Ruida Zeng
14f1ec7817
Fix CVE typo in CVE-2025-40364_lts_cos metadata ( #361 )
...
The metadata.json incorrectly lists CVE-2024-40364 instead of CVE-2025-40364, mismatching the directory name.
Fixes #358
2026-05-20 14:21:52 +02:00
conlonial77
927f4ed511
Fix ( #351 )
2026-03-18 11:42:20 +01:00
conlonial77
eec2e575c8
Add kernelCTF CVE-2025-38500_lts_cos_mitigation ( #262 )
2026-03-10 12:15:31 +01:00
M Ramdhan
4a3a573cc2
add kernelCTF CVE-2025-40019_lts_cos_mitigation ( #305 )
2026-03-09 21:14:56 +01:00
M Ramdhan
d6af6af130
Add kernelCTF CVE-2025-39946_lts_cos ( #304 )
2026-03-09 21:09:46 +01:00
conlonial
570fc79afa
Add kernelCTF CVE-2024-50164_lts ( #267 )
2026-03-02 13:34:47 +01:00
st424204
571b5d0c0e
Add kernelCTF CVE-2024-58239_mitigation ( #254 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2024_58239_mitigation
* CVE-2024-58239_mitigation
* Update exploit.md
* AI_improve_PR
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-03-02 11:06:44 +01:00
st424204
d548a1c7fc
Add kernelCTF CVE-2025-37756-mitigation ( #255 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2025-37756-mitigation
* CVE-2025-37756_mitigation/
* CVE-2025-37756_mitigation/
* Update exploit.md
* Update exploit.md
* Improve_PR
* Fix_tls_record_comment
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-03-02 11:02:38 +01:00
Tamás Koczka
07cdcf4346
kernelCTF: CVE-2025-39682: remove script from vulnerability.md as it is attached separately
...
This was breaking GHA page genereation
2026-03-02 10:34:18 +01:00
n132
95f6678d40
Add kernelCTF CVE-2025-38477_cos ( #268 )
...
* Add kernelCTF CVE-2025-38477_cos
* Add deps for CVE-2025-38477: libx
* CVE-2025-38477: Update metadata
* CVE-2025-38477: Update metadata
* Add CVE-2025-38477_cos: Solve the dep issue
* Add CVE-2025-38477_cos: debug mode
* resubmit: retry the checks
* Update exploit.md
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Retest
* More trial
* Update exploit.md
* Update exploit.md with vulnerability details
Clarify details about security vulnerabilities and mmap usage.
* CI: Retest
* CI Reset & document format
* reset
* Update with correct kaslr leak
* Update with correct kaslr leak
* Make it debugable
* [v8ctf] Update v8CTF challenges
* fix: kaslr leaking
* retry
* code for test
* code for test
* code for test
* code for test
* retest
* retest
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* Style: Using macros
* Trial: Try to remove the not important payload data
* comments: explain the exploit
* conflict: remove synced chrome stuff
* fix: check
* Style: Define the size sk_buff spray
* chore: remove unused var
* chore: remove unused var
* chore: remove comments
* chore: remove comments
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: remove the dup write and I don't know if I gonna destroy the whole exp, figure cross!
* chore: more comments for exploitation
* Exploitation for Nperm
* More comment for used objects
* Writing: update
* Chore: writing
* Fix a wrong statement
* Doc: more explanation
* Doc: Tip for readers
* Fix: typo
* DoC: Details about nonfull_aggs
* Fix: typo
* Revert a change
* Doc: Clarify
* More explain
* Doc: Typo
* Doc: Typo
* Doc: Typo
* Doc: Typo
* Doc: Typo fixes
* Doc: Heap related
---------
Co-authored-by: swing <bestswngs@gmail.com >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-27 10:48:21 +01:00
conlonialC
746453d91c
Add kernelCTF CVE-2023-52433_mitigation ( #241 )
...
