Skip to content

Add kernelCTF CVE-2026-23351_cos#371

Open
11X0r wants to merge 1 commit into
google:masterfrom
11X0r:CVE-2026-23351-cos
Open

Add kernelCTF CVE-2026-23351_cos#371
11X0r wants to merge 1 commit into
google:masterfrom
11X0r:CVE-2026-23351-cos

Conversation

@11X0r
Copy link
Copy Markdown

@11X0r 11X0r commented Apr 27, 2026

Novel technique submission for CVE-2026-23351 (nft_set_pipapo GC UAF).

Submission ID: exp475

Novel technique: nft_immediate_eval OOB dreg write. Bypasses stack canaries by writing at a controlled register index (dreg=54) past the canary into saved callee registers on the kernel stack. No stack pivot, no branch to arbitrary code. See docs/novel-techniques.md.

Target: cos-121-18867.381.30

@google-cla
Copy link
Copy Markdown

google-cla Bot commented Apr 27, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@11X0r 11X0r force-pushed the CVE-2026-23351-cos branch 12 times, most recently from 1da4422 to 584131d Compare April 27, 2026 13:25
@11X0r 11X0r force-pushed the CVE-2026-23351-cos branch from 584131d to 52195d7 Compare April 27, 2026 13:34
@11X0r 11X0r changed the title kernelctf: CVE-2026-23351_cos Add kernelctf: CVE-2026-23351_cos Apr 27, 2026
@11X0r 11X0r changed the title Add kernelctf: CVE-2026-23351_cos kernelCTF: CVE-2026-23351_cos Apr 27, 2026
@11X0r 11X0r changed the title kernelCTF: CVE-2026-23351_cos Add kernelCTF CVE-2026-23351_cos Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant