Re: MDWE does not prevent read-only, executable, shared memory regions to be updated by backing file writes
Ali Polatel via Bugspray Bot <[email protected]> Thu, 17 Jul 2025 13:15:08 +0000
| Newsgroups | dev.linux.lists.bugs,org.kvack.linux-mm |
|---|---|
| Message-ID | <[email protected]> |
Ali Polatel added an attachment on Kernel.org Bugzilla: Created attachment 308384 Proof-of-Concept: MDWE bypass via file-backed RX mapping on Linux x86_64 Attached is a more complete POC which (ab)uses this bug to pop a shell. If I am correct, this means as an attacker I can use this to inject shellcode to most file-backed memory mappings and have it executed despite MDWE. Tested successfully on Linux-6.15.4 on x86_64. File: mdwe-bypass-poc.c (text/x-csrc) Size: 1.94 KiB Link: https://bugzilla.kernel.org/attachment.cgi?id=308384 --- Proof-of-Concept: MDWE bypass via file-backed RX mapping on Linux x86_64 You can reply to this message to join the discussion. -- Deet-doot-dot, I am a bot. Kernel.org Bugzilla (bugspray 0.1-dev)