<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://astronaut0703.github.io/</id><title>astronaut0703</title><subtitle></subtitle> <updated>2026-08-22T01:38:32+09:00</updated> <author> <name>astronaut0703</name> <uri>https://astronaut0703.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://astronaut0703.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en-US" href="https://astronaut0703.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 astronaut0703 </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>[Pwn2Own 2025 Canon Review] The Allocator Handed Out One Pointer, but the Code Gave Back Four</title><link href="https://astronaut0703.github.io/posts/pwn2own-2025-canon-printer-review/" rel="alternate" type="text/html" title="[Pwn2Own 2025 Canon Review] The Allocator Handed Out One Pointer, but the Code Gave Back Four" /><published>2026-08-21T10:00:00+09:00</published> <updated>2026-08-21T15:37:53+09:00</updated> <id>https://astronaut0703.github.io/posts/pwn2own-2025-canon-printer-review/</id> <content type="text/html" src="https://astronaut0703.github.io/posts/pwn2own-2025-canon-printer-review/" /> <author> <name>astronaut0703</name> </author> <category term="Paper Review" /> <summary>How a single misplaced free() in Canon&amp;#39;s proprietary CPCA protocol turned into a $10,000 remote code execution on a networked office printer — plus my own review of the research.</summary> </entry> <entry><title>[DMGuard Review] The CPU Freed the Page, but the GPU Is Still Looking at It</title><link href="https://astronaut0703.github.io/posts/dmguard-review/" rel="alternate" type="text/html" title="[DMGuard Review] The CPU Freed the Page, but the GPU Is Still Looking at It" /><published>2026-08-19T21:00:00+09:00</published> <updated>2026-08-19T21:00:00+09:00</updated> <id>https://astronaut0703.github.io/posts/dmguard-review/</id> <content type="text/html" src="https://astronaut0703.github.io/posts/dmguard-review/" /> <author> <name>astronaut0703</name> </author> <category term="Paper Review" /> <summary>A review of DMGUARD (USENIX Security 2026), the first runtime defense against physical-page use-after-free across CPU, GPU, and IOMMU translation domains.</summary> </entry> <entry><title>3. [Bad epoll CVE-2026-46242] Opening the Kernel: From Arbitrary Read to ROP and Root</title><link href="https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-3-opening-the-kernel/" rel="alternate" type="text/html" title="3. [Bad epoll CVE-2026-46242] Opening the Kernel: From Arbitrary Read to ROP and Root" /><published>2026-08-19T00:00:00+09:00</published> <updated>2026-08-19T00:00:00+09:00</updated> <id>https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-3-opening-the-kernel/</id> <content type="text/html" src="https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-3-opening-the-kernel/" /> <author> <name>astronaut0703</name> </author> <category term="1-day analysis" /> <summary>Goal: the payoff. Reproduce the full chain from the hijacked file: arbitrary read → KASLR bypass → ROP → root. Series Introduction This is the final part of the three-part series on CVE-2026-46242 (Bad Epoll). Part 1 - The Root of the Bug: epoll close-vs-close race and UAF Part 2 - Heap! : the SLUB allocator and cross-cache Part 3 (this article) - Opening the Kernel: from arbitrary re...</summary> </entry> <entry><title>2. [Bad epoll CVE-2026-46242] Heap! — The SLUB Allocator and Cross-Cache Attack</title><link href="https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-2-heap-and-cross-cache/" rel="alternate" type="text/html" title="2. [Bad epoll CVE-2026-46242] Heap! — The SLUB Allocator and Cross-Cache Attack" /><published>2026-08-18T00:00:00+09:00</published> <updated>2026-08-18T14:32:54+09:00</updated> <id>https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-2-heap-and-cross-cache/</id> <content type="text/html" src="https://astronaut0703.github.io/posts/Bad-epoll-CVE-2026-46242-2-heap-and-cross-cache/" /> <author> <name>astronaut0703</name> </author> <category term="1-day analysis" /> <summary>GOAL Understand, from a heap perspective, why the 8-byte write-after-free obtained in Part 1 cannot be exploited with same-cache reuse alone, and how it leads — through a cross-cache attack — to taking control of a struct file. Series Introduction This is the second part of a three-part series analyzing CVE-2026-46242 (Bad Epoll). Part 1 - The Root of the Bug: epoll Close-vs-Close Race...</summary> </entry> <entry><title>1. [Bad epoll CVE-2026-46242] epoll close vs close race and UAF</title><link href="https://astronaut0703.github.io/posts/bad-epoll-cve-2026-46242/" rel="alternate" type="text/html" title="1. [Bad epoll CVE-2026-46242] epoll close vs close race and UAF" /><published>2026-08-15T00:00:00+09:00</published> <updated>2026-08-15T00:00:00+09:00</updated> <id>https://astronaut0703.github.io/posts/bad-epoll-cve-2026-46242/</id> <content type="text/html" src="https://astronaut0703.github.io/posts/bad-epoll-cve-2026-46242/" /> <author> <name>astronaut0703</name> </author> <category term="1-day analysis" /> <summary>GOAL Help the reader understand why the UAF occurs and how the 8-byte UAF write primitive works. Series Introduction This is the first part of a three-part series analyzing CVE-2026-46242 (Bad Epoll), a 1-day vulnerability in the Linux kernel’s epoll subsystem. Part 1 (this article) - The Root of the Bug: epoll Close-vs-Close Race and UAF Part 2 - Heap! : The SLUB Allocator and Cross...</summary> </entry> </feed>
