logo

MidnightsunQuals 2021 BroHammer Writeup (Single Bit Flip to Kernel Privilege Escalation)

ID: 4a9fc071-9935-5092-9251-f0eb73f797fe

STIX ID: report--4a9fc071-9935-5092-9251-f0eb73f797fe

Feed Name: Will's Root

Threat Score
35/100

Date Published: 2021-04-13

Date Updated: 2026-04-19

Author: Unknown

...
...

This is a concise CTF writeup detailing a kernel privilege-escalation exploit named “brohammer” that uses an arbitrary one-bit-flip syscall to alter x86_64 page-table entry bits via the physmap direct mapping. The author describes 4-level paging, targeted flipping of U/S and R/W bits to obtain user-mode write access over kernel page tables, and overwrites a kernel function to execute commit_creds(init_cred) for privilege escalation, noting environmental caveats like KASLR/SMEP/SMAP being disabled and TLB caching differences in QEMU.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.