Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2022-27666 | Kitploit
ツール/GitHubGitHub/ngtuonghung/cve-2022-27666
メモリフォレンジック脆弱性分析エクスプロイトデバッガバイナリエクスプロイト
GitHubngtuonghung/cve-2022-27666

CVE-2022-27666

リポジトリを見る
3ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2022-27666

Linux カーネルの IPsec ESP6 実装におけるヒープバッファオーバーフロー (linux 5.13.19)。


セットアップ (root ユーザーを想定)

1. カーネルのビルド (VM 内)

依存関係のインストール:

root@kitploit:~
apt update && apt install -y \
    build-essential bc bison flex \
    libssl-dev libelf-dev libncurses-dev \
    dwarves pahole gcc make wget xz-utils git python3 libfuse3-dev

ダウンロードと展開:

root@kitploit:~
cd /home/ubuntu/
wget https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.13.19.tar.xz
tar xf linux-5.13.19.tar.xz
cd linux-5.13.19

設定:

root@kitploit:~
cp /boot/config-$(uname -r) .config
make olddefconfig

# Enable full debug symbols and GDB support
scripts/config --enable  CONFIG_DEBUG_INFO
scripts/config --enable  CONFIG_DEBUG_INFO_DWARF4
scripts/config --disable CONFIG_DEBUG_INFO_REDUCED
scripts/config --enable  CONFIG_FRAME_POINTER
scripts/config --enable  CONFIG_GDB_SCRIPTS

# Build ESP modules — CVE target
scripts/config --module  CONFIG_INET6_ESP
scripts/config --module  CONFIG_INET_ESP

# Disable KASLR for easier debugging
scripts/config --disable CONFIG_RANDOMIZE_BASE

# Disable module signing to load unsigned modules
scripts/config --disable CONFIG_MODULE_SIG
scripts/config --disable CONFIG_MODULE_SIG_FORCE
scripts/config --disable CONFIG_SYSTEM_TRUSTED_KEYS
scripts/config --disable CONFIG_SYSTEM_REVOCATION_KEYS

# Disable BTF to avoid pahole build errors
scripts/config --disable CONFIG_DEBUG_INFO_BTF

# Disable watchdog to prevent panic/reboot during GDB breakpoints
scripts/config --disable CONFIG_SOFTLOCKUP_DETECTOR
scripts/config --disable CONFIG_HARDLOCKUP_DETECTOR
scripts/config --disable CONFIG_DETECT_HUNG_TASK
scripts/config --disable CONFIG_WQ_WATCHDOG

make olddefconfig

ビルドとインストール:

root@kitploit:~
make -j$(nproc) 2>&1 | tee ~/build.log

make modules_install
make install
update-grub

2. カーネル 5.13.19 で起動

root@kitploit:~
# Find menu entry index
grep -E "menuentry|submenu" /boot/grub/grub.cfg | grep -v "^#" | head -20

# Set default (adjust index as needed)
vi /etc/default/grub
# GRUB_DEFAULT="1>2"

update-grub
reboot

再起動後に確認:

root@kitploit:~
uname -r          # should print 5.13.19

# Auto-load esp6 on boot and load it now
echo "esp6" >> /etc/modules
modprobe esp6

# Verify
modinfo esp6
grep CONFIG_INET6_ESP /boot/config-5.13.19   # CONFIG_INET6_ESP=m

不要なサービスを無効化して、起動を高速化し、テスト中の干渉を防ぎます:

root@kitploit:~
# Cloud / network wait
systemctl disable cloud-init cloud-config cloud-final \
    cloud-init-local systemd-networkd-wait-online

# Prevent crash reporter from interfering with kernel panics
systemctl disable apport

# Prevent random disk I/O during testing
systemctl disable apt-daily apt-daily-upgrade \
    apt-daily.timer apt-daily-upgrade.timer

# Not needed in a dev VM
systemctl disable snapd multipathd fwupd

デバッグセットアップ

シンボル用に vmlinux をコピー (ホスト側)

root@kitploit:~
IP=<VM-IP>
scp ubuntu@${IP}:~/linux-5.13.19/vmlinux .
scp ubuntu@${IP}:~/linux-5.13.19/net/ipv6/esp6.ko .
scp ubuntu@${IP}:/usr/bin/fusermount3 ./exploit/bin/
scp ubuntu@${IP}:/usr/lib/x86_64-linux-gnu/libfuse3.so.3 ./exploit/lib/
scp -r ubuntu@${IP}:/usr/include/fuse3 ./exploit/include/

QEMU/libvirt で GDB スタブを有効化

ドメイン XML に追加:

root@kitploit:~
<domain type='kvm' xmlns:qemu='http://libvirt.org/schemas/domain/qemu/1.0'>
  ...
  <qemu:commandline>
    <qemu:arg value='-s'/>
  </qemu:commandline>
</domain>

ホストディレクトリを VM と共有

ドメイン XML の <devices> 内に追加:

root@kitploit:~
<filesystem type='mount' accessmode='passthrough'>
  <source dir='/path/to/your/host/dir'/>
  <target dir='hostshare'/>
</filesystem>

VM 内でマウント:

root@kitploit:~
mkdir -p /pwn
mount -t 9p -o trans=virtio hostshare /pwn
ツールをダウンロード