CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel
D3v17 published an article describing the solution of their corCTF challenge CoRJail.
The PoC exploit used a single null-byte out-of-bounds write to corrupt a poll_list object in the kmalloc-4k slab cache and obtain an arbitrary free primitive.
It allowed the researcher to corrupt a user_key_payload structure and get out-of-bounds read.
Finally the researcher used the arbitrary free primitive to corrupt a pipe_buffer structure and hijack the kernel control flow to escape the container.
Post #183
2.67K