MCPcopy Create free account

hub / github.com/bsauce/kernel-exploit-factory / functions

Functions847 in github.com/bsauce/kernel-exploit-factory

↓ 88 callersFunctionnetlink_attr
CVE-2022-27666/exploit/exploit.c:274
↓ 42 callersFunctionnetlink_done
CVE-2022-27666/exploit/exploit.c:292
↓ 38 callersFunctionget_time_ns
CVE-2026-23271/exploit/exploit.cpp:429
↓ 35 callersFunctionnetlink_nest
CVE-2022-27666/exploit/exploit.c:284
↓ 35 callersFunctionptr_to_u64
CVE-2020-8835/exp/exp_multi_core.c:254
↓ 33 callersFunctiondie
CVE-2021-4154/exploit/exploit-ROP.c:62
↓ 26 callersFunctiondebug
CVE-2017-6074/exp.c:64
↓ 26 callersFunctionerrExit
CVE-2022-0995/exploit.c:112
↓ 24 callersFunctionerror
CVE-2022-34918/exploit/exploit.c:30
↓ 17 callersFunctionerror
CVE-2022-1015/exploit/exploit.c:35
↓ 16 callersFunctionupdate_elem
CVE-2021-31440/exp/CVE-2021-31440.c:332
↓ 16 callersFunctionupdate_elem
CVE-2021-31440/exp/CVE-2021-31440_2.c:333
↓ 16 callersFunctionupdate_elem
CVE-2020-27194/exp/CVE-2020-27194.c:300
↓ 16 callersFunctionupdate_elem
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:335
↓ 15 callersFunctionsend_msg
CVE-2022-0185/exploit/util.c:48
↓ 14 callersFunctionpagealloc_pad
spray ring_buffer --- page fengshui
CVE-2022-27666/exploit/exploit.c:1241
↓ 14 callersFunctiontp_spin_delay_ns
CVE-2026-23271/exploit/exploit.cpp:492
↓ 13 callersFunctionmake_queue
CVE-2022-0185/exploit/util.c:18
↓ 13 callersFunctionnetlink_send
CVE-2022-27666/exploit/exploit.c:351
↓ 12 callersFunctionpagealloc_pad
CVE-2022-2639/exploit.c:759
↓ 12 callersFunctiontp_cpu_relax_once
CVE-2026-23271/exploit/exploit.cpp:483
↓ 11 callersFunctionMnl_socket_sendto
CVE-2025-21702/exploit/exploit.c:432
↓ 11 callersFunction__exit
CVE-2017-16995/exp.c:170
↓ 11 callersFunctionget_msg
CVE-2022-0185/exploit/util.c:36
↓ 11 callersFunctionvalidate_mnl_socket_operation_success
validate_mnl_socket_operation_success() - just receive msg and judge if socket operation success
CVE-2025-21702/exploit/exploit.c:579
↓ 10 callersFunctionaddattr_l
add attribute (maxlen limitation)
CVE-2022-2588/exploit.c:231
↓ 9 callersFunctionarbitrary_read
CVE-2020-8835/exp/exp_multi_core.c:466
↓ 9 callersFunctionfail
CVE-2021-31440/exp/CVE-2021-31440.c:110
↓ 9 callersFunctionfail
CVE-2021-31440/exp/CVE-2021-31440_2.c:110
↓ 9 callersFunctionfail
CVE-2020-27194/exp/CVE-2020-27194.c:91
↓ 9 callersFunctionfail
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:110
↓ 9 callersFunctionkernel_read
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/exploit.c:80
↓ 9 callersFunctionnetlink_device_change
CVE-2022-27666/exploit/exploit.c:535
↓ 9 callersFunctiontrigger_qdisc_enqueue
trigger_qdisc_enqueue() - send empty msghdr
CVE-2025-21702/exploit/exploit.c:611
↓ 9 callersFunctionudp_fifo_init
CVE-2017-6074/exp.c:205
↓ 9 callersFunctionunix_error
CVE-2025-21702/exploit/exploit.c:400
↓ 8 callersFunctionnetlink_add_device_impl
