Skip Navigation
Exploit Development @infosec.pub udunadan @infosec.pub

prctl anon_vma_name: An Amusing Linux Kernel Heap Spray

starlabs.sg prctl anon_vma_name: An Amusing Linux Kernel Heap Spray

TLDR prctl PR_SET_VMA (PR_SET_VMA_ANON_NAME) can be used as a (possibly new!) heap spray method targeting the kmalloc-8 to kmalloc-96 caches. The sprayed object, anon_vma_name, is dynamically sized, and can range from larger than 4 bytes to a maximum of 84 bytes. The object can be easily allocated a...

prctl anon_vma_name: An Amusing Linux Kernel Heap Spray
0
0 comments