Imagine this — you click play on Netflix on a Friday night and behind the scenes hundreds of containers spring to action in a few seconds to answer your call. At Netflix, scaling containers efficiently is critical to delivering a seamless streaming experience to millions of members worldwide. To keep up with responsiveness at this scale, we modernized our container runtime, only to hit a surprising bottleneck: the CPU architecture itself.
Let us walk you through the story of how we diagnosed the problem and what we learned about scaling containers at the hardware level.
The Problem
When application demand requires that we scale up our servers, we get a new instance from AWS. To use this new capacity efficiently, pods are assigned to the node until its resources are considered fully allocated. A node can go from no applications running to being maxed out within moments of being ready to receive these applications.
As we migrated more and more from our old container platform to our new container platform, we started seeing some concerning trends. Some nodes were stalling for long periods of time, with a simple health check timing out after 30 seconds. An initial investigation showed that the mount table length was increasing dramatically in these situations, and reading it alone could take upwards of 30 seconds. Looking at systemd’s stack it was clear that it was busy processing these mount events as well and could lead to complete system lockup. Kubelet also timed out frequently talking to containerd in this period. Examining the mount table made it clear that these mounts were related to container creation.
The affected nodes were almost all r5.metal instances, and were starting applications whose container image contained many layers (50+).
Challenge
Mount Lock Contention
The flamegraph in Figure 1 clearly shows where containerd spent its time. Almost all of the time is spent trying to grab a kernel-level lock as part of the various mount-related activities when assembling the container’s root filesystem!
Figure 1: Flamegraph depicting lock contention
Looking closer, containerd executes the following calls for each layer if using user namespaces:
open_tree() to get a reference to the layer / directory
mount_setattr() to set the idmap to match the container’s user range, shifting the ownership so this container can access the files
move_mount() to create a bind mount on the host with this new idmap applied
These bind mounts are owned by the container’s user range and are then used as the lowerdirs to create the overlayfs-based rootfs for the container. Once the overlayfs rootfs is mounted, the bind mounts are then unmounted since they are not necessary to keep around once the overlayfs is constructed.
If a node is starting many containers at once, every CPU ends up busy trying to execute these mounts and umounts. The kernel VFS has various global locks related to the mount table, and each of these mounts requires taking that lock as we can see in the top of the flamegraph. Any system trying to quickly set up many containers is prone to this, and this is a function of the number of layers in the container image.
For example, assume a node is starting 100 containers, each with 50 layers in its image. Each container will need 50 bind mounts to do the idmap for each layer. The container’s overlayfs mount will be created using those bind mounts as the lower directories, and then all 50 bind mounts can be cleaned up via umount. Containerd actually goes through this process twice, once to determine some user information in the image and once to create the actual rootfs. This means the total number of mount operations on the start up path for our 100 containers is 100 * 2 * (1 + 50 + 50) = 20200 mounts, all of which require grabbing various global mount related locks!
Diagnosis
What’s Different In The New Runtime?
As alluded to in the introduction, Netflix has been undergoing a modernization of its container runtime. In the past a virtual kubelet + docker solution was used, whereas now a kubelet + containerd solution is being used. Both the old runtime and the new runtime used user namespaces, so what’s the difference here?
Old Runtime: All containers shared a single host user range. UIDs in image layers were shifted at untar time, so file permissions matched when containers accessed files. This worked because all containers used the same host user.
New Runtime: Each container gets a unique host user range, improving security — if a container escapes, it can only affect its own files. To avoid the costly process of untarring and shifting UIDs for every container, the new runtime uses the kernel’s idmap feature. This allows efficient UID mapping per container without copying or changing file ownership, which is why containerd performs many mounts.
Figure 2 below is a simplified example of how this idmap feature looks like:
Figure 2: idmap feature
Why Does Instance Type Matter?
As noted earlier, the issue was predominantly occurring on r5.metal instances. Once we identified the root issue we could easily reproduce by creating a container image with many layers and sending hundreds of workloads using the image to a test node.
