alcuna interazione dell’utente privilegiato, non richiede configurazioni particolari, e la finestra di race condition — appena sei istruzioni macchina — non è un ostacolo, perché l’exploit pubblicato la sfrutta con un’affidabilità di circa il 99%.

Cos’è epoll e dove si trova il bug


epoll è il meccanismo con cui il kernel Linux notifica in modo efficiente ai processi eventi di I/O su un gran numero di file descriptor, ed è alla base di praticamente ogni event loop moderno: da Nginx a Node.js, da systemd a Chrome. Proprio perché è così centrale, non è un modulo che si possa scaricare o disabilitare come contromisura temporanea.

Il ricercatore Jaeyoung Chung, dottorando al CompSec Lab della Seoul National University, ha individuato un use-after-free (UAF) nella funzione ep_remove(), quella che ripulisce un file descriptor epoll quando viene chiuso. In condizioni normali, ep_remove() azzera file->f_ep sotto file->f_lock, ma continua a utilizzare l’oggetto file all’interno della sezione critica durante le chiamate a hlist_del_rcu() e spin_unlock(). Se in quella finestra ristrettissima una chiamata concorrente a __fput() osserva un valore transitorio NULL, salta eventpoll_release_file() e procede direttamente a f_op->release, liberando una struttura eventpoll ancora in uso.

Il risultato è memoria del kernel corrotta. Poiché struct file è allocata con SLAB_TYPESAFE_BY_RCU, lo slot liberato può essere immediatamente riciclato da alloc_empty_file(), aprendo la strada a un cross-cache attack: l’attaccante fa in modo che il kernel richiami kmem_cache_free() sulla cache sbagliata, ottenendo il controllo su un oggetto di tipo diverso da quello originariamente allocato in quello slot.

La catena dell’exploit


L’exploit pubblicato da Chung costruisce quattro file descriptor epoll collegati tra loro, organizzati in due coppie: chiudendo una coppia si innesca ripetutamente la race condition, mentre l’altra coppia funge da “vittima”. In questo modo una scrittura UAF di soli 8 byte viene trasformata in un use-after-free completo su un oggetto file tramite cross-cache attack. Da lì, l’attaccante ottiene lettura arbitraria della memoria del kernel attraverso /proc/self/fdinfo e dirotta il flusso di esecuzione con una catena ROP (return-oriented programming) fino a ottenere una shell root.

# Schema semplificato della sequenza (pseudocodice concettuale)
fd1, fd2 = crea_coppia_epoll()   # coppia "trigger"
fd3, fd4 = crea_coppia_epoll()   # coppia "vittima"

thread_A: chiudi(fd1)   # innesca ep_remove() ripetutamente
thread_B: chiudi(fd3)   # __fput() concorrente osserva f_ep == NULL
# -> eventpoll_release_file() saltato
# -> free prematuro dell'oggetto eventpoll ancora referenziato
# -> alloc_empty_file() ricicla lo slot -> cross-cache attack

Va sottolineato che questo bug è raggiungibile anche dall’interno della sandbox del processo di rendering di Google Chrome, il che significa che un exploit lato browser potrebbe in teoria essere incatenato a Bad Epoll per ottenere l’esecuzione di codice completa a livello kernel, superando l’isolamento del sandbox.

Perché nemmeno un modello AI lo ha trovato


La storia di questo bug ha un risvolto interessante per chi segue l’evoluzione degli strumenti di analisi automatica del codice. Entrambe le vulnerabilità nascono da un singolo commit del 2023 nello stesso percorso di codice di epoll, lungo circa 2.500 righe. La prima, oggi tracciata come CVE-2026-43074, era stata individuata dal modello AI di Anthropic, Mythos, e già corretta all’inizio del 2026. Bad Epoll è la seconda falla, gemella della prima ma molto più difficile da individuare, che Mythos non aveva notato.

Chung stesso indica due possibili ragioni: la finestra temporale è talmente stretta da rendere difficile “visualizzare” la sequenza esatta degli eventi anche leggendo il codice con attenzione, e l’errore di memoria raramente attiva KASAN, il principale rilevatore di bug del kernel, lasciando pochissime tracce a runtime. È un promemoria utile: gli strumenti di code review basati su AI stanno diventando sempre più capaci di individuare race condition nel kernel, ma i bug di concorrenza restano difficili da scovare a ogni livello, per una macchina come per una persona.

Patch e mitigazioni per i sistemisti


Non esiste un workaround praticabile, perché disabilitare epoll non è un’opzione realistica su un sistema Linux moderno. La correzione definitiva è arrivata con il commit upstream a6dc643c6931, dopo che un primo tentativo di patch non aveva risolto completamente il problema — la correzione corretta è arrivata a circa due mesi dalla divulgazione iniziale.

Le azioni concrete da intraprendere:

  • Verificare la versione del kernel in uso: sono interessati i kernel basati su 6.4 e successivi; i kernel 6.1 più datati (compresi alcuni dispositivi Android come il Pixel 8) non sono vulnerabili perché il bug è stato introdotto solo con la 6.4.
  • Applicare l’aggiornamento del kernel non appena la propria distribuzione rilascia il backport della patch (Debian, Ubuntu, RHEL e derivate stanno seguendo il processo standard di backport della sicurezza).
  • Su flotte Android/embedded, verificare i cicli di aggiornamento del vendor per il patch level di sicurezza corrispondente.
  • Non fare affidamento su mitigazioni lato SELinux/AppArmor come sostituto della patch: riducono la superficie d’attacco ma non chiudono la race condition nel kernel.

Vale la pena ricordare che Bad Epoll si inserisce in una serie di bug di privilege escalation del kernel Linux usati storicamente anche per il root di Android, come Bad Binder, Bad IO_uring e Bad Spin. A differenza di altri bug recenti più deterministici (come Copy Fail o Dirty Frag), Bad Epoll appartiene alla categoria più “classica” delle race condition da vincere, nello stile di Dirty Cow del 2016: meno affidabile in teoria, ma qui resa quasi deterministica da un exploit ben costruito.

Conclusione


Per chi amministra server Linux, workstation di sviluppo o flotte Android aziendali, Bad Epoll è un chiaro caso da trattare con priorità alta: patch del kernel disponibile, nessuna mitigazione alternativa valida, e un exploit pubblico con affidabilità prossima al 100%. La lezione più ampia è che, nonostante i progressi degli strumenti di analisi automatica basati su AI nel trovare bug di concorrenza nel kernel, la revisione umana e soprattutto la prontezza nell’applicare le patch di sicurezza restano parte essenziale della gestione del rischio su qualunque infrastruttura Linux.

Fonte: 4sysops.com, con approfondimenti da The Hacker News e Cyber Security News.