Commit Graph

581 Commits

Author SHA1 Message Date
Tamas Koczka 849fd2ca92 kernelCTF: GHA: vuln-verify: fix 2026-03-17 19:59:04 +00:00
Tamas Koczka 632bde3461 kernelCTF: GHA: vuln-verify: support bold in summary 2026-03-17 19:54:03 +00:00
Tamas Koczka ea96600258 kernelCTF: GHA: vuln-verify: artifact fix 2026-03-17 19:51:06 +00:00
Tamas Koczka 820ba83368 kernelCTF: GHA: vuln-verify upload logs as artifacts, write summary 2026-03-17 19:46:01 +00:00
Tamas Koczka b5ff798f4c kernelCTF: GHA: vuln-verify fix 2026-03-17 19:13:46 +00:00
Tamas Koczka 3fcf07fd75 kernelCTF: GHA: vuln-verify: faster checkout, fix gzip upload, less noisy cache logs 2026-03-17 19:09:54 +00:00
Tamas Koczka d72dbc86f6 kernelCTF: GHA: verbose build output for vuln-verify (fix 1) 2026-03-17 17:30:44 +00:00
Tamas Koczka a1d2773964 kernelCTF: GHA: verbose build output for vuln-verify 2026-03-17 17:24:21 +00:00
Tamas Koczka 37e1915258 kernelCTF: GHA: fix vuln-verify 6 2026-03-17 16:57:17 +00:00
Tamas Koczka 6dbbfe9da1 kernelCTF: GHA: fix vuln-verify 5 2026-03-17 16:37:54 +00:00
Tamas Koczka 387bf1e4b6 kernelCTF: GHA: fix vuln-verify 4 2026-03-17 16:35:09 +00:00
Tamas Koczka df26939f96 kernelCTF: GHA: fix vuln-verify 3 2026-03-17 16:22:39 +00:00
Tamas Koczka 64795d4bbf kernelCTF: GHA: fix vuln-verify 2 2026-03-17 16:22:05 +00:00
Tamas Koczka 62e7342a46 kernelCTF: GHA: fix vuln-verify 2026-03-17 16:18:30 +00:00
Tamas Koczka 9f3972c34d kernelCTF: add vuln-verify workflow 2026-03-17 16:10:11 +00:00
Tamas Koczka 5745a3c191 kernelCTF: add vuln-verify workflow 2026-03-17 15:56:18 +00:00
Artem Metla a7d0bf1a33 kernelCTF: server: update to latest version 2026-03-17 14:14:32 +01:00
Tamás Koczka 50daccf87c kernelCTF: rules: fix typo 2026-03-12 16:24:51 +01:00
Tamás Koczka 854319230b kernelCTF: rules: make it clear that the patch needs to correctly fix the vulnerability 2026-03-12 16:24:11 +01:00
Stephen Roettger fce98d0e79 [v8ctf] rm chrome M145 2026-03-11 13:18:19 +01:00
v8CTF github action 6f56de5508 [v8ctf] Update v8CTF challenges 2026-03-11 00:01:53 +00:00
Tamas Koczka ff47cd117d kernelCTF: server: update to latest version 2026-03-10 15:43:56 +00:00
conlonial77 eec2e575c8 Add kernelCTF CVE-2025-38500_lts_cos_mitigation (#262) 2026-03-10 12:15:31 +01:00
M Ramdhan 4a3a573cc2 add kernelCTF CVE-2025-40019_lts_cos_mitigation (#305) 2026-03-09 21:14:56 +01:00
M Ramdhan d6af6af130 Add kernelCTF CVE-2025-39946_lts_cos (#304) 2026-03-09 21:09:46 +01:00
Tamas Koczka 06374d5f0f kernelctf: move Android dep install script from kernelctf-submission-verification.yaml 2026-03-03 11:14:51 +00:00
Tamas Koczka 484489c406 kernelctf: remove unused .github/copilot-instructions.md 2026-03-03 11:09:12 +00:00
rcorrea35 8c18d23f7a Update README.md 2026-03-02 09:25:26 -05:00
conlonial 570fc79afa Add kernelCTF CVE-2024-50164_lts (#267) 2026-03-02 13:34:47 +01:00
st424204 571b5d0c0e Add kernelCTF CVE-2024-58239_mitigation (#254)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2024_58239_mitigation

