CVE-2017-8890 is a double-free vulnerability in the Linux kernel's inet_csk_clone_lock function in the IPv4 Internet connection-socket implementation. In affected kernels through 4.10.15, cloning a socket can result in two inet_sock instances referencing the same multicast socket-list object. When one instance frees that shared object, the other retains a dangling reference, creating a use-after-free and subsequent double-free condition reachable through the accept system call.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real local Android kernel exploit research project centered on CVE-2017-8890, a Linux IPv4 multicast use-after-free. It is not a scanner or detection script. The main exploit is implemented in exploit/CVE-2017-8890/1003/rootz.c and built with Android NDK files under jni/, while reusable support code lives in utils/ and an offline NVE journal analysis/builder tool lives in tools/p10_nve_journal.py. The exploit is a heavily modified port of androotzf for a single tested target: Huawei P10 VTR-L29C432B151. The code and docs describe a staged chain: trigger the multicast UAF, overlap reclaimed memory with ip_mc_socklist-related structures, force deferred RCU callback execution, execute an AArch64 JOP chain, temporarily redirect ptmx_fops.check_flags, widen the current task address limit to KERNEL_DS, and then use pipe-based primitives for arbitrary kernel read/write. After proving the primitive, the exploit restores the hijacked function pointer, patches current task credentials and SELinux security context for temporary root, and can optionally dump protected partitions or interact with Huawei's NVE subsystem. Capabilities observed in the code and documentation include: local privilege escalation to uid 0 for the exploit process; spawning a root shell via /system/bin/sh; arbitrary kernel memory read/write via pipe abuse; restoration of modified kernel function pointers to reduce instability; optional dumping of boot/recovery and protected partitions such as nvme, misc, oeminfo, and frp; and a guarded persistent stage that uses the legitimate /dev/nve0 ioctl interface to update the USRKEY verifier in Huawei's NVE journal so fastboot will accept a chosen plaintext unlock code. The repository explicitly states this is not a universal unlocker and that the included kernel profile uses absolute addresses for one exact firmware build. Repository structure: README.md, SAFETY.md, SECURITY.md, and docs/*.md provide extensive operational and safety guidance; exploit/CVE-2017-8890/1003/rootz.c and rootz.h contain the exploit logic and target-specific JOP/profile material; utils/*.c and utils/include/*.h provide argument parsing, logging, device inspection, kernel memory helpers, vendor bypass helpers, and legacy shell/reverse-shell support; jni/Android.mk and Application.mk build a static Android executable named rootz; tools/p10_nve_journal.py is a separate read-only offline utility that inspects a copied 6 MiB NVME image and builds a candidate next-generation block containing only a USRKEY change. That Python tool is not itself an exploit; it supports the persistent post-exploitation workflow. Notable targeting details include hardcoded kernel addresses and offsets documented for VTR-L29C432B151, use of ADB for deployment, and reliance on Android procfs/system files for environment checks. The exploit is operational rather than weaponized: it contains a working payload and post-exploitation stages, but they are tightly bound to one device/firmware profile and require manual preparation and operator-supplied parameters.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel use-after-free scenario involving inet_sock cloning leading to a dangling pointer to an ip_mc_socklist object freed via kfree_rcu; discussed as a case study for how AUTOSLAB’s random offset and invalid-free protections can disrupt common UAF exploitation patterns.
A double-free vulnerability in the Linux kernel IPv4 inet_csk_clone_lock function.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.