3 ms·
I wrote a bit about it: https://blog.lizzie.io/notes-about-cve-2016-7117.html https://blog.lizzie.io/notes-about-cve-2016-7117.html tl;dr looks like it'd funct
by startling 10y ago
I wrote a bit about it: https://blog.lizzie.io/notes-about-cve-2016-7117.html https://blog.lizzie.io/notes-about-cve-2016-7117.html
tl;dr looks like it'd function well a local privilege exploit. not an expert, but as a remote exploit think it would need 1) a service running recvmmsg (which is kind of unlikely) 2) a way to cause recvmsg to error, and 3) a way to cause the service to close its socket in the middle of the recvmmsg call.
- vzcx 10y agoNice writeup! I was just starting to look into this since people were claiming it was pretty severe and yet I hadn't seen any POC's. Have you made any more progress? For whatever my opinion is worth (i.e. not much), I would agree with you that remote exploitation of this particular bug would be really difficult.