corCTF 2023 sysruption - Exploiting Sysret on Linux in 2023
ID: 51032df2-6296-524d-bf48-ed8f3d4b3334
STIX ID: report--51032df2-6296-524d-bf48-ed8f3d4b3334
Feed Name: Will's Root
This corCTF 2023 writeup describes the "sysruption" challenge: a detailed exploit chain that revives a historic SYSRET/GPF micro-architectural/kernel issue on modern Linux. The author reverts an earlier kernel check, uses a prefetch (µarch) attack to leak kernel/physmap/gsbase values despite KASLR, and combines a ptrace-based non-canonical return PoC with ROP and kernel function-pointer overwrites (tcp_prot) to escalate to root; the report includes full PoC source and exploitation notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
