文章预览
一 前言 看雪的二进制课程已经学习结束了,此篇是考核内容,顺便检测一下我对课程内容的理解程度。 参考内容 https://www.anquanke.com/post/id/254027 https://arttnba3.cn/2022/04/01/CVE-0X07-CVE-2021-22555/ https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html 以及看雪的二进制课程。 二 漏洞分析 先看一下kasan给出的信息。 [ 1185.205439] ================================================================== [ 1185.205993] BUG: KASAN: slab-out-of-bounds in xt_compat_target_from_user+0x20a/0x4c0 [x_tables] [ 1185.206102] Write of size 4 at addr ffff8881e4c97600 by task poc/2059 [ 1185.206255] CPU: 1 PID: 2059 Comm: poc Not tainted 5.8.1 #1 [ 1185.206257] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 [ 1185.206259] Call Trace: [ 1185.206326] dump_stack+0x9d/0xda [ 1185.206346] print_address_description.constprop.0+0x1f/0x210 [ 1185.206353]
………………………………