Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20210201192439.GA23096@openwall.com>
Date: Mon, 1 Feb 2021 20:24:39 +0100
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Linux Kernel: local priv escalation via futexes

On Fri, Jan 29, 2021 at 06:01:11PM +0100, Marcus Meissner wrote:
> Mitre has now assigned CVE-2021-3347.

FWIW, here's a recent writeup and exploit for a different futex
vulnerability:

https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html
https://github.com/elongl/CVE-2014-3153

Might help someone get into futexes... and exploiting their bugs.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.