TGViewer
Channel Public Channel
Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
Subscribers
4.72K
Photos
123
Videos
0
Links
356

Showing posts older than #193 · Back to latest

Older Posts 20 shown
Post #192 3.81K
How I started chasing speculative type confusion bugs in the kernel and ended up with 'real' ones

Jakob Koschel gave a talk (slides, video) at the Linux Plumbers Conference about the tool for discovering speculative type confusion bugs in the Linux kernel. He described how this research suddenly led to the kernel upgrading from C89 to C11.
  • 👍 12
  • 🔥 4
Post #189 4.54K
Sanitizing the Linux kernel: On KASAN and other Dynamic Bug-finding Tools

Slides from a talk by Andrey Konovalov about Sanitizers — a family of Linux kernel bug detectors.

The talk covers:

🐧 Implementation of the Generic mode of KASAN
🔥 Brief overview of other Sanitizers
🗡 Tips on extending KASAN and KMSAN to find more bugs
Google Docs 2022, LSS Europe: Sanitizing the Linux kernel Sanitizing the Linux kernel On KASAN and other Dynamic Bug-finding Tools Andrey Konovalov, xairy.io Linux Security Summit Europe September 16th 2022
  • 🔥 14
  • 👍 5
Post #187 3.19K
An exploit primitive in the Linux kernel inspired by DirtyPipe

A brief description of an exploitation technique inspired by the DirtyPipe vulnerability.

The technique works by overwriting the flags field of a pipe_buffer object with PIPE_BUF_FLAG_CAN_MERGE via a memory corruption. This allows changing the contents of an arbitrary read-only file via the splicing trick used by DirtyPipe.
GitHub GitHub - veritas501/pipe-primitive: An exploit primitive in linux kernel inspired by DirtyPipe An exploit primitive in linux kernel inspired by DirtyPipe - veritas501/pipe-primitive
  • 👍 2
Post #186 2.65K
E'rybody Gettin' TIPC: Demystifying Remote Linux Kernel Exploitation

A talk by Sam Page about attempts to exploit CVE-2022-0435, a remotely-triggerable stack overflow in the TIPC protocol.
Post #185 2.43K
Android Universal Root: Exploiting xPU Drivers

A talk about exploiting Android devices with PowerVR GPUs.
  • 👍 1
Post #184 2.27K
DirtyCred

A talk by Zhenpeng Lin about an exploitation technique for memory corruptions called DirtyCred.

The technique works by freeing an unprivileged credentials object via a memory corruption and allocating a privileged one in the same slot.
Post #183 2.67K
CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel

D3v17 published an article describing the solution of their corCTF challenge CoRJail.

The PoC exploit used a single null-byte out-of-bounds write to corrupt a poll_list object in the kmalloc-4k slab cache and obtain an arbitrary free primitive.

It allowed the researcher to corrupt a user_key_payload structure and get out-of-bounds read.

Finally the researcher used the arbitrary free primitive to corrupt a pipe_buffer structure and hijack the kernel control flow to escape the container.
[corCTF 2022] CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel CoRJail is a kernel exploitation challenge designed for corCTF 2022. Players were asked to escape from a hardened Docker container with custom seccomp filters exploiting a Off-By-Null vulnerability in a Linux Kernel Module accessible via procfs. With this…
  • 👍 7
  • 🔥 3
Post #182 2.27K
Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage

FizzBuzz101 published an article describing a solution of their corCTF challenge Cache of Castaways.

The PoC exploit implemented a cross cache overflow attack against cred structs in isolated slabs.
www.willsroot.io Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage Vulnerability Research on Low-Level Systems
  • 👍 4
Post #181 2.87K
CVE-2022-29582, an io_uring vulnerability

A detailed and well-written article by Awarau and David Bouman about exploiting a slab use-after-free vulnerability in the io_uring subsystem.

The exploit leverages a cross-cache attack and msg_msg spraying to overwrite a tls_context object and execute a ROP chain to gain root.
Computer security and related topics CVE-2022-29582 This post covers an interesting vulnerability we (Jayden and David) found in the io_uring subsystem of the Linux kernel.
  • 👍 4
  • 🔥 3
  • 🤯 2
Post #180 2.4K
The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I)

Xingyu Jin published an article describing the root cause of a race condition in the garbage collection for SCM_RIGHTS.

This bug is used for Android exploitation in the wild.
  • 👍 3
Post #178 3.15K
Corrupting memory without memory corruption

An article by Man Yue Mo about exploiting CVE-2022-20186, an integer overflow in the Arm Mali GPU driver.

The bug allows mapping arbitrary physical pages to the GPU memory with both read and write access. The exploit gets arbitrary kernel code execution on Pixel 6, disables SELinux, and gains root.
The GitHub Blog Corrupting memory without memory corruption In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights…
  • 👍 9
Post #177 2.61K
[CVE-2022-34918] A crack in the Linux firewall

An article by Arthur Mongodin about exploiting a slab-buffer-overflow in the netfilter subsystem.

The exploit uses the unlinking technique from Lam Jun Rong's io_uring exploit.
  • 👍 4
Post #176 2.81K
TripleCross

A Linux eBPF rootkit providing a backdoor with command and control (C2) capabilities, library injection, execution hijacking, persistence, and hiding.
  • 🔥 7
  • 👍 3
  • 🤔 1
Post #174 2.91K
The Android kernel mitigations obstacle race

A great article by Man Yue Mo about exploiting a race condition that leads to a use-after-free vulnerability in the Qualcomm GPU driver for Samsung Galaxy Z Flip3.

The researcher widened the race window to hit the bug reliably, and then bypassed kCFI, automatic variable initialization, and Samsung RKP in the exploit.
The GitHub Blog The Android kernel mitigations obstacle race In this post I’ll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I’ll look at various mitigations that are implemented on modern Android devices…
  • 👏 7
  • 🔥 1
Post #173 2.36K
io_uring - new code, new bugs, and a new exploit technique

Lam Jun Rong published an article that covers analyzing and exploiting CVE-2021-41073, an invalid-free vulnerability in the io_uring subsystem.

This vulnerability has previously been exploited by Valentina Palmiotti, but that exploit relied on eBPF. The new exploit targets Ubuntu 21.10, where eBPF is not available to unprivileged users.
  • 👍 3
Post #172 2.72K
Yet another bug into Netfilter

An article by Arthur Mongodin about exploiting an out-of-bounds access in the netfilter subsystem to achieve an info-leak. The article also suggests a potential approach to gain privilege escalation.
  • 👍 9
Post #171 2.27K
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →