And if I read the article correctly, you have to be root to load the module
And if I read the article correctly, you have to be root to load the module
Using a kernel module with the bug in it lets the article talk about that particular transformation, without emboldening a bunch of script kiddies with a new rootme script. You can of course replace that kernel module with any null-pointer dereference you happen to notice in the kernel changelog.
Still, the title can be misinterpreted. The vulnerability being used is not a "real one" but one injected by a kernel module.
3 by itself is not a vulnerability. In fact, it is by itself just a stupidly written peice of code, the real vulnerability is in 1 & 2 which take advantage of a vulnerability in null pointer handling.
In fact, even if I didn't know anything other than 1 and 2, It is possible to start fuzzing syscalls until I accidentally cause one to dereference a null pointer, in which case it is game over.
Edit: another way to say this is: Kernel null pointer vulnerabilities are a class of vulnerability, much like buffer overflows are a class of vulnerability. Even if there is just a toy example of the exploit in an article, it doesn't change the concept. Much like the classic "Smashing the stack for fun an profit"
The point of the article is to demonstrate why they are dangerous, and how they are exploited, not to provide an example of a current vulnerabilty.
If you found such a vulnerabilty (which does happen, hence the example given in the article) you would be able to use this technique to root. (Assuming you were able to circumvent mid address limition on mmap, which the author says used to be, and possibly still is feasible.)
The title seems to accurately describe the article, given a "kernel NULL pointer vulnerabilty" here is how to root it.