
Heap buffer overflow exploit for CVE-2022-27666 in Linux kernel IPsec ESP6 implementation. Includes kernel build, debug setup with GDB stub, and exploitation steps for version 5.13.19.
Heap buffer overflow in Linux kernel's IPsec ESP6 implementation (linux 5.13.19).
Install dependencies:
apt update && apt install -y \
build-essential bc bison flex \
libssl-dev libelf-dev libncurses-dev \
dwarves pahole gcc make wget xz-utils git python3 libfuse3-dev
Download and extract:
cd /home/ubuntu/
wget https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.13.19.tar.xz
tar xf linux-5.13.19.tar.xz
cd linux-5.13.19
Configure:
cp /boot/config-$(uname -r) .config
make olddefconfig
# Enable full debug symbols and GDB support
scripts/config --enable CONFIG_DEBUG_INFO
scripts/config --enable CONFIG_DEBUG_INFO_DWARF4
scripts/config --disable CONFIG_DEBUG_INFO_REDUCED
scripts/config --enable CONFIG_FRAME_POINTER
scripts/config --enable CONFIG_GDB_SCRIPTS
# Build ESP modules — CVE target
scripts/config --module CONFIG_INET6_ESP
scripts/config --module CONFIG_INET_ESP
# Disable KASLR for easier debugging
scripts/config --disable CONFIG_RANDOMIZE_BASE
# Disable module signing to load unsigned modules
scripts/config --disable CONFIG_MODULE_SIG
scripts/config --disable CONFIG_MODULE_SIG_FORCE
scripts/config --disable CONFIG_SYSTEM_TRUSTED_KEYS
scripts/config --disable CONFIG_SYSTEM_REVOCATION_KEYS
# Disable BTF to avoid pahole build errors
scripts/config --disable CONFIG_DEBUG_INFO_BTF
# Disable watchdog to prevent panic/reboot during GDB breakpoints
scripts/config --disable CONFIG_SOFTLOCKUP_DETECTOR
scripts/config --disable CONFIG_HARDLOCKUP_DETECTOR
scripts/config --disable CONFIG_DETECT_HUNG_TASK
scripts/config --disable CONFIG_WQ_WATCHDOG
make olddefconfig
Build and install:
make -j$(nproc) 2>&1 | tee ~/build.log
make modules_install
make install
update-grub
# Find menu entry index
grep -E "menuentry|submenu" /boot/grub/grub.cfg | grep -v "^#" | head -20
# Set default (adjust index as needed)
vi /etc/default/grub
# GRUB_DEFAULT="1>2"
update-grub
reboot
Verify after reboot:
uname -r # should print 5.13.19
# Auto-load esp6 on boot and load it now
echo "esp6" >> /etc/modules
modprobe esp6
# Verify
modinfo esp6
grep CONFIG_INET6_ESP /boot/config-5.13.19 # CONFIG_INET6_ESP=m
Disable unnecessary services to speed up boot and avoid interference during testing:
# Cloud / network wait
systemctl disable cloud-init cloud-config cloud-final \
cloud-init-local systemd-networkd-wait-online
# Prevent crash reporter from interfering with kernel panics
systemctl disable apport
# Prevent random disk I/O during testing
systemctl disable apt-daily apt-daily-upgrade \
apt-daily.timer apt-daily-upgrade.timer
# Not needed in a dev VM
systemctl disable snapd multipathd fwupd
IP=<VM-IP>
scp ubuntu@${IP}:~/linux-5.13.19/vmlinux .
scp ubuntu@${IP}:~/linux-5.13.19/net/ipv6/esp6.ko .
scp ubuntu@${IP}:/usr/bin/fusermount3 ./exploit/bin/
scp ubuntu@${IP}:/usr/lib/x86_64-linux-gnu/libfuse3.so.3 ./exploit/lib/
scp -r ubuntu@${IP}:/usr/include/fuse3 ./exploit/include/
Add to domain XML:
<domain type='kvm' xmlns:qemu='http://libvirt.org/schemas/domain/qemu/1.0'>
...
<qemu:commandline>
<qemu:arg value='-s'/>
</qemu:commandline>
</domain>
Add inside <devices> in domain XML:
<filesystem type='mount' accessmode='passthrough'>
<source dir='/path/to/your/host/dir'/>
<target dir='hostshare'/>
</filesystem>
Mount inside VM:
mkdir -p /pwn
mount -t 9p -o trans=virtio hostshare /pwn