CVE-2010-4258: Turning denial-of-service into privilege escalation

from blog Posts on Made of Bugs, | ↗ original
Dan Rosenberg recently released a privilege escalation bug for Linux, based on three different kernel vulnerabilities I reported recently. This post is about CVE-2010-4258, the most interesting of them, and, as Dan writes, the reason he wrote the exploit in the first place. In it, I’m going to do a brief tour of the various kernel features that...