$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: Linux kernel exploitation via custom module krown.ko with 64-slot typed object registry; bind stores raw child pointers without reference counting, break frees without invalidating parent references, creating deterministic UAF. Solution: pipe_buffer spray for KASLR leak, same-cache type confusion to corrupt backing pointer, arbitrary kernel write to core_pattern for root privilege escalation.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar