Toot

Written by Jann Horn on 2024-10-12 at 13:01

@ljs @brenns10 there was a fun anon_vma ->degree confusion bug that was fixed in 2022, where an assumption in vma mergability checks is broken and you can get an anon page mapped in a VMA which is not connected to the page's anon_vma, and that leads to anon_vma UAF

https://project-zero.issues.chromium.org/issues/42451486

=> More informations about this toot | View the thread | More toots from jann@infosec.exchange

Mentions

=> View ljs@social.kernel.org profile | View brenns10@snake.club profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113294579481621968
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
221.004036 milliseconds
Gemini-to-HTML Time
0.542646 milliseconds

This content has been proxied by September (3851b).