>_0xFORUM
Sign in

Use-after-realloc when the buffer moved and a pointer did not

in Exploits10 replies5.3k views

Classic. The patch stores the index, not the pointer. Detection: look for the pointer cache in old builds.

If you cache pointers into reallocable buffers, that is the class. Talk about it without a fuzzer output dump of a private target.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

@shadow_spb

Same wall I hit last quarter. The load-bearing line: Classic. Date your heap notes. 2012 grooming diagrams are history. If anyone DMs me a z

This is the writeup I wanted when I was stuck. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. Date your heap notes. 2012 grooming diagrams are history. I still have the snapshot named expl-222-pre.

@yunuszone

I dumped after OEP and then did this. The load-bearing line: Classic. If the thread slides toward a live target, lock it. I will report it.

Call-convention guess is not evidence. Same wall I hit last quarter. The load-bearing line: Classic. Date your heap notes. 2012 grooming diagrams are history. If anyone DMs me a zip I will not open it. Hash in-thread.

This is the writeup I wanted when I was stuck. You wrote «Classic». That is the sentence I keep. If you wrap memcpy, I want the check on every path. Which build of the tool? I got burned mixing notes across versions. Same class as the January thread, different binary.

I want the listing, not the decompiler story. The load-bearing line: Classic. Vendor bump is patch Tuesday. Forgotten trees grow extra years. If anyone DMs me a zip I will not open it. Hash in-thread.

I failed this exact class in January. «Use-after-realloc when the buffer moved and a pointer did not» — specifically Classic. A saturating add that hangs is not a complete patch. Hunt the hang too. Same class as the June thread, different binary.

@shieldx

I failed this exact class in January. «Use-after-realloc when the buffer moved and a pointer did not» — specifically Classic. A saturating a

Came back to this after a coffee. Still hold. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. system() on a user path is the class. execve with argv is the patch. If anyone DMs me a zip I will not open it. Hash in-thread.

@southsideguy

Came back to this after a coffee. Still hold. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. system() on a use

That is not what the listing shows. You are arguing a vibe. Did this on ARM64 last week — same shape, different pain. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. system() on a user path is the class. execve with argv is the patch. If anyone DMs me a zip I will not open it. Hash in-thread.

Bookmarking this for the lab wiki. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. A saturating add that hangs is not a complete patch. Hunt the hang too. Is the hang the incomplete patch, or a second bug? I still have the snapshot named expl-222-pre.

@unitx

Bookmarking this for the lab wiki. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. A saturating add that hangs

Good. Dated shot, version in the post. On «Use-after-realloc when the buffer moved and a pointer did not»: Classic. OOB read is a leak until proven otherwise. In the notes, not in a PoC. If anyone DMs me a zip I will not open it. Hash in-thread.

I dumped after OEP and then did this. The load-bearing line: Classic. If the thread slides toward a live target, lock it. I will report it. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.