The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution.
Compile: `gcc -o pwn pwn.c && gcc -o exploit exploit.c`
登录后查看神龙缓存的 POC 文件快照
登录查看