Tamas Koczka
849fd2ca92
kernelCTF: GHA: vuln-verify: fix
2026-03-17 19:59:04 +00:00
Tamas Koczka
632bde3461
kernelCTF: GHA: vuln-verify: support bold in summary
2026-03-17 19:54:03 +00:00
Tamas Koczka
ea96600258
kernelCTF: GHA: vuln-verify: artifact fix
2026-03-17 19:51:06 +00:00
Tamas Koczka
820ba83368
kernelCTF: GHA: vuln-verify upload logs as artifacts, write summary
2026-03-17 19:46:01 +00:00
Tamas Koczka
b5ff798f4c
kernelCTF: GHA: vuln-verify fix
2026-03-17 19:13:46 +00:00
Tamas Koczka
3fcf07fd75
kernelCTF: GHA: vuln-verify: faster checkout, fix gzip upload, less noisy cache logs
2026-03-17 19:09:54 +00:00
Tamas Koczka
d72dbc86f6
kernelCTF: GHA: verbose build output for vuln-verify (fix 1)
2026-03-17 17:30:44 +00:00
Tamas Koczka
a1d2773964
kernelCTF: GHA: verbose build output for vuln-verify
2026-03-17 17:24:21 +00:00
Tamas Koczka
37e1915258
kernelCTF: GHA: fix vuln-verify 6
2026-03-17 16:57:17 +00:00
Tamas Koczka
6dbbfe9da1
kernelCTF: GHA: fix vuln-verify 5
2026-03-17 16:37:54 +00:00
Tamas Koczka
387bf1e4b6
kernelCTF: GHA: fix vuln-verify 4
2026-03-17 16:35:09 +00:00
Tamas Koczka
df26939f96
kernelCTF: GHA: fix vuln-verify 3
2026-03-17 16:22:39 +00:00
Tamas Koczka
64795d4bbf
kernelCTF: GHA: fix vuln-verify 2
2026-03-17 16:22:05 +00:00
Tamas Koczka
62e7342a46
kernelCTF: GHA: fix vuln-verify
2026-03-17 16:18:30 +00:00
Tamas Koczka
9f3972c34d
kernelCTF: add vuln-verify workflow
2026-03-17 16:10:11 +00:00
Tamas Koczka
5745a3c191
kernelCTF: add vuln-verify workflow
2026-03-17 15:56:18 +00:00
Artem Metla
a7d0bf1a33
kernelCTF: server: update to latest version
2026-03-17 14:14:32 +01:00
Tamás Koczka
50daccf87c
kernelCTF: rules: fix typo
2026-03-12 16:24:51 +01:00
Tamás Koczka
854319230b
kernelCTF: rules: make it clear that the patch needs to correctly fix the vulnerability
2026-03-12 16:24:11 +01:00
Stephen Roettger
fce98d0e79
[v8ctf] rm chrome M145
2026-03-11 13:18:19 +01:00
v8CTF github action
6f56de5508
[v8ctf] Update v8CTF challenges
2026-03-11 00:01:53 +00:00
Tamas Koczka
ff47cd117d
kernelCTF: server: update to latest version
2026-03-10 15:43:56 +00:00
conlonial77
eec2e575c8
Add kernelCTF CVE-2025-38500_lts_cos_mitigation ( #262 )
2026-03-10 12:15:31 +01:00
M Ramdhan
4a3a573cc2
add kernelCTF CVE-2025-40019_lts_cos_mitigation ( #305 )
2026-03-09 21:14:56 +01:00
M Ramdhan
d6af6af130
Add kernelCTF CVE-2025-39946_lts_cos ( #304 )
2026-03-09 21:09:46 +01:00
Tamas Koczka
06374d5f0f
kernelctf: move Android dep install script from kernelctf-submission-verification.yaml
2026-03-03 11:14:51 +00:00
Tamas Koczka
484489c406
kernelctf: remove unused .github/copilot-instructions.md
2026-03-03 11:09:12 +00:00
rcorrea35
8c18d23f7a
Update README.md
2026-03-02 09:25:26 -05:00
conlonial
570fc79afa
Add kernelCTF CVE-2024-50164_lts ( #267 )
2026-03-02 13:34:47 +01:00
st424204
571b5d0c0e
Add kernelCTF CVE-2024-58239_mitigation ( #254 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2024_58239_mitigation
* CVE-2024-58239_mitigation
* Update exploit.md
* AI_improve_PR
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-03-02 11:06:44 +01:00
st424204
d548a1c7fc
Add kernelCTF CVE-2025-37756-mitigation ( #255 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2025-37756-mitigation
* CVE-2025-37756_mitigation/
* CVE-2025-37756_mitigation/
* Update exploit.md
* Update exploit.md
* Improve_PR
* Fix_tls_record_comment
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-03-02 11:02:38 +01:00
Stephen Roettger
6463b8f475
v8ctf: rm M143
2026-03-02 10:50:56 +01:00
Tamás Koczka
07cdcf4346
kernelCTF: CVE-2025-39682: remove script from vulnerability.md as it is attached separately
...