* Add CVE-2023-52433_mitigation
* Fix metadata.json
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix comments
* fix comments
* fix comments
* fix commits
* fix commits
* Update exploit.md
---------
Co-authored-by: conlonial <kongln9170@gmail.com >
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com >
2026-02-27 10:42:56 +01:00
liona24
eef74b8c02
Add kernelCTF CVE-2025-39946 mitigation ( #295 )
2026-02-26 14:16:02 +01:00
liona24
ce04c3f7c3
kernelCTF: CVE-2025-38350 ( #260 )
...
* Add kernelCTF CVE-2025-38350
* Fix debug build step (uses replace on gcc..)
* Add suggested style fixes
* Add note about RCU protection
2026-02-26 13:15:36 +01:00
st424204
e0c462526b
Add kernelCTF CVE-2024-26824_mitigation ( #256 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2024-26824_mitigation/
* CVE-2024-26824_mitigation
* fix
* Update metadata.json
* Update exploit.c
* Update exploit.c
* remove useless msg_msg
* Update exploit.c
* Update exploit.md
* Improve_PR
* Improve_PR
* done
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-25 22:12:05 +01:00
M Ramdhan
cf6a7dcc92
Add kernelCTF CVE-2025-39682_lts_cos_mitigation ( #251 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* add CVE-2025-39682_lts_cos_mitigation
* Update metadata.json
* Update metadata.json
* update metadata.json
* Improve exploit readability for all three targets (lts/cos/mitigation)
- Remove unused globals (buf2, sprayfd2) and remove unneeded sprayfd
socket spray that was confirmed unnecessary via remote testing
- Rename variables to descriptive names: pfd→splice_pipe, pfd2→uaf_pipe,
pfds→page_spray_pipes, addrs→pte_trigger_maps, dummy_serv/cli→aux_client/conn,
tpfd→victim_pte_pipe_fd, pa→core_pattern_pte, etc.
- Add #define constants with comments for all magic numbers:
PAGE_SPRAY_PIPE_COUNT, PTE_SPRAY_MAP_COUNT, PTE_MAP_STRIDE, PTE_FLAGS_RW,
PHYSMAP_ZERO_OFFSET, PHYSMAP_CORE_PATTERN
- Add top-level block comment explaining the full exploit chain
(page UAF → writable pipe → PTE reclaim → core_pattern write)
- Add numbered step comments throughout main() keyed to kernel function
names (tls_strp_load_anchor_with_queue, spd_fill_page, get_page, etc.)
- Rename TLS record variables to tls_appdata_record, tls_handshake_record,
tls_spliced_record for clarity
- All three targets verified working on remote after changes
* Extract TLS record generation script into docs/gen_tls_records.py
Resolves maintainer comment to move the inline Python script from
vulnerability.md into a standalone, runnable .py file.
---------
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
Co-authored-by: st424204 <st424204@yahoo.com.tw >
2026-02-25 18:19:59 +01:00
lonikon256k
c570685861
Add kernelCTF CVE-2025-38502_lts
2026-02-25 14:57:45 +01:00
Nevsor
1d1ab40015
Add kernelCTF CVE-2025-39965_cos ( #273 )
...
* Add kernelCTF CVE-2025-39965_cos
* Fix compiler flags for CI build
The GCC version used by the CI instance does not support "-std=c23"
* Remove an outdated and misleading log statement.
* Finish exploit.md
* Improve design of ASCII diagrams
Some characters rendered differently on GitHub than they did in VS Code. This should make the rendering a bit more robust.
2026-02-25 00:11:32 -08:00
Tamas Koczka
c3920dd9c0
kernelCTF: add few comments after review
2026-02-24 15:37:51 +00:00
st424204
ff349c26b3
Add kernelCTF CVE-2025-38616_lts_cos_mitigation ( #253 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2025-38616-lts-cos-mitigation
* X
* X
* X
* X
* X
* X
* fix lts
* fix lts
* fix lts
* fix lts
* fix lts
* test lts
* test lts
* Update exploit.md
* Update exploit.md
* Update exploit.c
* remove useless msg_msg
* Update exploit.md
* Improve_PR
* Improve exploit.md
* Improve
* Fix exploit.c
* Done
* Fix MIT
* Done
* Done
* Done
* done
* done
* done
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-24 16:34:07 +01:00
st424204
8e99b67f87
Add kernelCTF CVE-2023-52926_lts ( #213 )
...
