Crash Override: NetBSD 5.0-9.3 Coredump Kernel Refcount LPE.
NetBSD 5.0 (released 2009) introduced a change to the in-kernel coredump handler that accidentally introduced a reference count bug on the crashing process' credential. Triggering the vulnerability leads to a use-after-free that can be trivially (though slowly) exploited to achieve local privilege escalation, gaining root from an unprivileged starting point...
https://accessvector.net/2022/netbsd-coredump-lpe
#kernel #system
>>Click here to continue<<