Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Unroll0201
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
Unroll0201
3y ago
Manual auditing ;-) I have specified it in https://pwning.tech/nftables#31-finding-the-bug
2.
▲
by
Unroll0201
3y ago
I'm a bit late, but it's because I wanted my exploit to be universal. When patching kernel .text I'd need know: - know the offset to the patched instructions (memory scanning will not work) - know the architecture-compatible
3.
▲
by
Unroll0201
3y ago
Thank you so much! It feels great to hear this.
4.
▲
by
Unroll0201
3y ago
The sysctl command isn't available on specific kernel configurations. You could try running `unshare -Urn`. If it runs without sudo (and you haven't configured any specific permissions yourself), unprivileged namespaces are enable
5.
▲
by
Unroll0201
3y ago
Is there a reason why you did this? I knowingly chose the other title because it would apply more to the Hackernews audience to raise more awareness of the exploit and that people should update. This title was aimed at the Linux kernel VR c
6.
▲
by
Unroll0201
3y ago
For me it is about the ethics among other things. I do not know to which goverments Zerodium is selling, much like any other zeroday broker. Additionally, I wouldn't be surprised if selling to Zerodium is illegal to begin with. By taki
7.
▲
by
Unroll0201
3y ago
This is an educated guess, but I believe unprivileged Docker containers cannot create (user) namespaces. Hence, the vulnerability cannot be triggered, since the exploit requires interaction with nf_tables, which requires (namespace) root. L
8.
▲
by
Unroll0201
3y ago
This is indeed expected. I specified in the "Caveats" section in README.md that the exploit does not work on Ubuntu v6.5 (because it enables a certain kernel config value that indirectly mitigates the exploit starting from v6.4),
9.
▲
by
Unroll0201
3y ago
The exploit support from v6.4 - v6.6 is depending on a Linux kernel kconfig value. If `CONFIG_INIT_ON_ALLOC_DEFAULT_ON` is set to `y`, the exploit is not working. If it is set to `n`, it does work. I have updated my comment.
10.
▲
by
Unroll0201
3y ago
The attack vectors are pretty much the same for other Linux kernel LPE exploits. The impact is also much alike: privilege escalation from unprivileged user to root user. Should be noted that the exploit can read/write any physical memo
11.
▲
by
Unroll0201
3y ago
Correct, but it is definitively worth updating for on high-profile systems. I have not tested it, but because I have included the namespace escape in the exploit for KernelCTF, it may be able to break out of LXC containers and privileged Do
12.
▲
by
Unroll0201
3y ago
Thanks for the notice. I will immediately fix it.
13.
▲
Flipping Pages: New Linux vulnerability in nf_tables and exploitation techniques
(pwning.tech)
406 points
by
Unroll0201
3y ago
|
120 comments
14.
▲
by
Unroll0201
3y ago
Today I published a proof-of-concept exploit for CVE-2024-1086, working on Debian and Ubuntu among others. The affected exploit versions are from Linux kernel v5.14 up to v6.6. The support for v6.4 to v6.6 is depending on the `CONFIG_INIT_O