3 ms·
It's been done before, for example the "BadIRET" vulnerability (CVE-2015-5675) was used to jailbreak FreeBSD on the PS4 a couple of years ago.
by rrttt 9y ago
It's been done before, for example the "BadIRET" vulnerability (CVE-2015-5675) was used to jailbreak FreeBSD on the PS4 a couple of years ago.
- X86BSD 9y agoActually it hasn't been done before. That CVE required elevated privelages on the host already. They didn't break out of a jail.
- rrttt 9y agoThey did break out of a jail, the vulnerability was used to gain arbitrary code execution in kernel mode, which was used to modify the cr_prison structure, thus performing a jailbreak.
- X86BSD 9y agoAgain, they already had elevated or root privs. If you've already got root privs nothing will save you.
- rrttt 9y agoThey had root inside a jail, which isn't the same as being root outside the jail. To be able to gain arbitrary code execution in kernel mode from a jail is a security vulnerability.