Corrupting memory without memory corruption
In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights the strong primitives that an attacker may gain by exploiting errors in the memory management code of GPU drivers.
Discussion around the web
- Hacker News1 · 0 💬
Score breakdown
- Technical depth85
- Practical value60
- Originality85
- Writing quality82
- Source reputation85
- Recency0
- External engagement0
- On-site engagement0
More like this
Stripe Engineering52
Root cause analysis: significantly elevated error rates on 2019‑07‑10
unknown·10 min read
Engineering at Meta64
MemLab: An open source framework for finding JavaScript memory leaks
unknown·14 min read
The Cloudflare Blog56
However improbable: The story of a processor bug
unknown·18 min read
The Cloudflare Blog58
Every 7.8μs your computer’s memory has a hiccup
unknown·15 min read
Engradar shows a summary and links to the original article. The full article is hosted on github.blog.