CVE-2022-27666/exploit/exploit.c:397
↓ 8 callersFunctionnetlink_init
CVE-2022-27666/exploit/exploit.c:263
↓ 8 callersFunctionpin_on_cpu
set cpu affinity
CVE-2022-2588/exploit.c:113
↓ 8 callersFunctionset_nested_attr
set_nested_attr(): Prepare a nested netlink attribute
CVE-2022-34918/exploit/exploit.c:409
↓ 8 callersFunctionstuff_4k
free count msg_msg
CVE-2022-0185/exploit/exploit_kctf.c:107
↓ 8 callersFunctionudp_fifo_kmalloc
heap spray
CVE-2017-6074/exp.c:218
↓ 7 callersFunctiondo_error_exit
CVE-2022-32250/exploit/exploit.c:139
↓ 7 callersFunctioninitialise_shared
CVE-2022-27666/exploit/exploit.c:1217
↓ 7 callersFunctionnetlink_add_veth
CVE-2022-27666/exploit/exploit.c:420
↓ 7 callersFunctionread64
abitary read 64 bytes: 利用 bpf_obj_get_info_by_fd 读取两个4字节并拼接到一起
CVE-2021-31440/exp/CVE-2021-31440.c:348
↓ 7 callersFunctionread64
abitary read 64 bytes: 利用 bpf_obj_get_info_by_fd 读取两个4字节并拼接到一起
CVE-2021-31440/exp/CVE-2021-31440_2.c:349
↓ 7 callersFunctionread64
CVE-2020-27194/exp/CVE-2020-27194.c:316
↓ 7 callersFunctionread64
abitary read 64 bytes: 利用 bpf_obj_get_info_by_fd 读取两个4字节并拼接到一起
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:351
↓ 7 callersFunctionset_u32_attr
set_u32_attr(): Prepare an integer netlink attribute
CVE-2022-34918/exploit/exploit.c:416
↓ 6 callersFunction__exit
CVE-2020-8835/exp/exp_multi_core.c:333
↓ 6 callersFunction__exit
CVE-2020-8835/exp/exp_single_core.c:331
↓ 6 callersFunctionaddattr_nest
CVE-2022-2588/exploit.c:248
↓ 6 callersFunctionaddattr_nest_end
CVE-2022-2588/exploit.c:255
↓ 6 callersFunctionbye
CVE-2022-32250/exploit/exploit.c:133
↓ 6 callersFunctionchange_hfsc_qdisc_route
CVE-2025-21702/exploit/exploit.c:787
↓ 6 callersFunctiondo_futex
CVE-2026-23271/exploit/exploit.cpp:422
↓ 6 callersFunctionnla_total_size
CVE-2022-2639/exploit.c:62
↓ 6 callersFunctionperf_event_open
CVE-2026-23271/exploit/exploit.cpp:416
↓ 6 callersFunctionsend_batch_request
send_batch_request() —— send request
CVE-2022-1015/exploit/helpers.c:44
↓ 6 callersFunctionset_trigger_set_and_overwrite
set_trigger_set_and_overwrite() —— create vulnerable expression
CVE-2022-32250/exploit/exploit.c:276
↓ 6 callersFunctionuser_key_payload_alloc
CVE-2025-21702/exploit/exploit.c:856
↓ 6 callersFunctionuser_synchronize_rcu
用户态 RCU 同步: 通过 membarrier 系统调用强制所有 CPU 执行内存屏障 这确保 RCU callbacks 在已调度过的 CPU 上被处理,加速 RCU 宽限期完成 关键作用: 确保 call_rcu(free_event_rcu) 的回调被执行,事件 A 内存真正释放
CVE-2026-23271/exploit/exploit.cpp:1738
↓ 6 callersFunctionwrite_msg
write_msg() —— trigger to execute eBPF code
CVE-2021-31440/exp/CVE-2021-31440.c:317
↓ 6 callersFunctionwrite_msg
write_msg() —— trigger to execute eBPF code
CVE-2021-31440/exp/CVE-2021-31440_2.c:318
↓ 6 callersFunctionwrite_msg
CVE-2020-27194/exp/CVE-2020-27194.c:285
↓ 6 callersFunctionwrite_msg
write_msg() —— trigger to execute eBPF code
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:320
↓ 5 callersFunctionadd_tc_basic
spray spray_count objects ???
