Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2019-18885 — Prova de conceito para uma desreferência de ponteiro nulo no sistema de arquivos BTRFS do kernel Linux (CVE-2019-18885), incluindo uma imagem personalizada, etapas de reprodução e logs do KASAN. | Kitploit
Ferramentas/GitHubGitHub/bobfuzzer/cve-2019-18885
Análise de VulnerabilidadesFuzzingCTFAprendizado e EducaçãoExploração de Binários
GitHubbobfuzzer/cve-2019-18885

CVE-2019-18885

Prova de conceito para uma desreferência de ponteiro nulo no sistema de arquivos BTRFS do kernel Linux (CVE-2019-18885), incluindo uma imagem personalizada, etapas de reprodução e logs do KASAN.

Ver Repositório
2312há 5 anosAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

CVE-2019-18885

  • CVE-2019-18885
    • bobfuzzer
      • Membros da Equipe
    • Informações
      • Visão Geral
      • Alvo
      • Reprodução
      • Causas do Bug
      • Visão do Depurador
      • Logs do KASAN
    • Agradecimentos

bobfuzzer

equipe do projeto no BoB (Best of the Best), República da Coreia. ([email protected])

encontrando bugs em módulos do sistema de arquivos do kernel Linux

Membros da Equipe

Membro do Projeto: 김동희(Kieast), 조형진(zkaryaJo), 홍승표(Ph4nt0m), 남지효(NJhyo), 정원영(nonetype)

Líder do Projeto: 조성준(DelspoN)

Mentor do Projeto: 이상섭(k1rh4), 박천성(Ashine)


Informações

desreferência de ponteiro nulo em btrfs_verify_dev_extents (entrada da lista de loop)

Visão Geral

ao montar uma imagem btrfs maliciosa, ocorre Null-Ptr-Deref.

Alvo

Testado no sistema de arquivos BTRFS do Kernel Linux 5.0.21 (fonte aqui)

(Pode ser necessária a opção CONFIG_BTRFS_FS=m.)

Reprodução

imagem maliciosa anexada aqui

mkdir ./mnt
mount -t btrfs ./poc_2019_18885.img ./mnt

Causas do Bug

fs/btrfs/volumes.c:430

static struct btrfs_device *find_device(struct btrfs_fs_devices *fs_devices,
		u64 devid, const u8 *uuid)
{
	struct btrfs_device *dev;

[1]	list_for_each_entry(dev, &fs_devices->devices, dev_list) {
		if (dev->devid == devid &&
		    (!uuid || !memcmp(dev->uuid, uuid, BTRFS_UUID_SIZE))) {
			return dev;
		}
	}
	return NULL;
}

no loop list_for_each_entry ([1]), a entrada da lista &fs_devices->devices pode ser NULL

Visão do Depurador

[ Legend: Modified register | Code | Heap | Stack | String ]
─────────────────────────────────────────────────────────── registers ────
$rax   : 0x0000000000000000  →  0x0000000000000000
$rbx   : 0xdffffc0000000000  →  0xdffffc0000000000
$rcx   : 0x0000000000000098  →  0x0000000000000098
$rdx   : 0x0000000000000013  →  0x0000000000000013
$rsp   : 0xffff888063d4e620  →  0xffff888067d9a200  →  0x1e44a09cf7d0cbce →  0x1e44a09cf7d0cbce
$rbp   : 0x0000000000c00000  →  0x0000000000c00000
$rsi   : 0x0000000000000001  →  0x0000000000000001
$rdi   : 0xffff88806a4eb248  →  0x0000000000000000  →  0x0000000000000000
$rip   : 0xffffffff81def0e8  →  0x0890850f001a3c80  →  0x0890850f001a3c80
$r8    : 0x1ffff1100d49d781  →  0x1ffff1100d49d781
$r9    : 0x0000000000000000  →  0x0000000000000000
$r10   : 0x0000000000000001  →  0x0000000000000001
$r11   : 0xffffed100cfb3463  →  0x0000000000000000  →  0x0000000000000000
$r12   : 0x0000000000000000  →  0x0000000000000000
$r13   : 0xffff888069f3b4d0  →  0xffff888069d0a560  →  0x0000000001c09000 →  0x0000000001c09000
$r14   : 0x0000000000000001  →  0x0000000000000001
$r15   : 0xffff8880696ee1a0  →  0xffff8880696ee000  →  0x0000000000000001 →  0x0000000000000001
$eflags: [zero carry parity adjust sign trap INTERRUPT direction overflowresume virtualx86 identification]
$cs: 0x0010 $ss: 0x0018 $ds: 0x0000 $es: 0x0000 $fs: 0x0000 $gs: 0x0000
─────────────────────────────────────────────────────────────── stack ────
0xffff888063d4e620│+0x0000: 0xffff888067d9a200  →  0x1e44a09cf7d0cbce  →0x1e44a09cf7d0cbce	 ← $rsp
0xffff888063d4e628│+0x0008: 0xffff888063d4e6b8  →  0x0000000000000001  →0x0000000000000001
0xffff888063d4e630│+0x0010: 0xffffed100c7a9cdf  →  0x00000000f2f8f8f8  →0x00000000f2f8f8f8
0xffff888063d4e638│+0x0018: 0x0000000000800000  →  0x0000000000800000
0xffff888063d4e640│+0x0020: 0xffff888063d4e6c0  →  0x00000000c00000cc  →0x00000000c00000cc
0xffff888063d4e648│+0x0028: 0xffff888063d4e6f8  →  0x0000000000000001  →0x0000000000000001
0xffff888063d4e650│+0x0030: 0xffff888067d9a318  →  0x0000000000000000  →0x0000000000000000
0xffff888063d4e658│+0x0038: 0x0000000000800000  →  0x0000000000800000
───────────────────────────────────────────────────────── code:x86:64 ────
   0xffffffff81def0da <btrfs_verify_dev_extents+1898> lea    rcx, [rax+0x98]
   0xffffffff81def0e1 <btrfs_verify_dev_extents+1905> mov    rdx, rcx
   0xffffffff81def0e4 <btrfs_verify_dev_extents+1908> shr    rdx, 0x3
 → 0xffffffff81def0e8 <btrfs_verify_dev_extents+1912> cmp    BYTE PTR [rdx+rbx*1], 0x0
   0xffffffff81def0ec <btrfs_verify_dev_extents+1916> jne    0xffffffff81def982 <btrfs_verify_dev_extents+4114>
   0xffffffff81def0f2 <btrfs_verify_dev_extents+1922> mov    rax, QWORD PTR [rax+0x98]
   0xffffffff81def0f9 <btrfs_verify_dev_extents+1929> cmp    rax, rcx
   0xffffffff81def0fc <btrfs_verify_dev_extents+1932> je     0xffffffff81def95c <btrfs_verify_dev_extents+4076>
   0xffffffff81def102 <btrfs_verify_dev_extents+1938> lea    rdi, [rax+0x88]
─────────────────────────────────────── source:fs/btrfs/volumes.c+430 ────
    425	 static struct btrfs_device *find_device(struct btrfs_fs_devices *fs_devices,
    426	 		u64 devid, const u8 *uuid)
    427	 {
    428	 	struct btrfs_device *dev;
    429
 →  430	 	list_for_each_entry(dev, &fs_devices->devices, dev_list) {
    431	 		if (dev->devid == devid &&
    432	 		    (!uuid || !memcmp(dev->uuid, uuid, BTRFS_UUID_SIZE))) {
    433	 			return dev;
    434	 		}
    435	 	}
───────────────────────────────────────────────────────────── threads ────
[#0] Id 1, Name: "", stopped, reason: BREAKPOINT
[#1] Id 2, Name: "", stopped, reason: BREAKPOINT
─────────────────────────────────────────────────────────────── trace ────
[#0] 0xffffffff81def0e8 → find_device(uuid=<optimized out>, devid=<optimized out>, fs_devices=<optimized out>)
[#1] 0xffffffff81def0e8 → verify_one_dev_extent(physical_len=<optimized out>, physical_offset=<optimized out>, devid=<optimized out>, chunk_offset=<optimized out>, fs_info=<optimized out>)
[#2] 0xffffffff81def0e8 → btrfs_verify_dev_extents(fs_info=<optimized out>)
[#3] 0xffffffff81d243f0 → open_ctree(sb=0xffff888069cf3b80, fs_devices=<optimized out>, options=<optimized out>)
[#4] 0xffffffff81c7c5d4 → btrfs_fill_super(data=<optimized out>, fs_devices=<optimized out>, sb=<optimized out>)
[#5] 0xffffffff81c7c5d4 → btrfs_mount_root(fs_type=<optimized out>, flags=<optimized out>, device_name=<optimized out>, data=0x0 <irq_stack_union>)
[#6] 0xffffffff816979d9 → mount_fs(type=0xffff88806a4eb248, flags=0x0, name=<optimized out>, data=<optimized out>)
[#7] 0xffffffff8170e8d9 → vfs_kern_mount(type=<optimized out>, flags=<optimized out>, name=0xffff88806c594160 "/dev/loop0", data=0x0 <irq_stack_union>)
[#8] 0xffffffff8170ec2a → vfs_kern_mount(type=<optimized out>, flags=<optimized out>, name=<optimized out>, data=<optimized out>)
[#9] 0xffffffff81c810d5 → btrfs_mount(fs_type=<optimized out>, flags=0x0,device_name=<optimized out>, data=0x0 <irq_stack_union>)
──────────────────────────────────────────────────────────────────────────

Thread 2 hit Breakpoint 1, 0xffffffff81def0e8 in find_device (uuid=<optimized out>, devid=<optimized out>, fs_devices=<optimized out>) at fs/btrfs/volumes.c:430
430		list_for_each_entry(dev, &fs_devices->devices, dev_list) {

instrução cmp BYTE PTR [rdx+rbx*1], 0x0 tentando ler o valor do endereço 0xdffffc0000000000 + 0x13

Baixar ferramenta