Sploitus

Exploit for CVE-2016-2384 CVE-2016-2384 CVE-2017-6074

gitee · 2020-12-02

Exploit Code

MARKDOWN8 lines
## https://sploitus.com/exploit?id=88E0AE6D-8DD5-5A04-8F44-BFEBE71826B1
This repository contains proof-of-concept exploits for two Linux kernel vulnerabilities: CVE-2016-2384 and CVE-2017-6074. 

CVE-2016-2384 is a double-free vulnerability in the USB MIDI driver. The exploit is a part of a proof-of-concept exploit for the vulnerability in the usb-midi driver. It is meant to be used in conjunction with a hardware USB emulator, which emulates a particular malicious USB device (a Facedancer21 for example). The exploit includes a semireliable SMEP/SMAP bypass (the kernel might crash shortly after the exploit succeeds).

CVE-2017-6074 is also a double-free vulnerability, this time in the DCCP protocol implementation. The exploit includes a semireliable SMEP/SMAP bypass (the kernel might crash shortly after the exploit succeeds). The exploit is a proof-of-concept local root exploit for the vulnerability in the DCCP protocol implementation.

Both exploits are tested on specific kernel versions and include usage instructions. The CVE-2016-2384 exploit is tested on 4.4.0-62-generic #83-Ubuntu kernel, while the CVE-2017-6074 exploit is tested on 4.4.0-62-generic #