Blog

Einblicke aus unserer täglichen Arbeit

Einige Beiträge wurden von einem LLM aus dem Englischen ins Deutsche übersetzt.

Per RSS abonnieren
Category Icon
embedded

Hunting Down a Go Runtime Bug on 32-bit Embedded Systems

A customer's Go application kept crashing on a 32-bit embedded Linux system. We traced the fatal netpoll error to a pointer aliasing bug in the Go runtime.

22.08.2026
Category Icon
sigma-star

Ausgewählte Blog-Posts nun auch auf Deutsch verfügbar

Wir veröffentlichen ausgewählte Blog-Posts ab sofort auch auf Deutsch. Die Übersetzungen entstehen zum Großteil mit Hilfe eines LLMs.

19.08.2026
Category Icon
security

Integrität auf Embedded-Linux-Geräten unter dem Cyber Resilience Act

Was die Integritätsanforderung des CRA in der Praxis für Embedded-Linux-Geräte bedeutet.

29.06.2026
Category Icon
security

TrustZone Intermezzo: Kaputte OP-TEE-Speicherisolation auf dem i.MX 8M

Ein Commit, der den TZASC auf NXP i.MX 8M aktiviert, schickte uns auf eine ausgedehnte Spurensuche: wie ein DDR-Speicher-Alias die Arm TrustZone umgeht und OP-TEEs sicheren Speicher gegenüber Linux offenlegt.

11.06.2026
Category Icon
embedded

Sie brauchen wahrscheinlich kein Yocto, und das ist auch gut so

Yocto ist mächtig, doch für viele Embedded-Linux-Projekte ist es überdimensioniert. Wann Sie es einsetzen sollten, wann besser nicht, und was stattdessen infrage kommt.

26.05.2026
Category Icon
security

Vertraulichkeit von Daten durch Speicherverschlüsselung auf Embedded-Linux-Geräten

Ein Überblick über die Optionen zur Speicherverschlüsselung unter Linux.

24.02.2026
Category Icon
security

TPM on Embedded Systems: Pitfalls and Caveats

This Blog Post Outlines Common Pitfalls and Caveats when Integrating a TPM

19.01.2026
Category Icon
security

Fixing a Buffer Overflow in UNIX v4 Like It's 1973

This blog post shows how to fix a buffer overflow in the su progam of UNIX v4

31.12.2025
Category Icon
embedded

Die sich wandelnde Landschaft des Yocto-Projekt-Setups: bitbake-setup vs. KAS

Das neue offizielle Tool des Yocto-Projekts, bitbake-setup, ist jetzt verfügbar und bietet eine Alternative zum etablierten KAS-Tool für das Projekt-Setup. Dieser Beitrag vergleicht die entscheidenden Unterschiede bei Funktionen, Konfiguration und Philosophie, um den aktuellen Stand und die Zukunft von Yocto-Builds zu klären.

28.10.2025
Category Icon
linux

Deep Down the Rabbit Hole: Bash, OverlayFS, and a 30-Year-Old Surprise

This blog post describes a recent debugging session that led through a surprising set of issues involving Bash, `getcwd()`, and OverlayFS. What started as a simple customer bug report turned into a deep dive worth sharing.

24.06.2025
Category Icon
security

Dateisystem-Schwachstellen in Bootloadern: Ein verstecktes Risiko für Verified-Boot-Mechanismen

Dateisystem-Schwachstellen in Bootloadern wie U-Boot und Barebox stellen ein kritisches, aber häufig übersehenes Risiko für den Verified-Boot-Prozess in Linux-basierten IoT-Systemen dar. Verified-Boot-Mechanismen authentifizieren zwar die Inhalte von Dateien, doch Schwächen bei der Verarbeitung von Filesystem-Metadaten können Angreifern ermöglichen, die Chain of Trust zu umgehen. Dadurch sind Geräte der Ausführung beliebigen Codes ausgesetzt und ihre Systemsicherheit ist gefährdet.

27.01.2025
Category Icon
security

sigma-star-sa-2024-001: CHAP authentication bypass in user-space Linux target framework (tgt) up to v1.0.92 (CVE-2024-45751)

The user-space iSCSI target daemon of the Linux target framework (tgt) uses an insecure random number generator to generate CHAP authentication callenges. This results in predictable challenges which an attacker capable of recording network traffic between iSCSI target and initiator can abuse to bypass CHAP authentication by replaying previous responses.

07.09.2024
Category Icon
security

Thoughts on Linux CNA's Approach and the Resulting CVE Flood

Recently, the Linux Kernel Project attained the status of a CNA (CVE Numbering Authority), granting it the capability to independently issue CVEs (Common Vulnerabilities and Exposures). While this development may not appear groundbreaking on its own, the substantial increase in the number of newly assigned CVEs has captured the attention of many individuals. I've received numerous inquiries from people seeking clarification on the situation surrounding the Linux CNA and expressing concern about the apparent surge in the issuance of CVE numbers for almost every non-trivial patch applied to the maintained stable kernel trees.

13.03.2024
Category Icon
security

Pseudo Graceful Process Termination through Code Injection

This blog post outlines the utilization of code injection to create a tool capable of gracefully terminating any program, setting its exit code to 0.

25.02.2024
Category Icon
embedded

A Time Consuming Pitfall for 32-bit Applications on AArch64

When running legacy applications on AArch64, an interesting pitfall can arise.

14.02.2024
Category Icon
linux

Investigating Paranormal Shell Activities

Recently, while attending a conference, I observed an unusual occurrence in my terminal emulator: terminal tab windows were getting highlighted without any apparent notification within the shell session. Time to unpack our trusty debugging tools to uncover the mystery of these activities.

17.11.2023
1 2 3
Icon with a waving hand

Get in touch

sigma star gmbh
Eduard-Bodem-Gasse 6, 1. Stock
6020 Innsbruck | Österreich

sigma star gmbh logo