To better understand why this bottleneck was more profound on some instances compared to others, we benchmarked container launches on different AWS instance types:
r5.metal (5th gen Intel, dual-socket, multiple NUMA domains)
m7i.metal-24xl (7th gen Intel, single-socket, single NUMA domain)
m7a.24xlarge (7th gen AMD, single-socket, single NUMA domain)
Baseline Results
Figure 3 shows the baseline results from scaling containers on each instance type
At low concurrency (≤ ~20 containers), all platforms performed similarly
As concurrency increased, r5.metal began to fail around 100 containers
7th generation AWS instances maintained lower launch times and higher success rates as concurrency grew
m7a instances showed the most consistent scaling behavior with the lowest failure rates even at high concurrency
Deep Dive
Using perf record and custom microbenchmarks, we can see the hottest code path was in the Linux kernel’s Virtual Filesystem (VFS) path lookup code — specifically, a tight spin loop waiting on a sequence lock in path_init(). The CPU spent most of its time executing the pause instruction, indicating many threads were spinning, waiting for the global lock, as shown in the disassembly snippet below
path_init(): … mov mount_lock,%eax test $0x1,%al je 7c pause …
Using Intel’s Topdown Microarchitecture Analysis (TMA), we observed:
95.5% of pipeline slots were stalled on contested accesses (tma_contested_accesses).
57% of slots were due to false sharing (multiple cores accessing the same cache line).
Cache line bouncing and lock contention were the primary culprits.
Given a high amount of time being spent in contested accesses, the natural thinking from a perspective of hardware variations led to investigation of NUMA and Hyperthreading impact coming from the architecture to this subset
NUMA Effects
Non-Uniform Memory Access (NUMA) is a system design where each processor has its own local memory for faster access but relies on an interconnect to access the memory attached to a remote processor. Introduced in the 1990s to improve scalability in multiprocessor systems, NUMA boosts performance but also introduces higher latency when a CPU needs to access memory attached to another processor. Figure 4 is a simple image describing local vs remote access patterns of a NUMA architecture
AWS instances come in a variety of shapes and sizes. To obtain the largest core count, we tested the 2-socket 5th generation metal instances (r5.metal), on which containers were orchestrated by the titus agent. Modern dual-socket architectures implement NUMA design, leading to faster local but higher remote access latencies. Although container orchestration can maintain locality, global locks can easily run into high latency effects due to remote synchronization. In order to test the impact of NUMA, we tested an AWS 48xl sized instance with 2 NUMA nodes or sockets versus an AWS 24xl sized instance, which represents a single NUMA node or socket. As seen from Figure 5, the extra hop introduces high latencies and hence failures very quickly.
Figure 5: Numa Impact
Hyperthreading Effects
Hyperthreading (HT): Disabling HT on m7i.metal-24xl (Intel) improved container launch latencies by 20–30% as seen in Figure 6, since hyperthreads compete for shared execution resources, worsening the lock contention. When hyperthreading is enabled, each physical CPU core is split into two logical CPUs (hyperthreads) that share most of the core’s execution resources, such as caches, execution units, and memory bandwidth. While this can improve throughput for workloads that are not fully utilizing the core, it introduces significant challenges for workloads that rely heavily on global locks. By disabling hyperthreading, each thread runs on its own physical core, eliminating this competition for shared resources between hyperthreads. As a result, threads can acquire and release global locks more quickly, reducing overall contention and improving latency for operations that generally share underlying resources.
Figure 6: Hyperthreading impact
Why Does Hardware Architecture Matter?
Centralized Cache Architectures
Some modern server CPUs use a mesh-style interconnect to link cores and cache slices, with each intersection managing cache coherence for a subset of memory addresses. In these designs, all communication passes through a central queueing structure, which can only handle one request for a given address at a time. When a global lock (like the mount lock) is under heavy contention, all atomic operations targeting that lock are funneled through this single queue, causing requests to pile up and resulting in memory stalls and latency spikes.
In some well-known mesh-based architectures as shown in Figure 7 below, this central queue is called the “Table of Requests” (TOR), and it can become a surprising bottleneck when many threads are fighting for the same lock. If you’ve ever wondered why certain CPUs seem to “pause for breath” under heavy contention, this is often the culprit.
Some modern server CPUs use a distributed, chiplet-based architecture (Figure 8), where multiple core complexes, each with their own local last-level cache — are connected via a high-speed interconnect fabric. In these designs, cache coherence is managed within each core complex, and traffic between complexes is handled by a scalable control fabric. Unlike mesh-based architectures with centralized queueing structures, this distributed approach spreads contention across multiple domains, making severe stalls from global lock contention less likely. For those interested in the technical details, public documentation from major CPU vendors provides deeper insight into these distributed cache and chiplet designs.
