TGViewer
Channel Public Channel
Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
Subscribers
4.72K
Photos
122
Videos
0
Links
355

Showing posts older than #295 · Back to latest

Older Posts 17 shown
Post #294 3.83K
Patch-Gapping the Google Container-Optimized OS for $0

Detailed article by h0mbre about exploiting a slab use-after-free in the network scheduler subsystem to target the COS 105 kernelCTF instance.
  • 🔥 10
  • 👍 2
Post #293 3.94K
Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)

Article by Ng Zhi Yang about exploiting a logical bug in the Arm Mali GPU driver discovered a few years ago.

The bug allows gaining write permissions to a read-only memory region. The article explains how to exploit this bug from the untrusted_app context on Pixel 6 to load an arbitrary kernel module to disable SELinux and spawn a root reverse shell.
  • 🔥 6
  • 🤯 5
  • 👍 4
Post #292 3.75K
Accidentally uncovering a seven years old vulnerability in the Linux kernel

Article by Anderson Nascimento about finding and analyzing a slab use-after-free vulnerability in the TCP sockets implementation.
  • 🔥 23
  • 👍 2
Post #290 4.95K
ksmbd vulnerability research

Article by Norbert Szetei about fuzzing the ksmbd module with syzkaller and finding a few memory corruption vulnerabilities.
  • 🔥 9
  • 👍 6
Post #288 4.71K
KernelSnitch: Side-Channel Attacks on Kernel Data Structures

Paper by Lukas Maar et al. about using a timing side-channel for leaking addresses of exploitation-relevant kernel structures.
  • 👍 16
  • 🔥 5
Post #285 4.95K
The Qualcomm DSP Driver — Unexpectedly Excavating an Exploit

An article by Seth Jenkins about investigating kernel crash logs produced by an In-The-Wild exploit that targeted the adsprpc Qualcomm driver and finding several vulnerabities in that driver.
  • 👍 10
  • 🔥 1
Post #284 3.95K
Bootkitty: Analyzing the first UEFI bootkit for Linux

Martin Smolár and Peter Strýček published a report about a PoC UEFI bootkit targeting Linux systems. The bootkit patches GRUB, disables the signature checking for Linux kernel modules, and loads malicious userspace libraries into the init process.

This bootkit turned out to be created by Korean cybersecurity students.
  • 👍 13
Post #282 10.7K
Diving into Linux kernel security

Alexander Popov (me) published his H2HC talk slides that describe how to get started with learning Linux kernel security and knowingly configure the security parameters of Linux-based systems.
  • 🔥 49
  • 👍 10
  • 😱 1
Post #281 4.5K
OtterRoot: Netfilter Universal Root 1-day

An article by Pedro Pinto about exploiting a slab double-free bug in the netfilter subsystem.

Pedro wrote two exploits for this bug: one that relies on ROP and that was used to exploit a kernelCTF instance, and the other that gets physical memory arbitrary read/write without relying on any offsets.
OtterSec OtterRoot: Netfilter universal root 1-day A peek into the state of Linux kernel security and the open-source patch-gap. We explore how we monitored commits to find new bug fixes and achieved 0day-like capabilities by exploiting a 1-day vulnerability.
  • 🔥 14
  • 👍 1
Post #280 3.95K
Novel approach to exploit a limited OOB on Ubuntu at Pwn2Own Vancouver 2024

Slides from a talk by Pumpkin Chang about exploiting a stack out-of-bounds write bug in the traffic control subsystem.

Pumpkin shaped vmalloc memory to make the stack out-of-bounds access land in an eBPF bytecode allocation and used the write primitive to overwrite the eBPF bytecode as it was being JITed.
  • 🔥 10
  • 🤯 4
  • 👏 2
  • 👍 1
  • 😱 1
Post #279 3.92K
Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels

An outstanding paper by Lukas Maar et al. about analyzing the exploitation techniques used in public 1-day Android kernel exploits over the last few years and cross-referencing them with the mitigations implemented by various Android vendors 🔥
  • 👍 9
  • 🔥 2
Post #277 3.66K
Restricting Unprivileged User Namespaces In Ubuntu

A talk (video) by John Johansen and Maxime Bélair about restricting capabilities within user namespaces in Ubuntu 24.04.
  • 👍 9
  • 🤯 1
Post #276 3.39K
Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel

A talk (video) by Mingi Cho and Wongi Lee about exploiting a slab use-after-free bug in the netfilter subsystem and an out-of-bounds bug in the traffic control subsystem.

The researchers managed to exploit both bugs on the kernelCTF migitation instance. Notably, they relied on cross-CPU slab/page_alloc shaping techniques in both exploits.
  • 🔥 14
Post #275 4.06K
Unleashing a 0day: Pivoting Capabilities and Conquering the Linux Kernel

A talk (video) by Pedro Pinto about exploiting a slab use-after-free bug in the traffic control subsystem.

The author performed multiple cross-cache attacks to ultimately get an arbitrary read/write primitive via pipe_buffer->page and escalate privileges via modprobe_path.

Pedro also shared his experience submitting this bug to the KernelCTF bug bounty program.
  • 🔥 18
  • 👍 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →