rhodawk-ai-devops-engine / architect /skills /linux-kernel-exploitation.md
Rhodawk Agent
Round 1 sync β€” files missed in previous push
2798900
|
Raw
History Blame Contribute Delete
2.67 kB
---
name: linux-kernel-exploitation
domain: kernel
triggers:
languages: [c, asm, rust]
frameworks: [linux, bpf, kvm, io_uring]
asset_types: [kernel, driver, module, syscall, ebpf]
tools: [syzkaller, kasan, kfence, crash, gdb, drgn, bpftool]
severity_focus: [P1, P2]
---
# Linux Kernel Exploitation
## When to load
`drivers/`, `fs/`, `net/`, `kernel/`, `mm/`, any `*.ko` module source, eBPF
programs (`*.bpf.c`), or container-escape research.
## Bug classes (with payout tiers)
1. **UAF / double-free** in `slab` allocator β€” heap-spray with
`setxattr` / `msgsnd`, escalate via `cred` overlap. Pays $50K+.
2. **Type confusion** in BPF verifier β€” old classic, still finds in JIT
re-write paths.
3. **OOB write** β€” netlink, USB, Bluetooth, NFC drivers; structured-fuzz
with syzkaller.
4. **Race conditions** β€” userfaultfd, FUSE, `splice`, `pipe`. Win the race
with userfaultfd page-faults to extend the window.
5. **Reference-counting bugs** β€” `refcount_t` underflow, `get_task_struct`
forgotten on error path.
6. **eBPF abuse** β€” verifier bypass, helper return-value confusion, map
spray for arbitrary read/write.
7. **Namespace escapes** β€” user-namespace + capability mismatch,
`CAP_SYS_ADMIN` exposed inside container, shared kernel objects.
8. **Privileged file write** β€” overlayfs `redirect_dir`, copy_up race,
`/proc/<pid>/setgroups` history.
## Recon
- `make menuconfig` β†’ list enabled drivers (`CONFIG_*=y`).
- Diff against vendor kernel: `git log --oneline v6.1..stable` β†’
unmerged security fixes are gold.
- Run `syzkaller` with `enable_syscalls` filtered to the new code surface.
## Building the exploit
1. **Triage primitive** β€” what does the bug give you? OOB-R, OOB-W, UAF,
double-free, refcount underflow.
2. **Heap shape** β€” pick a victim object that overlaps the freed slab
class. Common: `cred`, `tty_struct`, `seq_operations`, `pipe_buffer`,
`msg_msg`.
3. **Spray** β€” `setxattr` (fine-grained), `msgsnd`/`msgrcv` (large), io_uring
(fast).
4. **Pivot** β€” gain arbitrary read first, leak `kallsyms` / `modprobe_path`,
then write `cred->uid = 0`.
5. **KASLR / SMEP / SMAP / KPTI bypass** β€” leak via prefetch side-channel
(Spectre-PHT), or use a stack pivot inside the kernel's own code.
## Sanitisers
Build with `CONFIG_KASAN=y CONFIG_KFENCE=y CONFIG_UBSAN=y
CONFIG_KCSAN=y`. Reproduce every crash in qemu+gdb with
`-append "kasan.fault=panic"`.
## Reporting (kernel.org coordinated disclosure)
Email `security@kernel.org` with PGP-encrypted report; expect 7-day
embargo; CVE assigned by MITRE via Linux CNA. PoC must include kernel
config + qemu invocation.