Andrey Konovalov

Andrey Konovalov

@andreyknvl · Twitter ·

New attack surface for Pwn2Own unlocked? 😁 Unprivileged mounting allows reaching a staggering number of bugs in the filesystem drivers; see the syzbot dashboard (click through "Child subsystems"): https://syzkaller.appspot.com/upstream/s/fs

Linux Kernel Security

Linux Kernel Security

Linux kernel hfsplus slab-out-of-bounds Write Outstanding article by @4ttil4sz1a about exploiting a slab out-of-bounds bug in the HFS+ filesystem driver. https://ssd-disclosure.com/ssd-advisory-linux-kernel-hfsplus-slab-out-of-bounds-write/

Quoted post media