* init CVE-2023-52926
* Done
* improve_PR
2026-02-23 17:18:59 +01:00
ImV4bel
8e964c541c
Add kernelCTF CVE-2025-21756_lts_cos ( #205 )
...
* init
* modify exploit file
* modify Makefile
* modify exploit
* kernelCTF: remove CVE-2025-21756_cos as it did not pass tests
---------
Co-authored-by: Tamas Koczka <poprdi@google.com >
2026-02-23 16:05:33 +01:00
msh1307
2271225f5c
Add kernelCTF CVE-2023-5717_mitigation ( #168 )
...
* Add CVE-2023-5717_mitigation
* update
* Improved speed
* Improved speed
* Improve speed
* Adjust MIN, MAX
* Remove race_id & Fix kernel mem layout for exploit
* Adjust MIN, MAX
* Improved exploit speed
* Improved speed & relibility
* Revert read() loops
* Remove some stub codes
* Finding r
* Finding r
* Finding r
* Revert Timing
* Adjust timing & Overwriting ptes across the entire page
* FIx iteration
* making more reliable memory layout?
* Improved forming memory layout reliability
* Fix useless codes
* Testing
* Testing
* Fixed Typo
* improved memory layout reliability
* memory reliability
* Fix counters being migrated to next event by scheduler
* Fix missing timerfd
* Fix pte limit
* test
* Increase iteration & ensure tlb is flushed
* Flushing tlb effectively
* Test
* Using execve instead of system
* Final version of exploit
* Final
* same
* Last
* Fix code styles
* Fix code styles & docs
* Fix code styles & docs
* address review feedback
2026-02-23 15:44:28 +01:00
Gerrard
e9b6a52ba9
Added kernelCTF CVE-2025-38083_cos_mitigation ( #227 )
2026-02-10 12:24:26 +01:00
0xdevil
090538ae42
Add kernelCTF CVE-2025-38001_lts_cos_mitigation ( #223 )
...
* CVE-2025-38001_lts_cos_mitigation
* Fix GDB indentation
2026-02-06 17:10:05 +01:00
0xdevil
8eb2453001
Add kernelCTF CVE-2025-37752_cos ( #222 )
...
* Add kernelCTF CVE-2025-37752_cos
* Update exploit.c
* Update exploit.c
2026-02-06 14:55:00 +01:00
Hoàng Hải Long
44f6ce0223
Add kernelCTF CVE-2023-52927_cos ( #220 )
...
* init CVE-2023-52927
* fix file structure
2026-02-04 17:24:22 +01:00
lambdasprocket
7aafb56f9d
kernelCTF: add CVE-2024-26585_lts_cos ( #293 )
...
* kernelCTF: add CVE-2024-26585_lts_cos
* CVE-2024-26585_lts_cos: adjust timings
* CVE-2024-26585_lts_cos: limit attempts for COS
* CVE-2024-26585_lts_cos: adjust timings for COS
2026-01-22 17:51:22 +01:00
Bien Pham
d4a08c0ef1
kernelctf: add CVE-2023-4015_lts_2 ( #142 )
...
* kernelctf: add CVE-2023-4015_lts_2
* Rename post exploit func
* Remove some unneeded comments
* Add comment on reclaim
* Add comments in trigger_uaf
* Mark unused variable
* Add comment about where rsi is pointing to
* Define some magic numbers
* Fix failing compilation
2025-11-21 10:33:31 -08:00
chanijindal1
bc5f5d844e
Revert "Add kernelCTF CVE-2025-21703_lts_cos ( #276 )" ( #281 )
...
