TGViewer
Channel Public Channel
Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
Subscribers
4.73K
Photos
123
Videos
0
Links
356

Showing posts older than #107 · Back to latest

Older Posts 20 shown
Post #106 1.41K
How AUTOSLAB Changes the Memory Unsafety Game

An article about AUTOSLAB — a grsecurity hardening feature, which prevents certain heap-based exploitation scenarios.

Besides having purely grsecurity-related info, it contains an analysis of the techniques used in the heap-based exploits from the last 5 years.

By Zhenpeng Lin.
grsecurity.net grsecurity - How AUTOSLAB Changes the Memory Unsafety Game In this guest blog, Zhenpeng Lin details the three-month evaluation he performed of AUTOSLAB during a research internship with Open Source Security, Inc. AUTOSLAB is a compiler-plugin-enhanced feature of grsecurity introduced in 2020 that provides some interesting…
Post #105 1.35K
Big improvements in my Linux Kernel Defence Map showing:
🔴Vulnerability classes
🟠Exploitation techniques
🟣Bug detection mechanisms
🟢Defence technologies
Now it represents Linux v5.12.
I added KASAN_HW_TAGS with ARM64_MTE, AUTOSLAB, KFENCE and many more
https://github.com/a13xp0p0v/linux-kernel-defence-map
GitHub GitHub - a13xp0p0v/linux-kernel-defence-map: Linux Kernel Defence Map shows the relationships between vulnerability classes, exploitation… Linux Kernel Defence Map shows the relationships between vulnerability classes, exploitation techniques, bug detection mechanisms, and defence technologies - a13xp0p0v/linux-kernel-defence-map
  • 🔥 1
Post #104 1.39K
Two DEF CON talks about eBPF-based rootkits

#1: "eBPF, I thought we were friends!" (video) by Guillaume Fournier and Sylvain Afchain
#2: "Warping Reality: Creating and Countering the Next Generation of Linux Rootkits" (video) by Pat Hogan

Both are about building a rootkit via malicious eBPF programs. The programs are constrained to what the verifier permits (i.e., no AARW), but the allowed functionality is enough to mess with userspace daemons for LPE and with network packets for C&C.
YouTube DEF CON 29 - Guillaume Fournier, Sylvain Afchain, Sylvain Baubeau - eBPF, I thought we were friends! Since its first appearance in Kernel 3.18, eBPF (Extended Berkley Packet Filter) has progressively become a key technology for observability in the Linux kernel. Initially dedicated to network monitoring, eBPF can now be used to monitor and trace any kind…
Post #102 1.13K
Post #98 7.54K
Post #97 1.33K
Sequoia: A deep root in Linux's filesystem layer (CVE-2021-33909)

Qualys security advisory about a size_t-to-int conversion vulnerability in the Linux kernel's filesystem layer.

By creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB, an unprivileged local attacker can write the 10-byte string "//deleted" to an offset of exactly -2GB-10B below the beginning of a vmalloc()ated kernel buffer.

Report: https://www.openwall.com/lists/oss-security/2021/07/20/1
Post #96 3.64K
CVE-2021-22555: Turning \x00\x00 into 10000$ by Andy Nguyen

CVE-2021-22555 is a 15 years old heap out-of-bounds write vulnerability in Linux Netfilter that is powerful enough to bypass all modern security mitigations and achieve kernel code execution. It was used to break the kubernetes pod isolation of the kCTF cluster and won 10000$.

https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html

Amazingly, Andy independently reinvented the msgsnd() exploitation technique, that I created in January for my CVE-2021-26708 exploit:
https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html
security-research CVE-2021-22555: Turning \x00\x00 into 10000$ This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Post #94 1.1K
Post #91 1.09K
CVE-2021–20226: a reference counting bug which leads to local privilege escalation in io_uring

An article describing a bug in the io_uring subsystem. Improper handling of files_struct references leading to a use-after-free.

https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
Medium CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring. Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
Post #90 2.85K
A Nerve-Racking Bug Collision in Samsung's NPU Driver

An exploit write-up by Gyorgy Miru for another bug in the Samsung NPU driver. Unlike the vmalloc-based exploits published by P0 and others, this one relies on a race condition leading to a slab-out-of-bounds write.

https://labs.taszk.io/articles/post/bug_collision_in_samsungs_npu_driver/
labs.taszk.io [BugTales] A Nerve-Racking Bug Collision in Samsung's NPU Driver Last summer I have discovered several vulnerabilities in the implementation of Samsung's NPU device driver. While I was working on completing my proof of concept exploit
Post #89 1K
Post #88 882
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →