106 Commits

Author SHA1 Message Date
Ruida Zeng 14f1ec7817 Fix CVE typo in CVE-2025-40364_lts_cos metadata (#361)
The metadata.json incorrectly lists CVE-2024-40364 instead of CVE-2025-40364, mismatching the directory name.

Fixes #358
2026-05-20 14:21:52 +02:00
conlonial77 927f4ed511 Fix (#351) 2026-03-18 11:42:20 +01:00
conlonial77 eec2e575c8 Add kernelCTF CVE-2025-38500_lts_cos_mitigation (#262) 2026-03-10 12:15:31 +01:00
M Ramdhan 4a3a573cc2 add kernelCTF CVE-2025-40019_lts_cos_mitigation (#305) 2026-03-09 21:14:56 +01:00
M Ramdhan d6af6af130 Add kernelCTF CVE-2025-39946_lts_cos (#304) 2026-03-09 21:09:46 +01:00
conlonial 570fc79afa Add kernelCTF CVE-2024-50164_lts (#267) 2026-03-02 13:34:47 +01:00
st424204 571b5d0c0e Add kernelCTF CVE-2024-58239_mitigation (#254)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2024_58239_mitigation

* CVE-2024-58239_mitigation

* Update exploit.md

* AI_improve_PR

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-03-02 11:06:44 +01:00
st424204 d548a1c7fc Add kernelCTF CVE-2025-37756-mitigation (#255)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2025-37756-mitigation

* CVE-2025-37756_mitigation/

* CVE-2025-37756_mitigation/

* Update exploit.md

* Update exploit.md

* Improve_PR

* Fix_tls_record_comment

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-03-02 11:02:38 +01:00
Tamás Koczka 07cdcf4346 kernelCTF: CVE-2025-39682: remove script from vulnerability.md as it is attached separately
This was breaking GHA page genereation
2026-03-02 10:34:18 +01:00
n132 95f6678d40 Add kernelCTF CVE-2025-38477_cos (#268)
* Add kernelCTF CVE-2025-38477_cos

* Add deps for CVE-2025-38477: libx

* CVE-2025-38477: Update metadata

* CVE-2025-38477: Update metadata

* Add CVE-2025-38477_cos: Solve the dep issue

* Add CVE-2025-38477_cos: debug mode

* resubmit: retry the checks

* Update exploit.md

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Retest

* More trial

* Update exploit.md

* Update exploit.md with vulnerability details

Clarify details about security vulnerabilities and mmap usage.

* CI: Retest

* CI Reset & document format

* reset

* Update with correct kaslr leak

* Update with correct kaslr leak

* Make it debugable

* [v8ctf] Update v8CTF challenges

* fix: kaslr leaking

* retry

* code for test

* code for test

* code for test

* code for test

* retest

* retest

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* Style: Using macros

* Trial: Try to remove the not important payload data

* comments: explain the exploit

* conflict: remove synced chrome stuff

* fix: check

* Style: Define the size sk_buff spray

* chore: remove unused var

* chore: remove unused var

* chore: remove comments

* chore: remove comments

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: remove the dup write and I don't know if I gonna destroy the whole exp, figure cross!

* chore: more comments for exploitation

* Exploitation for Nperm

* More comment for used objects

* Writing: update

* Chore: writing

* Fix a wrong statement

* Doc: more explanation

* Doc: Tip for readers

* Fix: typo

* DoC: Details about nonfull_aggs

* Fix: typo

* Revert a change

* Doc: Clarify

* More explain

* Doc: Typo

* Doc: Typo

* Doc: Typo

* Doc: Typo

* Doc: Typo fixes

* Doc: Heap related

---------

Co-authored-by: swing <bestswngs@gmail.com>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-27 10:48:21 +01:00
conlonialC 746453d91c Add kernelCTF CVE-2023-52433_mitigation (#241)
* Add CVE-2023-52433_mitigation

* Fix metadata.json

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix comments

* fix comments

* fix comments

* fix commits

* fix commits

* Update exploit.md

---------

Co-authored-by: conlonial <kongln9170@gmail.com>
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com>
2026-02-27 10:42:56 +01:00
liona24 eef74b8c02 Add kernelCTF CVE-2025-39946 mitigation (#295) 2026-02-26 14:16:02 +01:00
liona24 ce04c3f7c3 kernelCTF: CVE-2025-38350 (#260)
* Add kernelCTF CVE-2025-38350

* Fix debug build step (uses replace on gcc..)

* Add suggested style fixes

* Add note about RCU protection
2026-02-26 13:15:36 +01:00
st424204 e0c462526b Add kernelCTF CVE-2024-26824_mitigation (#256)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2024-26824_mitigation/

* CVE-2024-26824_mitigation

* fix

* Update metadata.json

* Update exploit.c

* Update exploit.c

* remove useless msg_msg

* Update exploit.c

* Update exploit.md

* Improve_PR

* Improve_PR

* done

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-25 22:12:05 +01:00
M Ramdhan cf6a7dcc92 Add kernelCTF CVE-2025-39682_lts_cos_mitigation (#251)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* add CVE-2025-39682_lts_cos_mitigation

* Update metadata.json

* Update metadata.json

* update metadata.json

* Improve exploit readability for all three targets (lts/cos/mitigation)

- Remove unused globals (buf2, sprayfd2) and remove unneeded sprayfd
  socket spray that was confirmed unnecessary via remote testing
- Rename variables to descriptive names: pfd→splice_pipe, pfd2→uaf_pipe,
  pfds→page_spray_pipes, addrs→pte_trigger_maps, dummy_serv/cli→aux_client/conn,
  tpfd→victim_pte_pipe_fd, pa→core_pattern_pte, etc.
- Add #define constants with comments for all magic numbers:
  PAGE_SPRAY_PIPE_COUNT, PTE_SPRAY_MAP_COUNT, PTE_MAP_STRIDE, PTE_FLAGS_RW,
  PHYSMAP_ZERO_OFFSET, PHYSMAP_CORE_PATTERN
- Add top-level block comment explaining the full exploit chain
  (page UAF → writable pipe → PTE reclaim → core_pattern write)
- Add numbered step comments throughout main() keyed to kernel function
  names (tls_strp_load_anchor_with_queue, spd_fill_page, get_page, etc.)
- Rename TLS record variables to tls_appdata_record, tls_handshake_record,
  tls_spliced_record for clarity
- All three targets verified working on remote after changes

* Extract TLS record generation script into docs/gen_tls_records.py

Resolves maintainer comment to move the inline Python script from
vulnerability.md into a standalone, runnable .py file.

---------

Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
Co-authored-by: st424204 <st424204@yahoo.com.tw>
2026-02-25 18:19:59 +01:00
lonikon256k c570685861 Add kernelCTF CVE-2025-38502_lts 2026-02-25 14:57:45 +01:00
Nevsor 1d1ab40015 Add kernelCTF CVE-2025-39965_cos (#273)
* Add kernelCTF CVE-2025-39965_cos

* Fix compiler flags for CI build

The GCC version used by the CI instance does not support "-std=c23"

* Remove an outdated and misleading log statement.

* Finish exploit.md

* Improve design of ASCII diagrams

Some characters rendered differently on GitHub than they did in VS Code. This should make the rendering a bit more robust.
2026-02-25 00:11:32 -08:00
Tamas Koczka c3920dd9c0 kernelCTF: add few comments after review 2026-02-24 15:37:51 +00:00
st424204 ff349c26b3 Add kernelCTF CVE-2025-38616_lts_cos_mitigation (#253)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2025-38616-lts-cos-mitigation

* X

* X

* X

* X

* X

* X

* fix lts

* fix lts

* fix lts

* fix lts

* fix lts

* test lts

* test lts

* Update exploit.md

* Update exploit.md

* Update exploit.c

* remove useless msg_msg

* Update exploit.md

* Improve_PR

* Improve exploit.md

* Improve

* Fix exploit.c

* Done

* Fix MIT

* Done

* Done

* Done

* done

* done

* done

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-24 16:34:07 +01:00
st424204 8e99b67f87 Add kernelCTF CVE-2023-52926_lts (#213)
* init CVE-2023-52926

* Done

* improve_PR
2026-02-23 17:18:59 +01:00
ImV4bel 8e964c541c Add kernelCTF CVE-2025-21756_lts_cos (#205)
* init

* modify exploit file

* modify Makefile

* modify exploit

* kernelCTF: remove CVE-2025-21756_cos as it did not pass tests

---------

Co-authored-by: Tamas Koczka <poprdi@google.com>
2026-02-23 16:05:33 +01:00
msh1307 2271225f5c Add kernelCTF CVE-2023-5717_mitigation (#168)
* Add CVE-2023-5717_mitigation

* update

* Improved speed

* Improved speed

* Improve speed

* Adjust MIN, MAX

* Remove race_id & Fix kernel mem layout for exploit

* Adjust MIN, MAX

* Improved exploit speed

* Improved speed & relibility

* Revert read() loops

* Remove some stub codes

* Finding r

* Finding r

* Finding r

* Revert Timing

* Adjust timing & Overwriting ptes across the entire page

* FIx iteration

* making more reliable memory layout?

* Improved forming memory layout reliability

* Fix useless codes

* Testing

* Testing

* Fixed Typo

* improved memory layout reliability

* memory reliability

* Fix counters being migrated to next event by scheduler

* Fix missing timerfd

* Fix pte limit

* test

* Increase iteration & ensure tlb is flushed

* Flushing tlb effectively

* Test

* Using execve instead of system

* Final version of exploit

* Final

* same

* Last

* Fix code styles

* Fix code styles & docs

* Fix code styles & docs

* address review feedback
2026-02-23 15:44:28 +01:00
Gerrard e9b6a52ba9 Added kernelCTF CVE-2025-38083_cos_mitigation (#227) 2026-02-10 12:24:26 +01:00
0xdevil 090538ae42 Add kernelCTF CVE-2025-38001_lts_cos_mitigation (#223)
* CVE-2025-38001_lts_cos_mitigation

* Fix GDB indentation
2026-02-06 17:10:05 +01:00
0xdevil 8eb2453001 Add kernelCTF CVE-2025-37752_cos (#222)
* Add kernelCTF CVE-2025-37752_cos

* Update exploit.c

* Update exploit.c
2026-02-06 14:55:00 +01:00
Hoàng Hải Long 44f6ce0223 Add kernelCTF CVE-2023-52927_cos (#220)
* init CVE-2023-52927

* fix file structure
2026-02-04 17:24:22 +01:00
lambdasprocket 7aafb56f9d kernelCTF: add CVE-2024-26585_lts_cos (#293)
* kernelCTF: add CVE-2024-26585_lts_cos

* CVE-2024-26585_lts_cos: adjust timings

* CVE-2024-26585_lts_cos: limit attempts for COS

* CVE-2024-26585_lts_cos: adjust timings for COS
2026-01-22 17:51:22 +01:00
Bien Pham d4a08c0ef1 kernelctf: add CVE-2023-4015_lts_2 (#142)
* kernelctf: add CVE-2023-4015_lts_2

* Rename post exploit func

* Remove some unneeded comments

* Add comment on reclaim

* Add comments in trigger_uaf

* Mark unused variable

* Add comment about where rsi is pointing to

* Define some magic numbers

* Fix failing compilation
2025-11-21 10:33:31 -08:00
chanijindal1 bc5f5d844e Revert "Add kernelCTF CVE-2025-21703_lts_cos (#276)" (#281)
This reverts commit 9c5e122d3c. PR 276 still needs to be reviewed. Reverting so it can go through the correct process
2025-11-21 10:28:23 -08:00
mingi 9c5e122d3c Add kernelCTF CVE-2025-21703_lts_cos (#276)
* Add kernelCTF CVE-2025-21703_lts_cos

* update filename

* update metadata.json

* update metadata.json

* update exploit.c

---------

Co-authored-by: Mingi Cho <mgcho.minic@gmail.com>
2025-11-21 03:33:47 -08:00
st424204 284329c63b Add kernelCTF CVE-2025-40364_lts_cos (#210)
* init CVE-2025-40364

* Update exploit.c

* fix exp

* fix exp

* Update exploit.md

* Update exploit.md

* Improve

* Improve 2

* Improve 3

* Test

* TEST

* TEST

* TEST

* Added comment for sleep

* Added comment for refcount clac

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
2025-11-21 10:48:00 +01:00
0xdevil 744dce70df Add kernelCTF CVE-2024-58240_cos (#274)
* Add kernelCTF CVE-2024-58240_cos

* Update exploit.c
2025-11-06 13:25:04 +01:00
st424204 806efd3257 Add kernelCTF CVE-2025-21756_cos (#188)
* CVE-2025-21756_cos

* CVE-2025-21756_cos

* CVE-2025-21756_cos

* CVE-2025-21756_cos

* CVE-2025-21756_cos

* import_exploit.c

* import_exploit.c

* Upload exploit.md

* Fix typo in exploit.md

* Fix comment in exploit.c

* Fix comment in exploit.c

* improve_exp

* improve_exp_doc

* Improve docs
2025-10-14 17:36:20 +02:00
lonialcon2 2ae6c4fef4 Add kernelCTF CVE-2024-53125_lts (#200)
* Add files

* Fix some problems

* Fix some problems

* Fix some problems

* Fix some problems

* Fix some problems

* Fix some problems

* Fix some problems

* change vulnerability.md

* Fix comments

---------

Co-authored-by: conlonial <kongln9170@gmail.com>
Co-authored-by: kongln9170@gmail.com <conlonial7@gmail.com>
2025-10-10 20:45:36 +02:00
conlonial 08be3e8096 Add kernelCTF CVE-2024-49861_lts (#193)
* Add files

* Fix files

* Fix files

* Fix comments

* Fix comments

---------

Co-authored-by: kongln9170@gmail.com <conlonial7@gmail.com>
2025-10-10 20:43:51 +02:00
liona24 bd20b8829a Add kernelCTF CVE-2025-21700 (#202)
* Add kernelCTF CVE-2025-21700

