* Add CVE-2023-5717_mitigation * update * Improved speed * Improved speed * Improve speed * Adjust MIN, MAX * Remove race_id & Fix kernel mem layout for exploit * Adjust MIN, MAX * Improved exploit speed * Improved speed & relibility * Revert read() loops * Remove some stub codes * Finding r * Finding r * Finding r * Revert Timing * Adjust timing & Overwriting ptes across the entire page * FIx iteration * making more reliable memory layout? * Improved forming memory layout reliability * Fix useless codes * Testing * Testing * Fixed Typo * improved memory layout reliability * memory reliability * Fix counters being migrated to next event by scheduler * Fix missing timerfd * Fix pte limit * test * Increase iteration & ensure tlb is flushed * Flushing tlb effectively * Test * Using execve instead of system * Final version of exploit * Final * same * Last * Fix code styles * Fix code styles & docs * Fix code styles & docs * address review feedback
Security Research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
We believe that vulnerability disclosure is a two-way street. Vendors, as well as researchers, must act responsibly. This is why Google adheres to a 90-day disclosure deadline. We notify vendors of vulnerabilities immediately, with details shared in public with the defensive community after 90 days, or sooner if the vendor releases a fix.
You can read up on our full policy at: https://www.google.com/about/appsecurity/.
Advisories
The disclosure of vulnerabilities are all in the form of security advisories, which can be browsed in the Security Advisories page.
License & Patents
The advisories and patches posted here are free and open source.
See LICENSE for further details.
Contributing
The easiest way to contribute to our security research projects is to correct the patches when you see mistakes.
Please read up our Contribution policy.