Linux Heap TCache Free Chunk Information Disclosure


In this paper, I introduce the reader what is in a free tcache chunk. There are two pointers maintained in these free chunks that leak information about the address layout and internal allocator structures. This paper will discuss those leaks.

Comments

Popular posts from this blog

Heap Exploitation in Chrome's PartitionAlloc - part 1

Pointer Compression in V8

Linux Kernel Stack Smashing