logo

corCTF 2023 sysruption - Exploiting Sysret on Linux in 2023

ID: 51032df2-6296-524d-bf48-ed8f3d4b3334

STIX ID: report--51032df2-6296-524d-bf48-ed8f3d4b3334

Feed Name: Will's Root

Threat Score
60/100

Date Published: 2023-08-03

Date Updated: 2026-04-19

Author: Unknown

...
...

This corCTF 2023 writeup describes the "sysruption" challenge: a detailed exploit chain that revives a historic SYSRET/GPF micro-architectural/kernel issue on modern Linux. The author reverts an earlier kernel check, uses a prefetch (µarch) attack to leak kernel/physmap/gsbase values despite KASLR, and combines a ptrace-based non-canonical return PoC with ROP and kernel function-pointer overwrites (tcp_prot) to escalate to root; the report includes full PoC source and exploitation notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.