遇见数据集

RTOSExploit2: A Unified Exploitation Paradigm for MMU-less Embedded RTOS (Artifact)

收藏
Zenodo2026-08-16 更新2026-08-20 收录
官方服务:

资源简介:

Reproducibility artifact for the paper "A Unified Exploitation Paradigm forMMU-less Embedded RTOS: Systematizing Allocator Primitives, Privilege-BoundaryEscapes, and Language Type-Safety Gaps". It packages three controlled, MMU-less Cortex-M3 targets and the scripts torebuild and rerun all three complete exploitation chains: * L1 -- FreeRTOS heap_4/heap_5 allocator primitives, ending in a write-what-where control-flow hijack (QEMU lm3s6965evb). * L2 -- Zephyr userspace privilege-boundary escape via in-pool kernel-object metadata corruption, yielding a kernel-mediated privileged write (board mps2/an385). * L3 -- embedded Rust (no_std on Zephyr) unsoundness demonstrations (FFI layout mismatch, transmute, use-after-free, cross-FFI double free) and a UAF-to-type-confusion guest-to-admin escalation (QEMU lm3s6965evb). Contents: application sources, build/run/quantification scripts,reverse-engineering notes, and a self-contained FreeRTOS-Kernel tarball.The three chains reproduce bit-identically (N=100), and the heap_4/heap_5,K_OBJ_FLAG_PUBLIC, and CONFIG_ASSERT ablations reproduce at N=10, matchingthe paper's reported measurements 1:1. Environment: WSL2 (Ubuntu 22.04), Zephyr v4.3.1, arm-none-eabi-gcc 10.3.1,QEMU 6.2.0, GDB 12.1, Rust 1.97.1 (thumbv7m-none-eabi). Important: every vulnerability is a controlled, explicitly-injected defect inthe authors' own demo (deliberate out-of-bounds write, forged k_objectmetadata, unsafe type confusion), used to systematize an exploitationmethodology. No novel zero-day in any vendor code is disclosed. The manuscriptitself is not included in this archive.

提供机构:
Zenodo
创建时间:
2026-08-16
二维码
社区交流群
二维码
科研交流群
商业服务