
DEF CON 32 - Clash, Burn, and Exploit Manipulate Filters to Pwn kernelCTF - HexRabbit Chen
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 37:42
The speaker shares their journey discovering and exploiting vulnerabilities in Linux kernel NF tables during Google's CTF, ultimately earning their first Google VIP bounty after overcoming multiple technical and timing challenges.
• A double-free vulnerability in NF table object lifetime management was found due to incorrect use of NF is active checks during prepare phase, allowing repeated deletion of elements 4:55-5:47.
• A use-after-free vulnerability in the nft log expression caused out-of-bounds access to a global array, leading to type confusion and RCU head manipulation to control RIP 15:33-19:32.
• A race condition in the GC transaction API bypassed safety checks due to a timing window in module autoload, enabling double-free of set elements 30:52-32:58.
Despite multiple attempts, the speaker's exploit was ultimately accepted after a prior submission was disqualified due to a collision, securing their first Google VIP bounty. The journey highlights the challenges of zero-day research under tight constraints, including kernel config mismatches and the eventual disabling of NF tables from April 1.
Sources:
- 4:55 Discussion of double-free vulnerability in NF table object lifetime management
- 15:33 Explanation of out-of-bounds access and RCU manipulation in nft log expression
- 30:52 Detailed analysis of GC race condition and module autoload timing window
- 35:18 Announcement of NF tables being disabled from April 1, impacting exploit viability
- 36:28 Final submission acceptance after prior entry disqua
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
and with no further Ado please continue hello everyone and welcome to my talk Clash burn and Export manipulate filters to P Kel CF I'm hexit from Taiwan currently working as a security researcher at def cor I specialize in B export especially in lens kental exploitation I found some vulnerabilities in ly internal component like a urine kmbd NS tables and others today I will start from introducing Kel CTF and NF tables after that we will dive into the NS table internals and talk about three V abilities we discovered in NS T tables and in between these three viabilities I will also share some story behind the scene during my current CTF Journey so let's talk about first talk about the current CTF current CTF is part of Google vrp and the way it works is quite similar to a CTF challenge for a…