logo

DiceCTF 2021 HashBrown Writeup: From Kernel Module Hashmap Resize Race Condition to FG-KASLR Bypass

ID: 6d001d54-07f3-5f8b-9413-2c87e4c30256

STIX ID: report--6d001d54-07f3-5f8b-9413-2c87e4c30256

Feed Name: Will's Root

Threat Score
65/100

Date Published: 2021-02-08

Date Updated: 2026-04-19

Author: Unknown

...
...

This writeup documents a DiceCTF kernel challenge (HashBrown) that contains a race during hashmap resize enabling a use-after-free; the author describes creating a stable race with userfaultfd to leak kernel pointers (via shm_file_data) and obtain arbitrary write primitives to overwrite kernel writable strings (e.g., modprobe_path) for privilege escalation, including exploitation details and final exploit results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.