Day[0] cover image

[binary] TOCTOUs in Intel SMM and Shannon Baseband Bugs

Day[0]

00:00

Z's Up Call Workers

There is a mermaid graph provided in the P0 report so you just brought up an editor to render it but yeah it just comes down to like taking the different locks there. effectively there's no synchronization you can just free the socket in the up call data which can be used by the the up call thread after it's been freed. not really too much information on like the exploitability but that's not too surprising this is a phone report he does go into like annotating theYeah I do want to check out his fuzzer which uses something called concurrence which is like his proprietary library for fuzzing for race condition type issues It sounds pretty cool but I haven't gotten a chance to

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app