Here is a comparison of the same workload run on m7i (centralized cache architecture) vs m7a (distributed cache architecture). Note that, in order to make it closely comparable, Hyperthreading (HT) was disabled on m7i, given previous regression seen in Figure 6, and experiments were run using same core counts. The result clearly shows a fairly consistent difference in performance of approximately 20% as shown in Figure 9
Figure 9: Architectural impact between m7i and m7a
Microbenchmark Results
To prove the above theory related to NUMA, HT and micro-architecture, we developed a small microbenchmark which basically invokes a given number of threads that then spins on a globally contended lock. Running the benchmark at increasing thread counts reveals the latency characteristics of the system under different scenarios. For example, Figure 10 below is the microbenchmark results with NUMA, HT and different microarchitectures.
Figure 10: Global lock contention benchmark results
Results from this custom synthetic benchmark (pause_bench) confirmed:
On r5.metal, eliminating NUMA by only using a single socket significantly drops latency at high thread counts
On m7i.metal-24xl, disabling hyperthreading further improves scaling
On m7a.24xlarge, performance scales the best, demonstrating that a distributed cache architecture handles cache-line contention in this case of global locks more gracefully.
Improving Software Architecture
While understanding the impacts of the hardware architecture is important for assessing possible mitigations, the root cause here is contention over a global lock. Working with containerd upstream we came to two possible solutions:
Use the newer kernel mount API’s fsconfig() lowerdir+ support to supply the idmap’ed lowerdirs as fd’s instead of filesystem paths. This avoids the move_mount() syscall mentioned prior which requires global locks to mount each layer to the mount table
Map the common parent directory of all the layers. This makes the number of mount operations go from O(n) to O(1) per container, where n is the number of layers in the image
Since using the newer API requires using a new kernel, we opted to make the latter change to benefit more of the community. With that in place, no longer do we see containerd’s flamegraph being dominated by mount-related operations. In fact, as seen in Figure 11 below we had to highlight them in purple below to see them at all!
Figure 11: Optimized solution
Conclusion
Our journey migrating to a modern kubelet + containerd runtime at Netflix revealed just how deeply intertwined software and hardware architecture can be when operating at scale. While kubelet/containerd’s usage of unique container users brought significant security gains, it also surfaced new bottlenecks rooted in kernel and CPU architecture — particularly when launching hundreds of many layered container images in parallel. Our investigation highlighted that not all hardware is created equal for this workload: centralized cache management amplified cache contention while distributed cache design smoothly scaled under load.
Ultimately, the best solution combined hardware awareness with software improvements. For an immediate mitigation we chose to route these workloads to CPU architectures that scaled better under these conditions. By changing the software design to minimize per-layer mount operations, we eliminated the global lock as a launch-time bottleneck — unlocking faster, more reliable scaling regardless of the underlying CPU architecture. This experience underscores the importance of holistic performance engineering: understanding and optimizing both the software stack and the hardware it runs on is key to delivering seamless user experiences at Netflix scale.
We trust these insights will assist others in navigating the evolving container ecosystem, transforming potential challenges into opportunities for building robust, high-performance platforms.
Special thanks to the Titus and Performance Engineering teams at Netflix.
На 25-ти февруари парламента с гласовете на ГЕРБ, Възраждане, ИТН и част от ДСП-НН и БСП беше отхвърлено ветото на промените в Изборния кодекс. Тези промени намаляваха броя секции в страни извън ЕС, които може да се създадат извън дипломатическите представителства на 20. От обсъжданията и силната покрепа на Пеевски при първото гласуване и осигуряването на подкрепа при последното, става ясно, че целта е да се ограничат гласовете в Турция, Великобритания и САЩ.
Също така отлагат за пореден път с три години въвеждането на избирателен район Чужбина, който трябваше да бъде с 4 депутати специално представляващи българите зад граница. Към настоящия момент гласовете в чужбина се причисляват „служебно“ към избран от ЦИК район, изкривявайки значително волята на гласувалите там. Промените на Избирателния кодекс бяха обнародвани на 27-ми февруари. Още същия ден ЦИК измени решението си за разпределението на мандатите. Под новото решение ще намерите линк към старото и може да сравните. Веднага след това определи и местата, където автоматично ще се отварят секции зад граница. Правилото е, че в последните пет години трябва да са гласували поне 100 души в някоя от секциите на това място. Това означава, че се взимат предвид изборите за български и европейски парламент през юни 2024, изборите за парламент през октомври 2024, април 2023, октомври 2022 и юли 2021, както и смесените избори за парламент и президент през ноември 2021. Общо 7 вота.
