Live data from Hacker News

Susctl CVE-2024-54507: A particularly 'sus' sysctl in the XNU kernel

jprx.io

11–20 of 47 posts

Re: Susctl CVE-2024-54507: A particularly 'sus' sysctl in the XNU kernel

#11

Earlier quoted context omitted.

Is it even exploitable in the real world? Correct me if I'm wrong but you get 2 bytes of kernel data (potentially blank padding) and the same two bytes each time?

If the linker puts a pointer there, this would let you leak part of the pointer which could let you bypass kaslr. Not too likely for that to occur. If I were submitting this bug I would feel complete if they bought me a sandwich.

The bottom 2 bytes of a pointer contain two bits of the slide, assuming it's even a pointer into the kernelcache itself.

I'd take half a sandwich.

Re: Susctl CVE-2024-54507: A particularly 'sus' sysctl in the XNU kernel

#15
post #13
post #9

[flagged]

It's not possible to apply human morale and principles to companies. It just does not work that way. Why would they pay if no profit if pay and they are not forced to pay?

To inspire more of the same.

Re: Susctl CVE-2024-54507: A particularly 'sus' sysctl in the XNU kernel

#17
post #13
post #9

[flagged]

It's not possible to apply human morale and principles to companies. It just does not work that way. Why would they pay if no profit if pay and they are not forced to pay?

Do not fall into the trap of anthropomorphising Apple

Re: Susctl CVE-2024-54507: A particularly 'sus' sysctl in the XNU kernel

#18
post #13
post #9

[flagged]

It's not possible to apply human morale and principles to companies. It just does not work that way. Why would they pay if no profit if pay and they are not forced to pay?

Ideally Apple would incentivise people reporting security issues to them, instead of risking people selling them to someone else who pays more.
Post reply on HN