#FlippingPages

Thorsten Leemhuis (acct. 1/4)kernellogger@fosstodon.org
2024-03-26

#FlippingPages: An analysis of a new #Linux vulnerability in nf_tables and hardened exploitation techniques

pwning.tech/nftables/ – CVE-2024-1086

A tale about exploiting KernelCTF Mitigation, Debian, and Ubuntu instances with a double-free in nf_tables in the #Linuxkernel, using novel techniques like Dirty Pagedirectory. All without even having to recompile the exploit for different #kernel targets once.

Fix: kernel.dance/#f342de4e2f33e0e3

Local privilege escalation POC: github.com/Notselwyn/CVE-2024-

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst