Exploiting CVE-2022-42703 - Bringing back the stack attack
ID: 4753c90e-c2ae-5bb4-966d-150b0cba9180
STIX ID: report--4753c90e-c2ae-5bb4-966d-150b0cba9180
Feed Name: Google Project Zero
Threat Score
This write-up analyzes CVE-2022-42703, a complex Linux kernel anon_vma use-after-free that the author turns into a constrained arbitrary-write primitive via down_read_trylock, then leverages non-randomized exception stacks and hardware breakpoints to corrupt saved registers and produce kernel stack overflows leading to local kernel code execution; it also demonstrates a prefetch-based KASLR/CPU-entry-area disclosure PoC to defeat mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
