oss-sec mailing list archives

Re: fwd: [vs-plain] Kernel heap overflow in bpf leading to LPE (exploit provided)


From: Yves-Alexis Perez <corsac () debian org>
Date: Sat, 24 Nov 2018 10:08:15 +0100

On Fri, 2018-11-23 at 21:45 +0100, Yves-Alexis Perez wrote:
On Fri, 2018-11-23 at 19:09 +0100, Greg KH wrote:
As was discussed further on one of the threads on this topic, it looks
like this is a 4.20-rc issue only, and that 4.19 does not have this
issue.  So it might not be relevant to any distro at all, but I suggest
that people test themselves to be sure.

Hi Greg, thanks for the precision.

And considering no released kernel is vulnerable, here is the proof of concept
code provided initially.

Regards,
-- 
Yves-Alexis

Attachment: exp.c
Description:

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: