Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
accessvector
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
FreeBSD 11.0 Kernel LPE: Userspace Mutexes (Umtx) Use-After-Free Race Condition
(accessvector.net)
2 points
by
accessvector
2y ago
|
0 comments
2.
▲
by
accessvector
3y ago
Richard StaLLMan?
3.
▲
by
accessvector
3y ago
Thanks for your work in making an excellent tool; I, and many of my coworkers, use this. The price point is entirely fair and it’s a pleasure to use every time. But - above this - thank you also for prioritising personal life above developm
4.
▲
Sync *nix machine datetime behind HTTP(S) proxies
(echodate.org)
2 points
by
accessvector
3y ago
|
0 comments
5.
▲
by
accessvector
3y ago
I started programming with QBASIC at about 10 years old, too, after randomly coming across a book called “Practise Your BASIC”. It’s a great book and Usborne recently released it for free: https://usborne.com/gb/books&#
6.
▲
by
accessvector
3y ago
Right, so this is the crux of the vulnerability. Firstly, note that the `MAX` macro is defined as: #define MAX(a, b) ((a) > (b) ? (a) : (b)) This is important because it doesn't cast either arg to any particular type. You
7.
▲
by
accessvector
3y ago
Consider this: struct pinsyscall entries[] = { { .sysno = 1, .offset = 0x1234 }, { .sysno = 2, .offset = 0x5678 }, { .sysno = 1, .offset = 0x9abc } }; Now `nsyscalls` will be 3 and `pin` will be an array
8.
▲
by
accessvector
3y ago
Just to handle the case where the same syscall number is specified twice by the ELF header: in that case, the entry is set to -1 (presumably meaning it’s invalid).
9.
▲
by
accessvector
3y ago
Re-reading this, my analysis is slightly incorrect: the `MAX` at [5] with an unsigned arg means we can make `npins` an arbitrary `int` using the loop at [4]. Choosing to make `npins` negative using that loop means we'll end up allocati
10.
▲
by
accessvector
3y ago
Out-of-bounds heap write happens in this function: int elf_read_pintable(struct proc *p, Elf_Phdr *pp, struct vnode *vp, Elf_Ehdr *eh, uint **pinp) { struct pinsyscalls { u_int offset
11.
▲
by
accessvector
3y ago
Spoiler for anyone else that got excited: nothing new has been published.
12.
▲
Shelltpl – super simple shell templating
(github.com)
1 points
by
accessvector
3y ago
|
0 comments
13.
▲
Sudoedit can edit arbitrary files
(seclists.org)
109 points
by
accessvector
4y ago
|
55 comments
14.
▲
Crash Override: NetBSD 5.0-9.3 Coredump Kernel Refcount LPE
(accessvector.net)
7 points
by
accessvector
4y ago
|
0 comments
15.
▲
Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free
(accessvector.net)
1 points
by
accessvector
4y ago
|
1 comments
16.
▲
by
accessvector
4y ago
A pretty boring (non-exploitable) yet widespread use-after-free vulnerability that was recently patched and affected Linux kernels since ~2013. It involves a race condition between the exit path for a process and /proc/<pid>
17.
▲
FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug
(accessvector.net)
3 points
by
accessvector
4y ago
|
0 comments