Linux Kernel Slab Out-Of-Bounds Write ≈ Packet Storm

Home[1] Files[2] News[3] Contact[4] Add New[5]

Linux Kernel Slab Out-Of-Bounds Write[6]
Authored by Crusaders of Rust[7] | Site github.com[8]

This archive contains demo exploits for CVE-2022-0185. There are two versions here. The non-kctf version (fuse version) specifically targets Ubuntu with kernel version 5.11.0-44. It does not directly return a root shell, but makes /bin/bash suid, which will lead to trivial privilege escalation. Adjusting the single_start and modprobe_path offsets should allow it to work on most other Ubuntu versions that have kernel version 5.7 or higher; for versions between 5.1 and 5.7, the spray will need to be improved as in the kctf version. The exploitation strategy relies on FUSE and SYSVIPC elastic objects to achieve arbitrary write. The kctf version achieves code execution as the root user in the root namespace, but has at most 50% reliability - it is targeted towards Kubernetes 1.22 (1.22.3-gke.700). This exploitation strategy relies on pipes and SYSVIPC elastic objects to trigger a stack pivot and execute a ROP chain in kernelspace.

systems | linux[9], ubuntu[10]
advisories | CVE-2022-0185[11]
MD5 | bb5c8ef222c6b344deefbde1bb368f2d

Login[15] or Register[16] to add favorites

File Archive:

January 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services[120]
Hosting By
Rokasec[121]
close

Read more

Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"