Linux BPF Local Privilege Escalation
Posted by deepcore on November 15, 2016 – 2:28 am
Linux kernel versions 4.4 and above where CONFIG_BPF_SYSCALL and kernel.unprivileged_bpf_disabled sysctl is not set to 1 allow for BPF to be abused for privilege escalation. Ubuntu 16.04 has all of these conditions met.
Post a reply
You must be logged in to post a comment.