Notselwyn/CVE-2024-1086

Doesnt work on 5.4.0-164-generic #181-Ubuntu

CodeXTF2 opened this issue · 1 comments

kernel version: 5.4.0-164-generic #181-Ubuntu

(remote) ahope@nix01:/home/ahope$ ./exploit.1 
[*] creating user namespace (CLONE_NEWUSER)...
[*] creating network namespace (CLONE_NEWNET)...
[*] setting up UID namespace...
[*] configuring localhost in namespace...
[*] setting up nftables...
[+] running normal privesc
[*] waiting for the calm before the storm...
[*] sending double free buffer packet...
[*] spraying 16000 pte's...

[04:50:42] connection reset  
<box was down>

Hi, the exploit does not work on v5.4 kernels (the vuln exists, though). Please check the affected versions table in the blogpost: https://pwning.tech/nftables/#02-affected-kernel-versions