3 ms·
But is the security Bug exploitable in any realistic way?
by lafar6502 9y ago
But is the security Bug exploitable in any realistic way?
- blattimwind 9y agohttps://twitter.com/brainsmoke/status/948561799875502080 https://twitter.com/brainsmoke/status/948561799875502080
- cypherpunks01 9y agoWhat does that output mean? He was able to look up an address that was used in a speculative execution or something?
- blattimwind 9y agoHe successfully read from kernel memory, the first two bytes from the syscall table to be precise. The first entry is sys_read (on x86-64 anyway) and the first field is the address. That's why he shows the full address in the next line; the PoC exploit read the lower 2 bytes of that address.