hn.today

I Found a $113,337 Af_alg Linux Local Privilege Escalation Before Copy Fail

idnsec.com6 points0 comments
Screenshot of I Found a $113,337 Af_alg Linux Local Privilege Escalation Before Copy Fail

CVE-2025-39964 is a local privilege-escalation race in the AF_ALG cryptographic socket path that a researcher discovered in 2025 and exploited to gain root and escape a Docker container, earning a $113,337 reward after responsible disclosure. The bug arises when two concurrent writers to the same AF_ALG opfd leave the context's merge flag set while the final scatterlist structure has cur equal to zero, causing the kernel to compute a negative index (sg -1) and perform an out-of-bounds scatterlist access. Controlled metadata in the preceding heap object turns that access into a usercopy oracle and an arbitrary kernel write; the exploit chain uses that write to overwrite core_pattern and execute code as root. The vulnerability predates wider attention to AF_ALG (e.g., Copy Fail) and was fixed upstream by preventing concurrent writes to a single AF_ALG socket.

Technically, AF_ALG accumulates input across sendmsg() calls using a context per accepted socket that holds a linked list of af_alg_tsgl objects, each with a cur counter and an array of scatterlist entries. sendmsg() with MSG_MORE lets the kernel append data into the last scatterlist entry rather than allocating a new one; when allocation and merge logic race, cur can be observed as zero while code still indexes the “last” entry, producing the out-of-bounds read/write. The flaw leverages memcpy_from_msg() behavior for the usercopy oracle and heap layout manipulation to convert the OOB access into a reliable arbitrary write, which the exploit uses to escalate privileges.

Read on idnsec.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.