MCPcopy Create free account

hub / github.com/bsauce/kernel-exploit-factory / functions

Functions847 in github.com/bsauce/kernel-exploit-factory

↓ 4 callersFunctionspray_skbuff
CVE-2022-0995/exploit.c:146
↓ 4 callersFunctiontipc_send
CVE-2021-43267/exp1.c:290
↓ 4 callersFunctiontp_read_kernel_tainted
CVE-2026-23271/exploit/exploit.cpp:540
↓ 4 callersFunctiontp_set_thread_affinity
将当前线程绑定到指定的 CPU 核心 (用于控制并发执行)
CVE-2026-23271/exploit/exploit.cpp:505
↓ 4 callersFunctionuser_key_payload_free
CVE-2025-21702/exploit/exploit.c:870
↓ 4 callersFunctionwrite_file
CVE-2022-27666/exploit/exploit.c:236
↓ 3 callersFunctionMnl_socket_open
CVE-2025-21702/exploit/exploit.c:418
↓ 3 callersFunctionSocket
CVE-2025-21702/exploit/exploit.c:502
↓ 3 callersFunctionaddattr
add attribute
CVE-2022-2588/exploit.c:220
↓ 3 callersFunctionadjust_rlimit
setup process memory
CVE-2022-2588/exploit.c:157
↓ 3 callersFunctionbuildMsg
CVE-2022-0995/exploit.c:134
↓ 3 callersFunctionbuild_msg_msg
CVE-2021-22555/exploit.c:169
↓ 3 callersFunctioncalc_vuln_expr_params
CVE-2022-1015/exploit/exploit.c:92
↓ 3 callersFunctioncreate_chain
CVE-2022-1015/exploit/helpers.c:246
↓ 3 callersFunctiondelete_tclass
CVE-2025-21702/exploit/exploit.c:840
↓ 3 callersFunctionexit_err
CVE-2023-2598/exploit.c:99
↓ 3 callersFunctiongenlmsg_alloc
genlmsg_alloc() —— alloc a buffer with len (genlmsg)
CVE-2022-2639/exploit.c:92
↓ 3 callersFunctiongenlmsg_free
CVE-2022-2639/exploit.c:128
↓ 3 callersFunctionget_batch_begin_nlmsg
get_batch_begin_nlmsg(): Construct a BATCH_BEGIN message for the netfilter netlink
CVE-2022-34918/exploit/exploit.c:373
↓ 3 callersFunctionget_batch_end_nlmsg
get_batch_end_nlmsg(): Construct a BATCH_END message for the netfilter netlink
CVE-2022-34918/exploit/exploit.c:393
↓ 3 callersFunctionheap_read_primitive_reset
network interface & `user_key_payload`
CVE-2025-21702/exploit/exploit.c:1401
↓ 3 callersFunctionnetlink_add_linked
CVE-2022-27666/exploit/exploit.c:452
↓ 3 callersFunctionnetlink_send_ext
CVE-2022-27666/exploit/exploit.c:298
↓ 3 callersFunctionoob_write
CVE-2022-27666/exploit/exploit.c:1365
↓ 3 callersFunctionpacket_sock_kmalloc
(1-1) 消耗 kmalloc-2048
CVE-2017-7308/exploit.c:156
↓ 3 callersFunctionpeekMsg
CVE-2022-0995/exploit.c:129
↓ 3 callersFunctionpeek_msg
CVE-2021-22555/exploit.c:188
↓ 3 callersFunctionprepare_final_release_payload_xdk
将伪造 perf_event payload (含 ROP 链) 写入 msg_msgseg 的正确偏移位置 seg_start_rel_to_event: 分段起始位置相对于 perf_event 起始位置的偏移 用于处理 perf_event (0x520) 跨越两个 msg_msgseg (0
CVE-2026-23271/exploit/exploit.cpp:2119
↓ 3 callersFunctionptr_to_u64
CVE-2020-8835/exp/exp_single_core.c:252
↓ 3 callersFunctionreadMsg
CVE-2022-0995/exploit.c:118
↓ 3 callersFunctionread_msg
CVE-2021-22555/exploit.c:197
↓ 3 callersFunctionredact
CVE-2021-31440/exp/CVE-2021-31440.c:120
↓ 3 callersFunctionredact
CVE-2021-31440/exp/CVE-2021-31440_2.c:120
↓ 3 callersFunctionredact
CVE-2020-27194/exp/CVE-2020-27194.c:101
↓ 3 callersFunctionredact
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:120
↓ 3 callersFunctionrelease_spray_4k_lock
wait for spray_4k_thread()
CVE-2022-27666/exploit/exploit.c:1273
↓ 3 callersFunctionrule_add_cmp
CVE-2022-1015/exploit/helpers.c:194
↓ 3 callersFunctionset_binary_attr
set_binary_attr(): Prepare a byte array netlink attribute @buffer: Buffer with data to send @buffer_size: Size of the previous buffer
CVE-2022-34918/exploit/exploit.c:446
↓ 3 callersFunctiontp_set_thread_sched_best_effort
CVE-2026-23271/exploit/exploit.cpp:517
↓ 3 callersFunctionuser_key_payload_read
CVE-2025-21702/exploit/exploit.c:889
↓ 3 callersFunctionwrite32
CVE-2021-31440/exp/CVE-2021-31440.c:377
↓ 3 callersFunctionwrite32
CVE-2021-31440/exp/CVE-2021-31440_2.c:378
↓ 3 callersFunctionwrite32
CVE-2020-27194/exp/CVE-2020-27194.c:345
↓ 3 callersFunctionwrite32
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:380
↓ 3 callersFunctionwrite64
CVE-2021-43267/exp1.c:113
↓ 3 callersFunctionwrite_file
write_file(): Write a string into a file
CVE-2022-34918/exploit/exploit.c:40
↓ 3 callersFunctionwrite_file
CVE-2017-6074/exp.c:607
↓ 3 callersFunctionwrite_file
CVE-2017-1000112/exp.c:188
↓ 3 callersFunctionwrite_file
CVE-2017-7308/exploit.c:329
↓ 3 callersFunctionwrite_file
CVE-2022-2588/exploit.c:123
↓ 3 callersFunctionwrite_string_to_file
CVE-2025-21702/exploit/exploit.c:546
↓ 2 callersFunctionKeyctl_unlink
CVE-2025-21702/exploit/exploit.c:456
↓ 2 callersFunctionMnl_socket_bind
CVE-2025-21702/exploit/exploit.c:426
↓ 2 callersFunctionMnl_socket_recvfrom
CVE-2025-21702/exploit/exploit.c:440
↓ 2 callersFunction__read
CVE-2017-16995/exp.c:228
↓ 2 callersFunctionadd_elem_to_set
add_elem_to_set(): Trigger OOB * @sock: Socket used to communicate throught the netfilter netlink * @set_name: Name of the set to add the element *
CVE-2022-34918/exploit/exploit.c:627
↓ 2 callersFunctionadd_key
CVE-2022-34918/exploit/exploit.c:182
↓ 2 callersFunctionadd_key
CVE-2022-32250/exploit/exploit.c:125
↓ 2 callersFunctionadd_qdisc
add_qdisc() —— setup the socket
CVE-2022-2588/exploit.c:260
↓ 2 callersFunctionarbitrary_read
CVE-2020-8835/exp/exp_single_core.c:464
↓ 2 callersFunctionbpf_create_map
CVE-2020-8835/exp/exp_multi_core.c:280
↓ 2 callersFunctionbpf_create_map
CVE-2020-8835/exp/exp_single_core.c:278
↓ 2 callersFunctionbpf_obj_get_info_by_fd
CVE-2021-31440/exp/CVE-2021-31440.c:157
↓ 2 callersFunctionbpf_obj_get_info_by_fd
CVE-2021-31440/exp/CVE-2021-31440_2.c:157
↓ 2 callersFunctionbpf_obj_get_info_by_fd
CVE-2020-27194/exp/CVE-2020-27194.c:138
↓ 2 callersFunctionbpf_obj_get_info_by_fd
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:157
↓ 2 callersFunctionbpf_update_elem
CVE-2021-31440/exp/CVE-2021-31440.c:178
↓ 2 callersFunctionbpf_update_elem
CVE-2021-31440/exp/CVE-2021-31440_2.c:178
↓ 2 callersFunctionbpf_update_elem
CVE-2020-27194/exp/CVE-2020-27194.c:159
↓ 2 callersFunctionbpf_update_elem
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:178
↓ 2 callersFunctionchange_hfsc_class
CVE-2025-21702/exploit/exploit.c:755
↓ 2 callersFunctionclean_msq_1
release msg_msg in queue1
CVE-2022-2639/exploit.c:655
↓ 2 callersFunctionclean_msq_2
CVE-2022-2639/exploit.c:660
↓ 2 callersFunctionclose_queue
CVE-2021-42008/exp.c:641
↓ 2 callersFunctioncreate_dummy_network_interface
CVE-2025-21702/exploit/exploit.c:641
↓ 2 callersFunctioncreate_hfsc_qdisc
CVE-2025-21702/exploit/exploit.c:675
↓ 2 callersFunctioncreate_map
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/bpf.c:14
↓ 2 callersFunctioncreate_set
create_set(): Create a netfilter set * @sock: Socket used to communicate throught the netfilter netlink * @set_name: Name of the created set * @set
CVE-2022-34918/exploit/exploit.c:530
↓ 2 callersFunctiondccp_init
init dccp client and server
CVE-2017-6074/exp.c:139
↓ 2 callersFunctiondccp_kfree_again
second free skb
CVE-2017-6074/exp.c:187
↓ 2 callersFunctiondccp_kmalloc_kfree
first free skb?
CVE-2017-6074/exp.c:179
↓ 2 callersFunctiondelete_qdisc
CVE-2025-21702/exploit/exploit.c:824
↓ 2 callersFunctiondeplete_4k
release all msg_msg in kmalloc-4k
CVE-2022-0185/exploit/exploit_kctf.c:122
↓ 2 callersFunctiondie
CVE-2021-4154/exploit/exploit-DirtyCred.c:34
↓ 2 callersFunctiondo_heap_leak
do_heap_leak() —— leak heap address of net_device
CVE-2022-25636/exploit/exploit.c:252
↓ 2 callersFunctionentry_to_node
CVE-2021-3490/exp/5.11.16/Linux_LPE_eBPF_CVE-2021-3490-main/kmem_search.c:29
↓ 2 callersFunctionfree_skbuff
CVE-2021-22555/exploit.c:217
↓ 2 callersFunctionfree_skbuff
CVE-2022-0995/exploit.c:156
↓ 2 callersFunctiongenerate_payload
generate_payload() —— construct payload and encode it
CVE-2021-42008/exp.c:531
↓ 2 callersFunctiongenlmsg_get_family_id
CVE-2022-2639/exploit.c:268
↓ 2 callersFunctionget_elem
CVE-2021-31440/exp/CVE-2021-31440.c:339
↓ 2 callersFunctionget_elem
CVE-2021-31440/exp/CVE-2021-31440_2.c:340
↓ 2 callersFunctionget_elem
CVE-2020-27194/exp/CVE-2020-27194.c:307
↓ 2 callersFunctionget_elem
CVE-2021-3490/exp/5.11/CVE-2021-3490.c:342
↓ 2 callersFunctionget_kernel_sym
CVE-2017-5123/exp/exploit_null_ptr.c:38
↓ 2 callersFunctionget_value
CVE-2017-16995/exp.c:213
↓ 2 callersFunctioninit_fuse_mem
open fuse and mmap to a address, wait to trigger page fault
CVE-2022-27666/exploit/exploit.c:1308
↓ 2 callersFunctionkeyctl
CVE-2022-34918/exploit/exploit.c:186
↓ 2 callersFunctionkmalloc_pad
pad: 4 dccp connect + 4 af_packet + 128 udp send
CVE-2017-6074/exp.c:377
↓ 2 callersFunctionkmalloc_warm
CVE-2017-6074/exp.c:401
← previousnext →101–200 of 847, ranked by callers