Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2020-8835 — CVE-2020-8835에 대한 개념 증명 익스플로잇으로, Linux 커널 BPF 검증기 취약점으로 인해 경계를 벗어난 메모리 접근 및 권한 상승이 가능합니다. 컴파일 지침과 sysctl 기반 완화 절차를 포함합니다. | Kitploit
도구/GitHubGitHub/zilong3033/cve-2020-8835
Privilege EscalationVulnerability AnalysisExploitationBinary Exploitation
GitHubzilong3033/cve-2020-8835

CVE-2020-8835

CVE-2020-8835에 대한 개념 증명 익스플로잇으로, Linux 커널 BPF 검증기 취약점으로 인해 경계를 벗어난 메모리 접근 및 권한 상승이 가능합니다. 컴파일 지침과 sysctl 기반 완화 절차를 포함합니다.

저장소 보기
716년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2020-8835

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) 
does not properly restrict the register bounds for 32-bit operations,
leading to out-of-bounds reads and writes in kernel memory. 

This vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7,
as the introducing commit was backported to that branch. 
This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29.

Mitigation for this vulnerability is available by setting the 
'kernel.unprivileged_bpf_disabled' sysctl to '1'.
This disables unprivileged access to the bpf() syscall entirely.

This issue is also mitigated on systems that use secure
boot, because of the kernel lockdown feature which blocks
BPF program loading.

컴파일

gcc -o exploit ./exploit.c

완화

Ubuntu
$ sudo sysctl kernel.unprivileged_bpf_disabled=1

$ echo kernel.unprivileged_bpf_disabled=1 | \
  sudo tee /etc/sysctl.d/90-CVE-2020-8835.conf
Redhat
$ sysctl -w kernel.unprivileged_bpf_disabled=1
도구 다운로드