Add kernelCTF CVE-2025-37798_lts_cos_mitigation#301
Add kernelCTF CVE-2025-37798_lts_cos_mitigation#301phlaie wants to merge 7 commits intogoogle:masterfrom
Conversation
|
LTS only had 70% stability, which would make it ineligible for the stability bonus. I am running the tests again to see if stability will be better this time. |
|
Thanks for the catch. I think there might be some issues with the prefetch sidechannel (used to get KASLR leak) when on Github Actions runner. I'll check again. |
|
Hey! If I compile the 6.6 stable version of the patch commit (https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=829c49b6b2ff45b043739168fd1245e4e1a91a30) with KASAN and run the exploit, it still crashes the kernel just earlier at a different place: Can you help us understand why is that? Is this patch commit complete and fixes the vulnerability properly? (This blocks the payout of the first half of the reward.) Logs after the patch: Compared with before the patch (parent commit of 829c49b - https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=24e6280cdd7f8d01fc6b9b365fb800c2fb7ea9bb): |
|
@koczkatamas I've fixed the reliability issues stemming from the prefetch side-channel leak. Let me get back to you on the KASAN crash report. |
No description provided.