Overview
Syllabus
Intro
CVE-2012-0217 overview
Coordinating patches release
Known non-affected systems
More on Linux case
Crash course on ring transitions on x86_64
Exception while in ringo
More on stack switch mechanism
"syscall" instruction
"syscall" handler lifecycle
Exception in syscall handler...
Sysret manual entry, Intel
Impact?
Exploit techniques
What is a non-canonical address?
How to force non-canonical address?
FreeBSD exploit scenario
FreeBSD exploit demo
Windows 7 case
Windows User Mode Scheduling
#GP with usermode RSP
Windows 7 exploit
Is it reliable?
Related research
Witchhunt - whose fault is it?.
Mitigation?
Taught by
Black Hat