logo

Exploiting CVE-2022-42703 - Bringing back the stack attack

ID: 4753c90e-c2ae-5bb4-966d-150b0cba9180

STIX ID: report--4753c90e-c2ae-5bb4-966d-150b0cba9180

Feed Name: Google Project Zero

Threat Score
75/100

Date Published: 2022-12-08

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

This write-up analyzes CVE-2022-42703, a complex Linux kernel anon_vma use-after-free that the author turns into a constrained arbitrary-write primitive via down_read_trylock, then leverages non-randomized exception stacks and hardware breakpoints to corrupt saved registers and produce kernel stack overflows leading to local kernel code execution; it also demonstrates a prefetch-based KASLR/CPU-entry-area disclosure PoC to defeat mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.