ptrace_traceme reported EXPLOIT_OK while obtaining no root on a genuinely vulnerable host (Ubuntu 18.04.2 / 4.15.0-50). The bundled ptrace sequence is a non-working placeholder — it PTRACE_ATTACHes to the tracer, which by then has reparented to init, so the attach fails EPERM; the parent then execve'd the setuid trigger and the dispatcher's exec-transfer path reported a false OK. Now the parent fires the trigger in a grandchild, stays alive, and verifies euid==0 before claiming success — otherwise honest EXPLOIT_FAIL with a pointer to the real CVE-2019-13272 technique (Jann Horn / bcoles) that still needs porting. Adds docs/EXPLOITED.md: the exploit-verification ledger (root witnessed OUT OF BAND, not from the module's self-report). Confirmed landing root: refluxfs, overlayfs, pwnkit (after its gconv fix), sudo_runas_neg1. Needs PoC ports: ptrace_traceme, overlayfs_setuid (CVE-2023-0386 FUSE copy-up), sudo_samedit (heap), cgroup_release_agent. ~30 modules still exploit-untested. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0118iUgHY44hdRtANgyCmu7y
5.0 KiB
Exploit verification ledger
What this is: results of actually running each exploit against a genuinely
vulnerable VM and confirming uid=0 out of band (an independent root-owned
write / /etc/shadow read / setuid-bash sentinel — never the module's own
self-report). This is distinct from docs/VERIFICATIONS.jsonl's historical
records, which only checked that detect() returns the right verdict.
Harness: rootless qemu/KVM over frozen point-release cloud images (unpatched →
vulnerable by default), driver in the session scratch dir. Root witnessed via
witness.sh (shell-probe + setuid-bash finisher + module sentinels + /etc/passwd
tamper check).
Headline finding: the corpus was only ever detect-verified, never exploit-verified. Running the exploits shows a mix of genuinely-working, honestly-failing, and falsely-succeeding modules. Two flagship modules reported
EXPLOIT_OKwhile obtaining no root at all (pwnkit,ptrace_traceme) — a false positive from the dispatcher's "execve transferred → clean child exit = OK" path. Both are addressed below.
Confirmed landing root (uid=0 witnessed out of band)
| module | CVE | target | notes |
|---|---|---|---|
refluxfs |
CVE-2026-64600 | Rocky 9.8 / 5.14.0-687.el9 | full chain, /etc/passwd → root (earlier) |
overlayfs |
CVE-2021-3493 | Ubuntu 20.04.0 / 5.4.0-26 | userns + xattr copy-up, clean |
pwnkit |
CVE-2021-4034 | Ubuntu 20.04.0 / polkit 0.105-26ubuntu1 | after a fix — see below |
sudo_runas_neg1 |
CVE-2019-14287 | Ubuntu 18.04.2 / sudo 1.8.21p2 + sudoers (ALL,!root) |
sudo -u#-1 → uid 0 |
Fixed this session
pwnkit— reportedEXPLOIT_OKbut did not root (glibc "Could not open converter … to PWNKIT"). Root cause: missing theGCONV_PATH=.re-injection directory +chdir(workdir). Fixed → now lands real root on a vulnerable host. (commit24b839e)ptrace_traceme— reportedEXPLOIT_OKbut did not root; the bundled ptrace sequence is a non-working placeholder (itPTRACE_ATTACHes to the tracer, which by then has reparented to init →EPERM). Made honest (verifieseuid==0, otherwiseEXPLOIT_FAIL); a faithful CVE-2019-13272 port (Jann Horn / bcoles:PTRACE_TRACEME+ setuid execve + registered polkit agent) is still required to land root.
Needs a faithful PoC port (genuinely vulnerable target, exploit doesn't land)
| module | CVE | target tested | what's wrong |
|---|---|---|---|
ptrace_traceme |
CVE-2019-13272 | Ubuntu 18.04.2 / 4.15.0-50 | placeholder technique; needs the real cred-transfer PoC |
overlayfs_setuid |
CVE-2023-0386 | Ubuntu 22.04.0 / 5.15.0-25 | chown merged carrier: EPERM — wrong method; needs the FUSE copy-up PoC (xkaneiki) |
sudo_samedit |
CVE-2021-3156 | Ubuntu 18.04.2 + 20.04.0 | honest EXPLOIT_FAIL; Baron Samedit is heap/libc-specific, needs a tuned PoC |
cgroup_release_agent |
CVE-2022-0492 | Ubuntu 20.04.0 / 5.4.0-26 | honest EXPLOIT_FAIL; cgroup-v1/userns release_agent precondition/technique |
Inconclusive (detect version-blind vs vendor backport)
| module | CVE | note |
|---|---|---|
dirty_pipe |
CVE-2022-0847 | Ubuntu 22.04.0's 5.15.0-25.25 almost certainly carries the backported fix (USN-5317); detect() is version-only so says VULNERABLE. Needs a genuinely pre-fix kernel (e.g. 5.13.0-19, or mainline 5.16.10) to verify the exploit. |
Not yet exploit-tested (the bulk — ~30 modules)
- 🟡 kernel primitives (
nf_tables,nft_set_uaf,nft_payload,nft_fwd_dup,netfilter_xtcompat,af_packet,af_packet2,af_unix_gc,cls_route4,fuse_legacy,stackrot,sequoia,nft_pipapo,vsock_uaf,pintheft): returnEXPLOIT_FAILby design; landing root needs a per-kernel--dump-offsets+--full-chain(modprobe_path finisher) pass on a vulnerable kernel. - Structural userspace (
sudoedit_editor,sudo_chwoot,sudo_host): need specific sudo versions + sudoers config; likely tractable. - 2026 CVEs (
copy_fail×5,dirtydecrypt,fragnesia,cifswitch,nft_catchall,ptrace_pidfd): need vulnerable 2026 kernels; the reconstructed race triggers (bad_epoll,ghostlock,nft_catchall) are deliberately under-driven and won't pop root by design. - Environment-blocked:
vmwgfx(VMware guest only),dirty_cow(needs ≤4.4),mutagen_astronomy(CentOS 6 / Debian 7). - D-Bus/desktop (
pack2theroot,udisks_libblockdev): need the polkit/D-Bus stack + a provisioner rule.
Method notes for continuation
- Frozen images:
cloud-images-archive.ubuntu.com/releases/<name>/release-<date>/are unpatched and vulnerable-by-default for CVEs disclosed after that date — far easier than downgrading packages on current images. - gcc must be present in the VM (several exploits compile payloads at runtime); on EOL LTS, point apt at the archive main pocket.
- Always verify root out of band. The module self-report is not trustworthy
(two flagships lied).
witness.shis the reference check.