* CVE-2025-21700: Make sure that we can open enough files

* CVE-2025-21700: Adapt filters for slightly different kernel code on CI

* CVE-2025-21700: Fix instruction sizes when stubs are used

* CVE-2025-21700: More fixes when stubs are used

* CVE-2025-21700: Crash the mitigation instance to deadlocking the CI

* Fix ref and inlining docs
2025-10-10 16:51:58 +02:00
liona24 1eaead6104 Add kernelCTF CVE-2024-53164 (#197)
* Add kernelCTF CVE-2024-53164

* Properly name the mitigation folder

* More details on spray and fix part on inlining
2025-10-10 16:50:31 +02:00
4ab48b3f1ded2472 fa6f2da24e kernelCTF: Add CVE-2023-4921_lts_cos_mitigation (#204)
* kernelCTF: Add CVE-2023-4921_lts_cos_mitigation

* CVE-2023-4921_lts_cos_mitigation: Fix metadata

* CVE-2023-4921_lts_cos_mitigation: Add missing files

* CVE-2023-4921_lts_cos_mitigation: Fix makefiles

* CVE-2023-4921_lts_cos_mitigation: Remove add_class_drr()
2025-10-04 13:58:57 -06:00
pumpkin ca0047183f Add kernelCTF CVE-2025-21836_lts (#201)
* add files

* add exploit & fix struct member

* add io_uring uses in metadata.json

* output try count

* add success output, remove kaslr side channel optimization

* fix corrupted side-channel leak in GitHub action & remove redundant success log

* auto fail after 30 mins to pass the GitHub action

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

---------

Co-authored-by: v8CTF github action <sroettger@google.com>
2025-10-04 10:51:41 -06:00
Chino Kafuu e29c8dceb8 Add kernelCTF CVE-2024-26582_mitigation (#192)
* Add kernelCTF CVE-2024-26582_mitigation

* Add kernelCTF CVE-2024-26582_mitigation

* Add kernelCTF CVE-2024-26582_mitigation

* Add kernelCTF CVE-2024-26582_mitigation

* Add kernelCTF CVE-2024-26582_mitigation

* Add kernelCTF CVE-2024-26582_mitigation

* final

* update

* update writeup
2025-10-04 10:12:41 -06:00
dayfly 16717f3335 Add kernelCTF CVE-2025-21701_lts_cos (#194)
* Add kernelCTF CVE-2025-21701_lts_cos exploit

* fix cache name of net device

* explain the mechanism for populating kernfs_pr_cont_buf

* explain the spray_padding_msg_msg()
2025-10-01 11:01:43 -06:00
liona24 bc255c7cf6 Add kernelCTF CVE-2024-53141 COS / Mitigation (#180)
* Add CVE-2024-53141 COS / Mitigation

* Add original exploit artifacts

* Apply provided KASLR leak correctly

* Apply suggestions from code review

Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com>

* Clarify oob write

---------

Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com>
2025-09-29 13:13:32 +02:00
quanggle97 463c85665e Add kernelCTF CVE-2025-21702_lts_cos (#187)
* Add kernelCTF CVE-2025-21702_lts_cos

* remove unused functions

* removed unused functions

* Update exploit.c

* Update exploit.c

* Update exploit.c

* Update exploit.c

* Update exploit.md to reflect exploit.c modified
2025-09-27 20:33:03 +02:00
mingi 9a3033ac5d Add kernelCTF CVE-2023-52925_mitigation (#166)
* Add kernelCTF CVE-2024-52925_mitigaiton

* update vulnerability.md exploit.c

* update exploit.md and exploit.c

---------

Co-authored-by: Mingi Cho <mincho@theori.io>
2025-09-26 12:33:11 +02:00
Sechack 4a0c2c4aba Add kernelCTF CVE-2023-6931_mitigation (#141)
* change style

* change style

* change style

* change style
2025-09-26 11:35:27 +02:00
Bien Pham ecfa8c5ae8 kernelctf: add CVE-2023-4015_cos (#140)
* kernelctf: add CVE-2023-4015_cos

* Rename post exploit func

* Remove unneeded comments

* Add comments in trigger_uaf

* Add comment on reclaim

* Add comment about where rsi is pointing to

* Define some magic numbers
2025-06-16 03:10:12 -07:00
mingi 54fd1a3848 Add kernelCTF CVE-2024-57947_mitigation (#162) 2025-06-12 19:50:44 +02:00
mingi 91e7875aa6 Add kernelCTF CVE-2023-4244_mitigation (#161) 2025-06-12 19:49:09 +02:00
mingi 99d8780bd8 Add kernelCTF CVE-2023-52924_mitigation (#164) 2025-06-06 17:47:46 +02:00
Nightu b48d1ba85e Add kernelCTF CVE-2023-6560_mitigation (#153)
* Init CVE-2023-6560_mitigation

* Add files

* Fix directory

* Add missing comments align to code style requirements
2025-05-20 11:48:49 +02:00