В решението си ЦИК определя 372 секции на 58 места. За сравнение за октомври 2024-та определиха над два пъти повече такива секции – 783. Забелязва се веднага, че в Турция са превидили 4 места, във Великобритания – 2, а в САЩ – 4. Това са все посолства и консулства. В действителност, на база активността в последните пет години, секциите отворени по този начин трябва да са съответно 123, 107 и 85. Причината за това е, че предложението на ИТН подкрепено от ГЕРБ, ДПС-НН и Възраждане създава умишлено правен хаос, в който няма яснота как да се приложи правилото за 100-те гласували. Най-логичното би било да се вземат 20-те секции извън консулствта с най-много гласували. Това обаче не е описано изрично и ЦИК са решили просто да не спазят чл. 14, ал. 2, т. 2 от ИК.
Това, което буди притеснение обаче е, че в доста други страни секциите са намалени значително. Пример за това е Канада, където ЦИК решава да отвори секции само в Отава и Торонто. Над 100 гласували само при изборите през 2024-та има в Брамптън, Ванкувър, Вон, Калгари и всяка от 5-те секции в Монреал поотделно. Аналогично в Австралия искат секция само в посолството в Канабера, но над 100 гласа през юни 2021-ва е имало и в Мелбърн, Сидни и Пърт. Други държави с подобни „пропуски“ са Албания, Молдова, Норвегия, Северна Македония, Южна Африка, Сърбия и Швейцария. Не определят секции в Исландия, Нова Зеландия, Сингапур и Чешка република макар в последните 5 да е имало секции с повече от 100 гласували. Причината за това е друга аспект от промените в Изборния кодекс публикивани вчера – правилото за „поне 100 гласували“ вече се прилага само за страни от Европейския съюз“. Това допълнително утежнава процеса за гласуване на десетки хиляди българи спрямо постигнатия напредък в последните години.
Единственият избор за тези държави е да подават повече заявления за гласуване. Дори във Великобритания, САЩ и Турция това има значение, защото изглежда ще сме свидетели на състезание къде да има секция. Повечето заявления ще покажат за пореден път как има желаещи да гласуват и подобни мерки ограничават конституционните права на български граждани.
Както писах в предишната си статия, според хонограмата на ЦИК след няколко часа изтича срокът, в който следва да публикуват електронния формуляр за подаване на заявления. Когато излезе ще публикувам нова статия със съвети и ще изпратя напомняне да подават заявления на над 3000-те хиляди абонирали се за новини за поровеждането на изборите в чужбина.
Два месеца от все още новата 2026 година са вече история. Една шеста от годината отлетя неусетно. Точно толкова е отрязъкът от време и между назначаването на служебното правителство на Андрей Гюров и предсрочните парламентарни избори на 19 април. Време, през което част от играчите на политическата сцена ще се изправят и на главите си, за да отблъснат колкото е възможно повече хора от идеята да гласуват. Така ще могат за пореден път да си напазаруват влияние евтино и да прескочат чертата за оставане в играта. За сметка на всички нас, които трябва да направим и невъзможното да убедим още други като нас да гласуват – въпреки всичко. Защото е време за друго политическо поколение с различна политическа култура. И защото всички имаме право на надежда и по-смислено бъдеще.
Няма друга по-важна цел през следващите седем седмици.
И в този ред на мисли защо да не започнем нетрадиционно редакционния обзор на седмицата, а именно със стихотворението на месеца? Този път то е на Мирела Иванова, озаглавено е „Игра с поговорки“ и пулсира в синхрон с все тази същата позната ни трескавост, с която толкова свикнахме напоследък.
Иначе, от началото на 2026 г. политическата сцена у нас сякаш е застинала в очакване, докато Румен Радев превръща мълчанието си в злато. Според актуални социологически данни бившият президент трупа обществено одобрение просто като отказва да участва в информационния шум. Докато повечето му политически опоненти приличат на „дебютантки на бал“, очакващи покана за танц, Радев залага на тактическо дистанциране от ежедневните скандали – от „Петрохангейт“ до споровете за съдебната реформа. Тази стратегия му позволява да остане „вкаменен като статуя“ и да не поема рискове, докато разочарованите избиратели проектират върху него коренно различни надежди: от юмрук срещу корупцията до „равнис“ по Москва. Прочетете повече в седмичния вътрешнополитически анализ на Емилия Милчева.
