Loading video...

Video Failed to Load

Go Home

CVE-2023-3390: UAF on Linux Netfilter nftables MFT_MSG_NEWRULE leads to LPE. We exploit this tiny 1-day vuln to pwn all targets of Google's kernelCTF for the first time in history. Nice and clear triple-kill 🥳

67,444 views • 3 years ago •via X (Twitter)

6 Comments

c0m0r1's profile picture
c0m0r13 years ago

For details about vuln, exploit, and our novel techniques & research:

c0m0r1's profile picture
c0m0r13 years ago

Thanks to @0x10n for outstanding collaboration on COS exploit & post-exploit analysis, and @insu_yun & KAIST Hacking lab for unwavering support and encouragement!

h0mbre's profile picture
h0mbre3 years ago

this is awesome, great job writing all the exploits

Minghao Lin's profile picture
Minghao Lin3 years ago

Strong!

💫 Dor 🎗️'s profile picture
💫 Dor 🎗️3 years ago

nice

Alex Plaskett's profile picture
Alex Plaskett3 years ago

@insitusec Great work, thanks for sharing! Netfilter, the subsystem that keeps giving.

Related Videos