Get 20% off all career paths from fullstack to AI
Learn Excel and Financial Modeling the Way Finance Teams Actually Use Them
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk demonstrates how unprivileged scheduler system calls can widen narrow race windows enough to exploit bugs in the Linux kernel and Android userspace. It covers a Linux kernel race and an Android userspace race on a Google Pixel 2.
Syllabus
Intro
Translation Lookaside Buffer (TLB)
mremap() moving a memory mapping
fallocate() (de)allocate space for a file
Exploit plan: Basics
Buddy allocator
Preemption
Scheduler control
Android kernel exploit (app - zygote)
userfaultfd and FUSE
komp() for reliable UAF
FUSE for exploiting struct file refcount
int getpidcon(pid t pid, char **context)
Bug 3: race condition in hwservicemanager
_mutex on kernel 4.4
Priority Inversion
Major faults
Repeated file mapping faults
Taught by
Linux Foundation