След края на Мюнхенската конференция по сигурността светът продължава да изглежда по-фрагментиран от всякога. И докато големите европейски държави трескаво търсят формулата за „стратегическа автономия“, България се оказва в деликатна позиция – между амбицията да бъде част от ядрото и риска да остане в сивата зона на новите геополитически линии на разделение. В анализа си за „Тоест“ Александър Малинов търси отговори на въпросите какво означава за нас пренареждането на приоритетите в Европа, каква е цената на политическото колебание и защо тишината от София по ключови теми се чува все по-силно в Брюксел.
Седмицата донесе лоша новина за все по-оредяващото медийно многообразие в България. Заради бюджетни ограничения редакциите на „Свободна Европа“ у нас и в Румъния спират работа на 31 март. Българският екип търси алтернативен начин да продължи работа и след закриването. А всички в редакцията на „Тоест“ здраво стискаме палци гласовете на колегите от „Свободна Европа“ да не заглъхнат.
Къде изчезна смисълът на образованието, е въпрос, който си задаваме непрекъснато и по различни поводи. А в новия си текст за „Тоест“ Светла Енчева изследва белезите, които и държавното образование, и неговите алтернативи оставят на подрастващите. И ако класната стая освен място за предаване на знания е и инструмент за социално инженерство, с което се произвеждат „винтчета“ вместо личности, дали бягството към домашното образование не заменя един капан с друг? Възможно ли е образование, което да не превръща детето нито в „още една тухла в стената“, нито в заложник на родителските предразсъдъци? Светла търси отговора в пролуката между обществения интерес и личната независимост, напомняйки, че в тази битка най-често залогът е самото дете.
Оставаме на същата тема и с най-новата статия на Донка Дойчева-Попова. Тя разговаря с Нели Керемидчиева – радетелка за модернизацията на родното образование и съоснователка на фестивала „Възможното образование“. Нели споделя за трудния път на една тиха, но категорична революция – от прожекциите на първите преведени филми, променили нагласите на много родители, до изграждането на общност и нови образователни пространства, в които личността и връзката между хората са поставени над сухата фактология и оценките.
Замисляли ли сте се колко често разговорите за архитектура са всъщност разговори за обществото? В предстоящия епизод на „Тоест разговаряме“ Владислав Севов ще търси смисъла отвъд фасадите именно с арх. Анета Василева – доктор по история и теория на архитектурата, преподавателка в УАСГ и авторка на множество критически текстове, писани през последните над 15 години за различни издания, в т.ч. и за „Тоест“. Формален повод за разговора ще бъде и новата ѝ книга „Неудобната модерност. Българската архитектура след Втората световна война“ (изд. „Жанет 45“), която предстои да излезе в най-скоро време.
Другата събота Анета и Владислав ще ни превеждат визуалния език на архитектурата в думи. Ще разберем защо в дигиталната ера книгата се оказва по-силната медия за съхраняване на паметта и защо писането за архитектура е акт на обществена отговорност. Двамата ще коментират важния въпрос кога архитектът е просто изпълнител и кога е длъжен да заеме позиция.
Гледайте „Тоест разговаряме“ с Анета Василева на 7 март 2026 г. от 16:00 часа в YouTube Live, като преди това може да довършите изречението „Градът за хората е…“ и да зададете предварителен въпрос на Анета в нашата анкета.
След като в първата част на своя текст за рубриката „Ориент кафе“ Атанас Шиников ни въведе в света на арабските приложения за запознанства, във втората продължаваме да лъкатушим между вярата и алгоритмите, търсейки отговора на въпроса могат ли онлайн запознанствата да бъдат „халал“. И как оцеляват моралните императиви на исляма във време, в което „суайпването“ наляво и надясно стана част от ежедневието на необвързаните. Не пропускайте да прочетете продължението на статията за „Тиндър/Миндър“ и за битката за сърцата в дигиталния Ориент.
Тръгвайки от провокацията на поредната голяма класация, Миглена Николчина, Еньо Стоянов, Николай Генов и Чавдар Парушев деконструират мита за обективността в гейминдустрията чрез характерното за тях дълбоко философско и естетическо изследване на видеоигрите като поле на социално общуване. Потопете се в „Награди, класации, списъци – какво (не) казват те за видеоигрите?“ – един текст за всички, които търсят смисъла зад екрана на конзолата си.
И накрая – две страхотни новини за българската литература. Три години след като романът „Времеубежище“ на Георги Господинов в превод на английски език от Анджела Родел спечели международната литературна награда „Букър“, в дългия списък с номинирани книги за 2026 г. попадна и второ заглавие от български автор – „Остайница“ от Рене Карабаш в превод на Изидора Анжел. Романът ни сблъсква със суровата традиция на албанските жени, които заживяват като мъже, за да избягат от оковите на вековния патриархален закон. „Остайница“ е разказ за високата цена на свободата в свят, в който единственият начин да оцелееш е да се отречеш от собствената си природа.
За мнозина този уикенд ще бъде по-дълъг, ако са си позволили в понеделник да са в отпуск, защото във вторник е националният празник на България. По този повод искам да припомня един текст на Зорница Христова отпреди осем години. Това е всъщност първата поява на Зорница в „Тоест“ – от времето, когато медията имаше зад гърба си едва един месец съществуване. И до днес обаче текстът ѝ „Трети март“ продължава да е актуален.
This release brings some serious firepower with multiple new exploit modules and critical vulnerability support! The standout additions are the Ollama path traversal RCE (CVE-2024-37032), a sophisticated exploit chaining arbitrary file writes into unauthenticated root RCE, and the Grandstream GXP1600 stack overflow (CVE-2026-2329), which targets VoIP devices with accompanying credential harvesting and SIP interception post-modules.
The BeyondTrust PRA/RS module got upgraded with support for the new CVE-2026-1731 command injection vulnerability along with legacy CVE support. On the evasion front, there’s fresh ARM64 RC4 encryption support with sleep-based detection bypass. Classic vulnerability modules like Unreal IRCd and vsftpd backdoors got quality-of-life improvements with proper check methods and multiple exploitation targets. Several auxiliary scanners (LDAP ESC, GraphQL introspection) also received critical bugfix updates eliminating false positives and crashes.
Description: This adds a new module for unauthenticated command injection in BeyondTrust PRA/RS (CVE-2026-1731). This change also introduces a new library for BeyondTrust familiar helper functions; existing modules have been ported to use it.
Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices. The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.
Description: This adds a new exploit module for Ollama (CVE-2024-37032). Ollama’s pull mechanism accepts arbitrary path traversal sequences, allowing an attacker to load a rogue OCI registry and write arbitrary files. The exploit does this by writing .so files into the target, then forcing Ollama to spawn a new process where the malicious library is loaded.
Description: This adds a new persistence module for WSL that writes a payload to the user’s startup folder. The module creates a persistence for Windows; however, the initial access needs to be in Linux.
Description: This adds new persistence for Windows, which uses the Windows feature Active Setup. The module abuse is used to launch our payload, with 2 caveats. 1) You downgrade from admin to user permissions, 2) it only launches the payload once per user.
Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices. The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.
Enhancements and features (9)
#20859 from dledda-r7 – Splits the exe.rb into separate, more consistent files. Each file responds to a combination of platform and architecture, offering a better granular approach.
#20938 from Chocapikk – Improves the check method in the beyondtrust_pra_rs_unauth_rrce to properly detect older versions that are also vulnerable but report the version in a different way.
#20950 from g0tmi1k – Updates the vsftp_234_backdoor module to add shell and Meterpreter payloads, improve checking, and increase the output for better traoubleshooting.
#20951 from g0tmi1k – Moves default payload into DefaultOptions in Remote for Mac module. This makes it more consistent with other existing modules.
#20952 from g0tmi1k – Enhances the unix/irc/unreal_ircd_3281_backdoor module to increase payload options, including adding a native Meterpreter session, adds debugging logic inside the module, and more verbose output.
#20988 from adfoster-r7 – Improved SolarWinds exploit module to automatically pick the correct SRVHOST value.
#20992 from adfoster-r7 – Adds a check method to the ms17-010 scanner module to improve the metadata associated with automation workflows.
#21010 from Nayeraneru – This adds reporting for GitLab services.
#21014 from adfoster-r7 – Fixes a crash when running the ldap esc vulnerable cert finder against a target when LDAP binding fails.
Bugs fixed (1)
#21012 from adfoster-r7 – Improves the GraphQL Introspection Scanner module to correctly handle invalid responses and false positives.
Documentation added (3)
#20832 from DataExplorerX – Adds comprehensive documentation for the linux/samba/chain_reply module targeting CVE-2010-2063.
#20990 from jheysel-r7 – This adds and an AI Usage Policy to GSoC Ideas Page as requested by GSoC.
#21005 from h00die – This adds example of GNU inetutils auth bypass module against a Synology NAS to existing documentation.
You can always find more documentation on our docsite at docs.metasploit.com.
Get it
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.