This is exactly why copy_from_user and READ_ONCE etc exist -- more of a realistic vuln for Windows drivers (http://www.osronline.com/article.cfm?article=514 …) I would think than Linux (since UDEREF weeded these out over a decade ago, and later, SMAP). Still neat for a CTF though
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Notes: - SMAP is really important - emulated SMEP from KPTI is useful - booting with slab_nomerge keeps heap UAFs isolated
-
Switch jump table exploit is a good example of what can go wrong when one is sloppy about data races
@paulmckrcu "gcc considered harmful" Errrr NO! - 1 more reply
New conversation -
-
-
Well written and informative
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
This Tweet is unavailable.
-
This Tweet is unavailable.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.