A use-after-free vulnerability exists in the Linux kernel's io_uring subsystem due to improper reference count handling in the io_msg_ring function when invoked with a fixed file. Specifically, the function incorrectly calls io_fput_file(), decrementing the reference count of a file that is permanently registered to the ring, leading to a use-after-free condition. This flaw allows a local attacker to exploit the dangling pointer for privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains multiple local privilege escalation exploits for CVE-2022-3910, a Linux kernel vulnerability involving io_uring file reference counting. The main exploit files are: - poc.c: A proof-of-concept that triggers the kernel bug and causes a crash by manipulating file descriptors and io_uring. - exp_dirtyfile.c: Exploits the vulnerability to overwrite /etc/passwd, potentially allowing the attacker to set a root password or add a root user. - exp_dirtymm.c: Exploits the vulnerability to inject shellcode into a SUID process (e.g., /bin/chsh), resulting in a root shell. - exp_dirtymm_container.c: Similar to exp_dirtymm.c but tailored for container environments, injecting a reverse shell payload that connects to 127.0.0.1:55555 as root. - suid_dummy.c: A helper SUID binary for testing. - boot.sh: Script to launch a QEMU virtual machine for testing the exploits. - liburing: Included library for io_uring support. The exploits require local access and are operational, providing real privilege escalation if the target is vulnerable. The code is well-structured, with each exploit in its own file and a Makefile for building all components. The repository is focused on demonstrating and exploiting CVE-2022-3910 on Linux systems.
This repository contains two main C exploit files (t1dexp.c and t1dpoc.c), a bash script (boot.sh), and a README. The exploits target CVE-2022-3910, a Linux kernel privilege escalation vulnerability related to DirtyCred and cross-cache attacks. - t1dexp.c implements a full exploit chain leveraging file descriptor manipulation, io_uring, and cross-cache techniques to achieve a use-after-free (UAF) condition in the kernel, ultimately allowing the attacker to overwrite credentials and spawn a root shell. The exploit interacts with /etc/passwd and /bin/sh, and includes detailed steps for manipulating kernel memory structures. - t1dpoc.c is a proof-of-concept demonstrating the UAF and file descriptor manipulation, using /tmp/test and /etc/passwd as targets, and also leveraging io_uring and pthreads for race conditions. - boot.sh is a helper script to launch a QEMU virtual machine with a custom kernel and root filesystem, providing a controlled environment for testing the exploit. The repository is operational in maturity, providing a working exploit with a hardcoded payload (root shell). The attack vector is local privilege escalation, requiring the attacker to execute code on a vulnerable Linux system. The main fingerprintable endpoints are the file paths /etc/passwd, /bin/sh, and /tmp/test, which are used in the exploitation process.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.