logo

Hunting for Blues – the WSL Plan 9 Protocol BSOD

ID: 5639032d-e6df-5a9e-8dc3-fac81bbe9fab

STIX ID: report--5639032d-e6df-5a9e-8dc3-fac81bbe9fab

Feed Name: McAfee Labs Blog

Threat Score
30/100

Date Published: 2020-07-23

Date Updated: 2026-04-28

Author: Eoin Carroll

...
...

McAfee Labs analysed the Windows WSL Plan 9 (P9) protocol implementation and found that a malicious P9 server (by hijacking the "fsserver" AF_UNIX socket) can send malformed R-messages that the p9rdr.sys driver processes in kernel context, resulting in local denial-of-service (BSOD). The issue requires local presence or privileged actions to enable WSL/socket hijack, does not enable kernel code execution or privilege escalation, and Microsoft validated the findings with mitigations focused on preventing socket hijacking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.