* CVE-2024-58239_mitigation

* Update exploit.md

* AI_improve_PR

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-03-02 11:06:44 +01:00
st424204 d548a1c7fc Add kernelCTF CVE-2025-37756-mitigation (#255)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2025-37756-mitigation

* CVE-2025-37756_mitigation/

* CVE-2025-37756_mitigation/

* Update exploit.md

* Update exploit.md

* Improve_PR

* Fix_tls_record_comment

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-03-02 11:02:38 +01:00
Stephen Roettger 6463b8f475 v8ctf: rm M143 2026-03-02 10:50:56 +01:00
Tamás Koczka 07cdcf4346 kernelCTF: CVE-2025-39682: remove script from vulnerability.md as it is attached separately
This was breaking GHA page genereation
2026-03-02 10:34:18 +01:00
Salman Chishti 9c2154ae5a Upgrade GitHub Actions for Node 24 compatibility (#337)
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
2026-03-02 10:25:34 +01:00
Salman Chishti 0b246115ee Upgrade GitHub Actions to latest versions (#338)
Signed-off-by: Salman Muin Kayser Chishti <13schishti@gmail.com>
2026-03-02 10:24:48 +01:00
artmetla 2914d2c208 Update rules.md 2026-02-27 18:06:38 +01:00
n132 95f6678d40 Add kernelCTF CVE-2025-38477_cos (#268)
* Add kernelCTF CVE-2025-38477_cos

* Add deps for CVE-2025-38477: libx

* CVE-2025-38477: Update metadata

* CVE-2025-38477: Update metadata

* Add CVE-2025-38477_cos: Solve the dep issue

* Add CVE-2025-38477_cos: debug mode

* resubmit: retry the checks

* Update exploit.md

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Fix the timeout issue

* CI: Retest

* More trial

* Update exploit.md

* Update exploit.md with vulnerability details

Clarify details about security vulnerabilities and mmap usage.

* CI: Retest

* CI Reset & document format

* reset

* Update with correct kaslr leak

* Update with correct kaslr leak

* Make it debugable

* [v8ctf] Update v8CTF challenges

* fix: kaslr leaking

* retry

* code for test

* code for test

* code for test

* code for test

* retest

* retest

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* Style: Using macros

* Trial: Try to remove the not important payload data

* comments: explain the exploit

* conflict: remove synced chrome stuff

* fix: check

* Style: Define the size sk_buff spray

* chore: remove unused var

* chore: remove unused var

* chore: remove comments

* chore: remove comments

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: explain the while loop

* chore: remove the dup write and I don't know if I gonna destroy the whole exp, figure cross!

* chore: more comments for exploitation

* Exploitation for Nperm

* More comment for used objects

* Writing: update

* Chore: writing

* Fix a wrong statement

* Doc: more explanation

* Doc: Tip for readers

* Fix: typo

* DoC: Details about nonfull_aggs

* Fix: typo

* Revert a change

* Doc: Clarify

* More explain

* Doc: Typo

* Doc: Typo

* Doc: Typo

* Doc: Typo

* Doc: Typo fixes

* Doc: Heap related

---------

Co-authored-by: swing <bestswngs@gmail.com>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-27 10:48:21 +01:00
conlonialC 746453d91c Add kernelCTF CVE-2023-52433_mitigation (#241)
* Add CVE-2023-52433_mitigation

* Fix metadata.json

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix exploit

* fix comments

* fix comments

* fix comments

* fix commits

* fix commits

* Update exploit.md

---------

Co-authored-by: conlonial <kongln9170@gmail.com>
Co-authored-by: artmetla <77324544+artmetla@users.noreply.github.com>
2026-02-27 10:42:56 +01:00
Artem Metla e4e17f4c28 kernelCTF: server: update to latest version 2026-02-26 16:56:15 +01:00
liona24 eef74b8c02 Add kernelCTF CVE-2025-39946 mitigation (#295) 2026-02-26 14:16:02 +01:00
liona24 ce04c3f7c3 kernelCTF: CVE-2025-38350 (#260)
* Add kernelCTF CVE-2025-38350

* Fix debug build step (uses replace on gcc..)

