>_0xFORUM
Sign in

Race on a refcount that looked like a leak and was a UAF

in Exploits11 replies201 views

Public, patched. The leak was the hint. The UAF was the bug. The patch is atomic and ordered.

If you see a weird leak in a refcounted object, look at the race, not the malloc.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

Not fully convinced yet. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

@freq

Not fully convinced yet. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. Canonicalize last. Conca

I disagree with the tone, not the bytes. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. If the thread slides toward a live target, lock it. I will report it. Pinned a comment at 0x1400065ac in the listing.

@grayx

I disagree with the tone, not the bytes. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. If the t

Do not call people skids because they use Ghidra. This is the kind of thread that should be a sticky and is not. On «Race on a refcount that looked like a leak and was a UAF»: Public, patched. If you wrap memcpy, I want the check on every path. I wrote a 12-line script and then threw it away. The listing was enough.

I still keep a paper notebook for this kind of note. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@iamflex

I still keep a paper notebook for this kind of note. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patch

I tried the naive path first and wasted a morning. You wrote «Public, patched». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. My note id for this: ec-04.

If you only have the decompiler, you do not have the bug. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. Canonicalize last. Concatenate after realpath is how .. comes back. I still have the snapshot named expl-236-pre.

@kabirjay

If you only have the decompiler, you do not have the bug. «Race on a refcount that looked like a leak and was a UAF» — specifically Public,

Take the telegram pitch to the bin. Market listing or nothing. I will argue the opposite and then probably agree. The load-bearing line: Public, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@l0gic

I will argue the opposite and then probably agree. The load-bearing line: Public, patched. A saturating add that hangs is not a complete pat

Not fully convinced yet. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I will +rep a listing and −rep a vibe. That is the deal.

Did this on ARM64 last week — same shape, different pain. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. If the thread slides toward a live target, lock it. I will report it. What did you key the join on — PID or process GUID? I reproduced it on lab build 1324.

I tried the naive path first and wasted a morning. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

@netrix

I tried the naive path first and wasted a morning. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched

You are treating a checksum as a signature again. This is the kind of thread that should be a sticky and is not. «Race on a refcount that looked like a leak and was a UAF» — specifically Public, patched. A saturating add that hangs is not a complete patch. Hunt the hang too. My note id for this: ec-10.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.