Re: MDWE does not prevent read-only, executable, shared memory regions to be updated by backing file writes

Ali Polatel via Bugspray Bot <[email protected]> Thu, 17 Jul 2025 13:15:08 +0000
Newsgroups dev.linux.lists.bugs,org.kvack.linux-mm
Message-ID <[email protected]>
Ali Polatel added an attachment on Kernel.org Bugzilla:

Created attachment 308384
Proof-of-Concept: MDWE bypass via file-backed RX mapping on Linux x86_64

Attached is a more complete POC which (ab)uses this bug to pop a shell. If I am correct, this means as an attacker I can use this to inject shellcode to most file-backed memory mappings and have it executed despite MDWE. Tested successfully on Linux-6.15.4 on x86_64.

File: mdwe-bypass-poc.c (text/x-csrc)
Size: 1.94 KiB
Link: https://bugzilla.kernel.org/attachment.cgi?id=308384
---
Proof-of-Concept: MDWE bypass via file-backed RX mapping on Linux x86_64

You can reply to this message to join the discussion.
-- 
Deet-doot-dot, I am a bot.
Kernel.org Bugzilla (bugspray 0.1-dev)