* Add suggested style fixes

* Add note about RCU protection
2026-02-26 13:15:36 +01:00
st424204 e0c462526b Add kernelCTF CVE-2024-26824_mitigation (#256)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2024-26824_mitigation/

* CVE-2024-26824_mitigation

* fix

* Update metadata.json

* Update exploit.c

* Update exploit.c

* remove useless msg_msg

* Update exploit.c

* Update exploit.md

* Improve_PR

* Improve_PR

* done

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-25 22:12:05 +01:00
M Ramdhan cf6a7dcc92 Add kernelCTF CVE-2025-39682_lts_cos_mitigation (#251)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* add CVE-2025-39682_lts_cos_mitigation

* Update metadata.json

* Update metadata.json

* update metadata.json

* Improve exploit readability for all three targets (lts/cos/mitigation)

- Remove unused globals (buf2, sprayfd2) and remove unneeded sprayfd
  socket spray that was confirmed unnecessary via remote testing
- Rename variables to descriptive names: pfd→splice_pipe, pfd2→uaf_pipe,
  pfds→page_spray_pipes, addrs→pte_trigger_maps, dummy_serv/cli→aux_client/conn,
  tpfd→victim_pte_pipe_fd, pa→core_pattern_pte, etc.
- Add #define constants with comments for all magic numbers:
  PAGE_SPRAY_PIPE_COUNT, PTE_SPRAY_MAP_COUNT, PTE_MAP_STRIDE, PTE_FLAGS_RW,
  PHYSMAP_ZERO_OFFSET, PHYSMAP_CORE_PATTERN
- Add top-level block comment explaining the full exploit chain
  (page UAF → writable pipe → PTE reclaim → core_pattern write)
- Add numbered step comments throughout main() keyed to kernel function
  names (tls_strp_load_anchor_with_queue, spd_fill_page, get_page, etc.)
- Rename TLS record variables to tls_appdata_record, tls_handshake_record,
  tls_spliced_record for clarity
- All three targets verified working on remote after changes

* Extract TLS record generation script into docs/gen_tls_records.py

Resolves maintainer comment to move the inline Python script from
vulnerability.md into a standalone, runnable .py file.

---------

Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
Co-authored-by: st424204 <st424204@yahoo.com.tw>
2026-02-25 18:19:59 +01:00
lonikon256k c570685861 Add kernelCTF CVE-2025-38502_lts 2026-02-25 14:57:45 +01:00
Tamas Koczka 4f788eb87f kernelCTF: server: update to latest version 2026-02-25 10:48:22 +00:00
Nevsor 1d1ab40015 Add kernelCTF CVE-2025-39965_cos (#273)
* Add kernelCTF CVE-2025-39965_cos

* Fix compiler flags for CI build

The GCC version used by the CI instance does not support "-std=c23"

* Remove an outdated and misleading log statement.

* Finish exploit.md

* Improve design of ASCII diagrams

Some characters rendered differently on GitHub than they did in VS Code. This should make the rendering a bit more robust.
2026-02-25 00:11:32 -08:00
Tamas Koczka c3920dd9c0 kernelCTF: add few comments after review 2026-02-24 15:37:51 +00:00
st424204 ff349c26b3 Add kernelCTF CVE-2025-38616_lts_cos_mitigation (#253)
* [v8ctf] Update v8CTF challenges

* [v8ctf] Update v8CTF challenges

* CVE-2025-38616-lts-cos-mitigation

* X

* X

* X

* X

* X

* X

* fix lts

* fix lts

* fix lts

* fix lts

* fix lts

* test lts

* test lts

* Update exploit.md

* Update exploit.md

* Update exploit.c

* remove useless msg_msg

* Update exploit.md

* Improve_PR

* Improve exploit.md

* Improve

* Fix exploit.c

* Done

* Fix MIT

* Done

* Done

* Done

* done

* done

* done

---------

Co-authored-by: M Ramdhan <n0psledbyte@gmail.com>
Co-authored-by: Gerrard <gerrard.tai@starlabs.sg>
Co-authored-by: v8CTF github action <sroettger@google.com>
2026-02-24 16:34:07 +01:00
st424204 8e99b67f87 Add kernelCTF CVE-2023-52926_lts (#213)
* init CVE-2023-52926

* Done

* improve_PR
2026-02-23 17:18:59 +01:00
ImV4bel 8e964c541c Add kernelCTF CVE-2025-21756_lts_cos (#205)
* init

* modify exploit file

* modify Makefile

* modify exploit

* kernelCTF: remove CVE-2025-21756_cos as it did not pass tests

---------

Co-authored-by: Tamas Koczka <poprdi@google.com>
2026-02-23 16:05:33 +01:00