Timekiller: Escape From QEMU/KVM - Exploiting Asynchronous Clock Vulnerabilities
Hack In The Box Security Conference via YouTube
2,000+ Free Courses with Certificates: Coding, AI, SQL, and More
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk demonstrates Timekiller, an asynchronous-clock race technique for turning a heap overflow write in QEMU’s virtio-crypto device into a guest-to-host escape. It explains how the technique enables arbitrary address writes and makes otherwise difficult-to-exploit vulnerabilities exploitable.
Syllabus
#HITB2023HKT D1T2 - Timekiller: Escape From QEMU/KVM - Y. Jia, X. Lei, Yiming Tao, G. Pan & C. Wu
Taught by
Hack In The Box Security Conference