This was breaking GHA page genereation
2026-03-02 10:34:18 +01:00
Salman Chishti
9c2154ae5a
Upgrade GitHub Actions for Node 24 compatibility ( #337 )
...
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com >
2026-03-02 10:25:34 +01:00
Salman Chishti
0b246115ee
Upgrade GitHub Actions to latest versions ( #338 )
...
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com >
2026-03-02 10:24:48 +01:00
artmetla
2914d2c208
Update rules.md
2026-02-27 18:06:38 +01:00
n132
95f6678d40
Add kernelCTF CVE-2025-38477_cos ( #268 )
...
* Add kernelCTF CVE-2025-38477_cos
* Add deps for CVE-2025-38477: libx
* CVE-2025-38477: Update metadata
* CVE-2025-38477: Update metadata
* Add CVE-2025-38477_cos: Solve the dep issue
* Add CVE-2025-38477_cos: debug mode
* resubmit: retry the checks
* Update exploit.md
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Fix the timeout issue
* CI: Retest
* More trial
* Update exploit.md
* Update exploit.md with vulnerability details
Clarify details about security vulnerabilities and mmap usage.
* CI: Retest
* CI Reset & document format
* reset
* Update with correct kaslr leak
* Update with correct kaslr leak
* Make it debugable
* [v8ctf] Update v8CTF challenges
* fix: kaslr leaking
* retry
* code for test
* code for test
* code for test
* code for test
* retest
* retest
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* Style: Using macros
* Trial: Try to remove the not important payload data
* comments: explain the exploit
* conflict: remove synced chrome stuff
* fix: check
* Style: Define the size sk_buff spray
* chore: remove unused var
* chore: remove unused var
* chore: remove comments
* chore: remove comments
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: explain the while loop
* chore: remove the dup write and I don't know if I gonna destroy the whole exp, figure cross!
* chore: more comments for exploitation
* Exploitation for Nperm
* More comment for used objects
* Writing: update
* Chore: writing
* Fix a wrong statement
* Doc: more explanation
* Doc: Tip for readers
* Fix: typo
* DoC: Details about nonfull_aggs
* Fix: typo
* Revert a change
* Doc: Clarify
* More explain
* Doc: Typo
* Doc: Typo
* Doc: Typo
* Doc: Typo
* Doc: Typo fixes
* Doc: Heap related
---------
Co-authored-by: swing <bestswngs@gmail.com >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-27 10:48:21 +01:00
conlonialC
746453d91c
Add kernelCTF CVE-2023-52433_mitigation ( #241 )
...
* Add CVE-2023-52433_mitigation
* Fix metadata.json
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix exploit
* fix comments
* fix comments
* fix comments
* fix commits
* fix commits
* Update exploit.md
---------
Co-authored-by: conlonial <kongln9170@gmail.com >
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com >
2026-02-27 10:42:56 +01:00
Artem Metla
e4e17f4c28
kernelCTF: server: update to latest version
2026-02-26 16:56:15 +01:00
liona24
eef74b8c02
Add kernelCTF CVE-2025-39946 mitigation ( #295 )
2026-02-26 14:16:02 +01:00
liona24
ce04c3f7c3
kernelCTF: CVE-2025-38350 ( #260 )
...
* Add kernelCTF CVE-2025-38350
* Fix debug build step (uses replace on gcc..)
