CVE-2022-27666: Exploit esp6 module in Linux kernel
Xiaochen Zou aka ETenal published an article on exploiting a page_alloc-out-of-bounds in the esp6 crypto module.
The researcher:
1️⃣ performed page-level heap fengshui to gain page_alloc-to-slab overflow,
2️⃣ constructed arbitrary read/write using the msg_msg kernel object,
3️⃣ finally achieved root privileges via modprobe_path overwrite.
The article comes with excellent animated diagrams.
Post #159
2.78K
- 🔥 9
- 👍 5