Skip to main content
This example demonstrates a real-world Linux kernel privilege escalation exploit using angrop. The chain escalates privileges by calling commit_creds() and switch_task_namespaces() with init credentials.

Overview

This exploit chain performs the following operations:
  1. Call commit_creds(init_cred) to gain root credentials
  2. Find the init task using find_task_by_vpid(1)
  3. Switch namespaces using switch_task_namespaces() with init namespace
  4. Fork a new process with elevated privileges
  5. Sleep indefinitely to maintain the exploit

Complete Working Example

Finding and Caching Gadgets

For large binaries like the Linux kernel, gadget analysis can take significant time. Use caching to avoid re-analyzing:

Optimizing the Gadget Graph

After finding gadgets, optimize the internal graph for better chain generation:

Building the Privilege Escalation Chain

Viewing the Generated Chain

Pretty Print Format

Output:

Python Payload Code

Output:

Performance Metrics

On a 16-core machine analyzing the full Linux kernel:
  • Gadget finding: ~404 seconds
  • Graph optimization: ~10 seconds
  • Chain generation: ~0.7 seconds
  • Total gadgets found: Varies by kernel version (typically 50,000+)

Key Configuration Options

kernel_mode=True

Enables kernel-specific analysis:
  • Handles kernel calling conventions
  • Processes kernel-specific gadgets
  • Adjusts for kernel address space

only_check_near_rets=False

For kernel exploitation, you often need more exotic gadgets:

Advanced Techniques

Preserving Registers

Notice the use of preserve_regs to maintain register values across calls:

Register Movement

Move return values between registers for subsequent calls:

Finding Kernel Addresses

Before exploitation, you need to find these kernel addresses:

Common Pitfalls

  1. Missing kernel_mode=True: Will fail to generate correct kernel chains
  2. Incorrect addresses: Kernel ASLR means addresses change; use info leaks
  3. SMEP/SMAP enabled: Modern kernels prevent userspace code execution
  4. Missing symbols: Use vmlinux with symbols, not compressed vmlinuz