CVE-2022-2588/exploit.c:402
↓ 5 callersFunctionbpf
CVE-2021-41073/exploit/bpf.c:11
↓ 5 callersFunctionbpf
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/bpf.c:9
↓ 5 callersFunctionbpf_update_elem
CVE-2020-8835/exp/exp_multi_core.c:293
↓ 5 callersFunctionbpf_update_elem
CVE-2020-8835/exp/exp_single_core.c:291
↓ 5 callersFunctioncreate_hfsc_class
CVE-2025-21702/exploit/exploit.c:723
↓ 5 callersFunctioncreate_pfifo_head_drop_qdisc
CVE-2025-21702/exploit/exploit.c:799
↓ 5 callersFunctiondelete_tc_basic
CVE-2022-2588/exploit.c:474
↓ 5 callersFunctionkernel_write_uint
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/exploit.c:102
↓ 5 callersFunctionmsg_spray
create $num_msg message queue and each send $loop msg_msg
CVE-2022-27666/exploit/exploit.c:185
↓ 5 callersFunctionprep_setxattr
CVE-2021-41073/exploit/exploit.c:186
↓ 5 callersFunctionrun_bpf_prog
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/bpf.c:64
↓ 5 callersFunctionset_str8_attr
set_str8_attr(): Prepare a 8 bytes long string netlink attribute @name: Buffer to copy into the attribute
CVE-2022-34918/exploit/exploit.c:435
↓ 5 callersFunctiontp_taint_warn_bit_set
CVE-2026-23271/exploit/exploit.cpp:562
↓ 5 callersFunctionudp_fifo_kfree
CVE-2017-6074/exp.c:235
↓ 5 callersFunctionupdate_map_element
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/bpf.c:23
↓ 4 callersFunctionCalloc
CVE-2025-21702/exploit/exploit.c:510
↓ 4 callersFunctionStrdup
CVE-2025-21702/exploit/exploit.c:518
↓ 4 callersFunctionadd_tc_
spray 1 vulnerable object (filter) with customized flags
CVE-2022-2588/exploit.c:293
↓ 4 callersFunctionbind_to_cpu
CVE-2026-23271/exploit/exploit.cpp:1677
↓ 4 callersFunctionbuild_rule
CVE-2022-1015/exploit/helpers.c:133
↓ 4 callersFunctiongen_tipc_hdr
tipc packet routines gen_tipc_hdr() —— 构造 tipc 消息头 (tipc_msg 结构)
CVE-2021-43267/exp1.c:276
↓ 4 callersFunctionget_msg
CVE-2022-25636/exploit/exploit.c:86
↓ 4 callersFunctionkeyutils_error
CVE-2025-21702/exploit/exploit.c:412
↓ 4 callersFunctionmnl_socket_error
CVE-2025-21702/exploit/exploit.c:406
↓ 4 callersFunctionmsg_recv
CVE-2021-4154/exploit/exploit-ROP.c:267
↓ 4 callersFunctionnla_attr_size
CVE-2022-2639/exploit.c:58
↓ 4 callersFunctionread_8byte
CVE-2020-8835/exp/exp_multi_core.c:482
↓ 4 callersFunctionread_8byte
CVE-2020-8835/exp/exp_single_core.c:480
↓ 4 callersFunctionrelease_partial_uring
release_partial_uring() —— release 1 `percpu_ref_data`
CVE-2022-32250/exploit/exploit.c:382
↓ 4 callersFunctionrule_add_payload
CVE-2022-1015/exploit/helpers.c:181
↓ 4 callersFunctionset_stable_table_and_set
set_stable_table_and_set() —— allocate a table and set
CVE-2022-32250/exploit/exploit.c:216
↓ 4 callersFunctionspray_skbuff
CVE-2021-22555/exploit.c:205
next →1–100 of 847, ranked by callers