FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Fix known security issues in Shiva · Issue #9 · advanced-microcode-patching/shiva · GitHub

Repository navigation

Fix known security issues in Shiva #9

Description

  1. Remove the global reference to context. Currently we have: struct shiva_ctx *ctx_global defined as a global initialized variable in shiva.c. This global variable is predictable in the AARCH64 version because our Interpreter is an ET_EXEC (vs. PIE ET_DYN). This means that an attacker who's exploiting a memory corruption vulnerability could use this as leak to determine the ASLR space or gain access to other read/write primitives.

(Will add more to the list)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


    Back | FazBrowse Home | New Git URL