A heap-based buffer overflow exists in the Linux kernel (through 5.14.14) within the AMD GPU display driver's debug filesystem interface. The vulnerability is present in the dp_link_settings_write function in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c, where the parse_write_buffer_into_params function fails to validate the size of user-supplied input before copying it into a fixed-size 40-byte heap buffer using copy_from_user. This allows an attacker with write access to the debugfs interface to overflow the buffer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a full local privilege escalation exploit for CVE-2021-42327, a SLUB overflow vulnerability in a custom Linux kernel module. The structure includes: - Two exploit implementations (exploit.c and exploit_userfaultfd.c), both targeting the vulnerable /dev/vuln device provided by the included kernel module (module/cdev.c). - The kernel module (cdev.c) is a character device with intentionally unsafe buffer handling, mimicking a real-world vulnerability. - The exploit works by manipulating kernel heap allocations via message queues and the vulnerable device, leaking the address of modprobe_path, and then overwriting it to point to a malicious script in /tmp/x. The script is then executed as root by triggering modprobe via a dummy file, resulting in privilege escalation and flag exfiltration. - The repository also includes scripts for building the exploit and setting up a QEMU-based test environment (run_challenge.sh, setup.sh), as well as a Makefile for building the kernel module. The exploit is operational and demonstrates a real-world kernel exploitation technique, including heap manipulation, kernel address leakage, and arbitrary kernel memory write. The main attack vector is local, requiring the attacker to execute code on the target system with access to the vulnerable device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.