This reverts commit 9c5e122d3c . PR 276 still needs to be reviewed. Reverting so it can go through the correct process
2025-11-21 10:28:23 -08:00
mingi
9c5e122d3c
Add kernelCTF CVE-2025-21703_lts_cos ( #276 )
...
* Add kernelCTF CVE-2025-21703_lts_cos
* update filename
* update metadata.json
* update metadata.json
* update exploit.c
---------
Co-authored-by: Mingi Cho <mgcho.minic@gmail.com >
2025-11-21 03:33:47 -08:00
st424204
284329c63b
Add kernelCTF CVE-2025-40364_lts_cos ( #210 )
...
* init CVE-2025-40364
* Update exploit.c
* fix exp
* fix exp
* Update exploit.md
* Update exploit.md
* Improve
* Improve 2
* Improve 3
* Test
* TEST
* TEST
* TEST
* Added comment for sleep
* Added comment for refcount clac
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
2025-11-21 10:48:00 +01:00
0xdevil
744dce70df
Add kernelCTF CVE-2024-58240_cos ( #274 )
...
* Add kernelCTF CVE-2024-58240_cos
* Update exploit.c
2025-11-06 13:25:04 +01:00
st424204
806efd3257
Add kernelCTF CVE-2025-21756_cos ( #188 )
...
* CVE-2025-21756_cos
* CVE-2025-21756_cos
* CVE-2025-21756_cos
* CVE-2025-21756_cos
* CVE-2025-21756_cos
* import_exploit.c
* import_exploit.c
* Upload exploit.md
* Fix typo in exploit.md
* Fix comment in exploit.c
* Fix comment in exploit.c
* improve_exp
* improve_exp_doc
* Improve docs
2025-10-14 17:36:20 +02:00
lonialcon2
2ae6c4fef4
Add kernelCTF CVE-2024-53125_lts ( #200 )
...
* Add files
* Fix some problems
* Fix some problems
* Fix some problems
* Fix some problems
* Fix some problems
* Fix some problems
* Fix some problems
* change vulnerability.md
* Fix comments
---------
Co-authored-by: conlonial <kongln9170@gmail.com >
Co-authored-by: kongln9170@gmail.com <conlonial7@gmail.com >
2025-10-10 20:45:36 +02:00
conlonial
08be3e8096
Add kernelCTF CVE-2024-49861_lts ( #193 )
...
* Add files
* Fix files
* Fix files
* Fix comments
* Fix comments
---------
Co-authored-by: kongln9170@gmail.com <conlonial7@gmail.com >
2025-10-10 20:43:51 +02:00
liona24
bd20b8829a
Add kernelCTF CVE-2025-21700 ( #202 )
...
* Add kernelCTF CVE-2025-21700
* CVE-2025-21700: Make sure that we can open enough files
* CVE-2025-21700: Adapt filters for slightly different kernel code on CI
* CVE-2025-21700: Fix instruction sizes when stubs are used
* CVE-2025-21700: More fixes when stubs are used
* CVE-2025-21700: Crash the mitigation instance to deadlocking the CI
* Fix ref and inlining docs
2025-10-10 16:51:58 +02:00
liona24
1eaead6104
Add kernelCTF CVE-2024-53164 ( #197 )
...
* Add kernelCTF CVE-2024-53164
* Properly name the mitigation folder
* More details on spray and fix part on inlining
2025-10-10 16:50:31 +02:00
4ab48b3f1ded2472
fa6f2da24e
kernelCTF: Add CVE-2023-4921_lts_cos_mitigation ( #204 )
...
* kernelCTF: Add CVE-2023-4921_lts_cos_mitigation
* CVE-2023-4921_lts_cos_mitigation: Fix metadata
* CVE-2023-4921_lts_cos_mitigation: Add missing files
* CVE-2023-4921_lts_cos_mitigation: Fix makefiles
* CVE-2023-4921_lts_cos_mitigation: Remove add_class_drr()
2025-10-04 13:58:57 -06:00
pumpkin
ca0047183f
Add kernelCTF CVE-2025-21836_lts ( #201 )
...
