CVE-2019-13049
HIGHToaruOS 1.10.10 - Integer Overflow in TOARU_SYS_FUNC_MMAP
Title source: llmDescription
An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland process space via TOARU_SYS_FUNC_MMAP, leading to escalation of privileges.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/mehsauce/kowasuos/blob/master/exploits/kowasu-sysfunc-revenge.c
Scores
CVSS v3
7.8
EPSS
0.0052
EPSS Percentile
40.3%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-190
Status
published
Products (1)
toaruos_project/toaruos
1.10.10
Published
Jun 29, 2019
Tracked Since
Feb 18, 2026