>_0xFORUM
Sign in

Double-fetch from user, patched with a local copy

in Exploits16 replies2.7k views

Public kernel class. Fetch length, alloc, fetch again. Patch copies once. Hunt the second fetch in old builds.

If you post a 'minimal trigger' I will delete it. Talk the patch.

Refs: CVE Program · MSRC

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

I disagree with the tone, not the bytes. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Canonicalize last. Concatenate after realpath is how .. comes back. Is the hang the incomplete patch, or a second bug? Same class as the June thread, different binary.

@alert

This is the kind of thread that should be a sticky and is not. On «Double-fetch from user, patched with a local copy»: Public kernel class.

Did this on ARM64 last week — same shape, different pain. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Same class as the October thread, different binary.

@control

I still keep a paper notebook for this kind of note. On «Double-fetch from user, patched with a local copy»: Public kernel class. Canonicali

Agreed on the class, not on the tool. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Canonicalize last. Concatenate after realpath is how .. comes back. My note id for this: e1-10.

@daemon

Agreed on the class, not on the tool. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Canonicalize l

You skipped isolation and then asked why the box is dirty. That is on you. The screenshot is the useful part of the post. On «Double-fetch from user, patched with a local copy»: Public kernel class. A saturating add that hangs is not a complete patch. Hunt the hang too. My note id for this: e1-11.

This belongs in the first-hour ritual. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I wrote a 12-line script and then threw it away. The listing was enough.

@foxtrot

Please keep the hashes and drop the mystery zips. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. sy

That is not what the listing shows. You are arguing a vibe. Quietly the best note on this board this month. The load-bearing line: Public kernel class. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

@voltx

If you only have the decompiler, you do not have the bug. You wrote «Public kernel class». That is the sentence I keep. If the thread slides

You are describing a live target. Stop. Patched class only. This is the kind of thread that should be a sticky and is not. On «Double-fetch from user, patched with a local copy»: Public kernel class. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Hash of the public file, or are we arguing a shape? Version in my shot: current lab snapshot, not last year's blog.

@audit

Did this on ARM64 last week — same shape, different pain. «Double-fetch from user, patched with a local copy» — specifically Public kernel c

Take the telegram pitch to the bin. Market listing or nothing. Bookmarking this for the lab wiki. You wrote «Public kernel class». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x1400043fe in the listing.

@ciph3r

I disagree with the tone, not the bytes. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Canonicaliz

You are treating a checksum as a signature again. I still keep a paper notebook for this kind of note. On «Double-fetch from user, patched with a local copy»: Public kernel class. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

@bravo

This belongs in the first-hour ritual. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. Patched class

Quote the bytes or sit down. This matches a public n-day class from last patch Tuesday. The load-bearing line: Public kernel class. If you wrap memcpy, I want the check on every path. I reproduced it on lab build 1388.

Please keep the hashes and drop the mystery zips. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. system() on a user path is the class. execve with argv is the patch. If anyone DMs me a zip I will not open it. Hash in-thread.

@edge

The screenshot is the useful part of the post. You wrote «Public kernel class». That is the sentence I keep. Date your heap notes. 2012 groo

I am not moving this to DMs so you can yell. Stay on the class. Quietly the best note on this board this month. The load-bearing line: Public kernel class. system() on a user path is the class. execve with argv is the patch. Did page heap see it, or only the sanitizer? If anyone DMs me a zip I will not open it. Hash in-thread.

The screenshot is the useful part of the post. You wrote «Public kernel class». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Took me 5 hours the first time.

Also: No samples, even public corpus files. Hashes and links. Attachments get pulled.

If you only have the decompiler, you do not have the bug. You wrote «Public kernel class». That is the sentence I keep. If the thread slides toward a live target, lock it. I will report it. Took me 9 hours the first time.

Please keep the hashes and drop the mystery zips. You wrote «Public kernel class». That is the sentence I keep. Canonicalize last. Concatenate after realpath is how .. comes back. Took me 2 hours the first time.

@vuln

Please keep the hashes and drop the mystery zips. You wrote «Public kernel class». That is the sentence I keep. Canonicalize last. Concatena

Do not call people skids because they use Ghidra. This is the kind of thread that should be a sticky and is not. «Double-fetch from user, patched with a local copy» — specifically Public kernel class. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.