oss-sec mailing list archives

Re: Linux Kernel: local priv escalation via futexes


From: Solar Designer <solar () openwall com>
Date: Mon, 1 Feb 2021 20:24:39 +0100

On Fri, Jan 29, 2021 at 06:01:11PM +0100, Marcus Meissner wrote:
Mitre has now assigned CVE-2021-3347.

FWIW, here's a recent writeup and exploit for a different futex
vulnerability:

https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html
https://github.com/elongl/CVE-2014-3153

Might help someone get into futexes... and exploiting their bugs.

Alexander


Current thread: