Category PS4 Jailbreaking       Thread starter PSXHAX       Start date Jun 3, 2019 at 8:47 AM       87,785       86            
Status
Not open for further replies.
Awhile back popular PS Vita scene developer TheFloW hinted that he'll be looking at the PS4 kernel in his H-ENcore Write-up, and today he shared on Twitter some details on a PS4 Kernel Bug discovered stating it is fxed somewhere between 5.05 and 6.20 OFW... with the PS4 Kernel Exploit 5.05 / 5.07 being the last public jailbreak currently available. :unsure:


PS4 kernel bug: sys_randomized_path could leak arbitrary amount of kernel stack:
Code:
char k_path[0x100];
int64_t max_len = fuword64(max_len_ptr);
if (path_len <= max_len) {
copyout(k_path, out_path, path_len);
} else {
copyout(k_path, out_path, max_len - 1);
}
Unfortunately fixed somewhere between 5.05 and 6.20.

:arrow: Update: TheFloW said his bug is not exploitable:

Nvm this bug is not exploitable, as copyout will simply abort if it dst+len wraps around or is higher than 0x8000000000000000. However, Sony did actually fix it by adding a max_len > 0 check, so I thought it could be abused.
From Pastebin.com:
Code:
// <6.00 bug (not exploitable) found by TheFloW, JS adaptation by CelesteBlue only useful for when we find an actual vulnerable syscall
    var try_sys_randomized_path_leak = function() {
        var mem = p.malloc(0x1000000); // allocate buffer
        alert(p.hexdump(mem, 0x500)); // display zeroed buffer
       
        var len_pointer = p.malloc(0x08); // allocate length
        p.write8(len_pointer, new int64(0, 2147483648)); // write length: 0x8000000000000000
        alert(p.hexdump(len_pointer, 8)); // display length
       
        alert(p.syscall("sys_randomized_path", 0, mem, len_pointer)); // trigger bug
        alert(p.hexdump(mem, 0x500)); // display buffer, should have been modified if success
    };
PS4 Kernel Bug Details by TheFloW, Fixed Between 5.05-6.20 OFW.jpg
 

Comments

Status
Not open for further replies.

SirSilvan83

Senior Member
Contributor
Verified
So he left the official scene but gave a hint were to find the solution? So now it's up to some good Devs to find it and make it public?

Mhhh not sure whether this will lead to that what we're looking for...
 
Status
Not open for further replies.
Recent Articles
Call of Duty: Advanced Warfare PS4 Mod Menu 1.23 is Now Available
Earlier this week we saw some GTA V PS4 Mod Menu 2020 Demos, and today PlayStation 4 scene developer @CustomHooker shared via Twitter a Call of Duty: Advanced Warfare PS4 Mod Menu 1.23 with help...
PlayStation Store's Totally Digital Sale Live with Savings on PSN Games
Get set to awaken a mysterious power within to save the world in Indivisible, make a daring escape with a little help from a friend in A Way Out or fight your way through the perfect run in the...
PlayStation 5 User Interface (PS5 UI) Rumored Image Leak Surfaces
An image that is rumored to be a screenshot of the current PlayStation 5 User Interface (PS5 UI) has reportedly leaked by an Anonymous game studio employee on the popular 4Chan bulletin board. 🤩...
Frost4 (PS4 Frostbite Engine) Toolkit & GNMF (BA2) Tools by SockNastre
Recently developer SockNastre made available on Github both a Frost4 Toolkit for modifying the proprietary Frostbite engine on PS4 alongside some BethesdaArchive2 GNMF tools to read / write in...
Top