* Add suggested style fixes
* Add note about RCU protection
2026-02-26 13:15:36 +01:00
st424204
e0c462526b
Add kernelCTF CVE-2024-26824_mitigation ( #256 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2024-26824_mitigation/
* CVE-2024-26824_mitigation
* fix
* Update metadata.json
* Update exploit.c
* Update exploit.c
* remove useless msg_msg
* Update exploit.c
* Update exploit.md
* Improve_PR
* Improve_PR
* done
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-25 22:12:05 +01:00
M Ramdhan
cf6a7dcc92
Add kernelCTF CVE-2025-39682_lts_cos_mitigation ( #251 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* add CVE-2025-39682_lts_cos_mitigation
* Update metadata.json
* Update metadata.json
* update metadata.json
* Improve exploit readability for all three targets (lts/cos/mitigation)
- Remove unused globals (buf2, sprayfd2) and remove unneeded sprayfd
socket spray that was confirmed unnecessary via remote testing
- Rename variables to descriptive names: pfd→splice_pipe, pfd2→uaf_pipe,
pfds→page_spray_pipes, addrs→pte_trigger_maps, dummy_serv/cli→aux_client/conn,
tpfd→victim_pte_pipe_fd, pa→core_pattern_pte, etc.
- Add #define constants with comments for all magic numbers:
PAGE_SPRAY_PIPE_COUNT, PTE_SPRAY_MAP_COUNT, PTE_MAP_STRIDE, PTE_FLAGS_RW,
PHYSMAP_ZERO_OFFSET, PHYSMAP_CORE_PATTERN
- Add top-level block comment explaining the full exploit chain
(page UAF → writable pipe → PTE reclaim → core_pattern write)
- Add numbered step comments throughout main() keyed to kernel function
names (tls_strp_load_anchor_with_queue, spd_fill_page, get_page, etc.)
- Rename TLS record variables to tls_appdata_record, tls_handshake_record,
tls_spliced_record for clarity
- All three targets verified working on remote after changes
* Extract TLS record generation script into docs/gen_tls_records.py
Resolves maintainer comment to move the inline Python script from
vulnerability.md into a standalone, runnable .py file.
---------
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
Co-authored-by: st424204 <st424204@yahoo.com.tw >
2026-02-25 18:19:59 +01:00
lonikon256k
c570685861
Add kernelCTF CVE-2025-38502_lts
2026-02-25 14:57:45 +01:00
Tamas Koczka
4f788eb87f
kernelCTF: server: update to latest version
2026-02-25 10:48:22 +00:00
Nevsor
1d1ab40015
Add kernelCTF CVE-2025-39965_cos ( #273 )
...
* Add kernelCTF CVE-2025-39965_cos
* Fix compiler flags for CI build
The GCC version used by the CI instance does not support "-std=c23"
* Remove an outdated and misleading log statement.
* Finish exploit.md
* Improve design of ASCII diagrams
Some characters rendered differently on GitHub than they did in VS Code. This should make the rendering a bit more robust.
2026-02-25 00:11:32 -08:00
Tamas Koczka
c3920dd9c0
kernelCTF: add few comments after review
2026-02-24 15:37:51 +00:00
st424204
ff349c26b3
Add kernelCTF CVE-2025-38616_lts_cos_mitigation ( #253 )
...
* [v8ctf] Update v8CTF challenges
* [v8ctf] Update v8CTF challenges
* CVE-2025-38616-lts-cos-mitigation
* X
* X
* X
* X
* X
* X
* fix lts
* fix lts
* fix lts
* fix lts
* fix lts
* test lts
* test lts
* Update exploit.md
* Update exploit.md
* Update exploit.c
* remove useless msg_msg
* Update exploit.md
* Improve_PR
* Improve exploit.md
* Improve
* Fix exploit.c
* Done
* Fix MIT
* Done
* Done
* Done
* done
* done
* done
---------
Co-authored-by: M Ramdhan <n0psledbyte@gmail.com >
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg >
Co-authored-by: v8CTF github action <sroettger@google.com >
2026-02-24 16:34:07 +01:00
st424204
8e99b67f87
Add kernelCTF CVE-2023-52926_lts ( #213 )
...
* init CVE-2023-52926
* Done
* improve_PR
2026-02-23 17:18:59 +01:00
ImV4bel
8e964c541c
Add kernelCTF CVE-2025-21756_lts_cos ( #205 )
...
* init
* modify exploit file
* modify Makefile
* modify exploit
* kernelCTF: remove CVE-2025-21756_cos as it did not pass tests
---------
Co-authored-by: Tamas Koczka <poprdi@google.com >
2026-02-23 16:05:33 +01:00