logo

CUCTF 2020 Hotrod Kernel Writeup (Userfaultfd Race + Kernel UAF + Timerfd_Ctx Overwrite)

ID: f4ede83e-32b6-5fac-a343-605c9898bfa1

STIX ID: report--f4ede83e-32b6-5fac-a343-605c9898bfa1

Feed Name: Will's Root

Threat Score
65/100

Date Published: 2020-10-04

Date Updated: 2026-04-19

Author: Unknown

...
...

This is a detailed CTF writeup for exploiting a vulnerable kernel module (hotrod). The author describes creating a race-induced UAF using userfaultfd to hijack timerfd_ctx function pointers, leaking KASLR via sprayed timerfd structures, and achieving kernel code execution and local privilege escalation by pivoting to userland and using a KPTI/SMEP-aware trampoline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.