* add files
* add exploit & fix struct member
* add io_uring uses in metadata.json
* output try count
* add success output, remove kaslr side channel optimization
* fix corrupted side-channel leak in GitHub action & remove redundant success log
* auto fail after 30 mins to pass the GitHub action
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
---------
Co-authored-by: v8CTF github action <sroettger@google.com >
2025-10-04 10:51:41 -06:00
Chino Kafuu
e29c8dceb8
Add kernelCTF CVE-2024-26582_mitigation ( #192 )
...
* Add kernelCTF CVE-2024-26582_mitigation
* Add kernelCTF CVE-2024-26582_mitigation
* Add kernelCTF CVE-2024-26582_mitigation
* Add kernelCTF CVE-2024-26582_mitigation
* Add kernelCTF CVE-2024-26582_mitigation
* Add kernelCTF CVE-2024-26582_mitigation
* final
* update
* update writeup
2025-10-04 10:12:41 -06:00
dayfly
16717f3335
Add kernelCTF CVE-2025-21701_lts_cos ( #194 )
...
* Add kernelCTF CVE-2025-21701_lts_cos exploit
* fix cache name of net device
* explain the mechanism for populating kernfs_pr_cont_buf
* explain the spray_padding_msg_msg()
2025-10-01 11:01:43 -06:00
liona24
bc255c7cf6
Add kernelCTF CVE-2024-53141 COS / Mitigation ( #180 )
...
* Add CVE-2024-53141 COS / Mitigation
* Add original exploit artifacts
* Apply provided KASLR leak correctly
* Apply suggestions from code review
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com >
* Clarify oob write
---------
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com >
2025-09-29 13:13:32 +02:00
quanggle97
463c85665e
Add kernelCTF CVE-2025-21702_lts_cos ( #187 )
...
* Add kernelCTF CVE-2025-21702_lts_cos
* remove unused functions
* removed unused functions
* Update exploit.c
* Update exploit.c
* Update exploit.c
* Update exploit.c
* Update exploit.md to reflect exploit.c modified
2025-09-27 20:33:03 +02:00
mingi
9a3033ac5d
Add kernelCTF CVE-2023-52925_mitigation ( #166 )
...
* Add kernelCTF CVE-2024-52925_mitigaiton
* update vulnerability.md exploit.c
* update exploit.md and exploit.c
---------
Co-authored-by: Mingi Cho <mincho@theori.io >
2025-09-26 12:33:11 +02:00
Sechack
4a0c2c4aba
Add kernelCTF CVE-2023-6931_mitigation ( #141 )
...
* change style
* change style
* change style
* change style
2025-09-26 11:35:27 +02:00
Bien Pham
ecfa8c5ae8
kernelctf: add CVE-2023-4015_cos ( #140 )
...
* kernelctf: add CVE-2023-4015_cos
* Rename post exploit func
* Remove unneeded comments
* Add comments in trigger_uaf
* Add comment on reclaim
* Add comment about where rsi is pointing to
* Define some magic numbers
2025-06-16 03:10:12 -07:00
mingi
54fd1a3848
Add kernelCTF CVE-2024-57947_mitigation ( #162 )
2025-06-12 19:50:44 +02:00
mingi
91e7875aa6
Add kernelCTF CVE-2023-4244_mitigation ( #161 )
2025-06-12 19:49:09 +02:00
mingi
99d8780bd8
Add kernelCTF CVE-2023-52924_mitigation ( #164 )
2025-06-06 17:47:46 +02:00
Nightu
b48d1ba85e
Add kernelCTF CVE-2023-6560_mitigation ( #153 )
...
* Init CVE-2023-6560_mitigation
* Add files
* Fix directory
* Add missing comments align to code style requirements
2025-05-20 11:48:49 +02:00