glibc (ptmalloc)¶
Tcache¶
Used to speed up repeated small allocations in a single thread.
Exploit Techniques¶
Tcache Poisoning¶
- Free two or more chunks of the same size. This will populate the
nextpointer of the second freed chunk. - Overwrite (poison)
nextpointer of the head of the list (last chunk freed), e.g. via UAF/overflow — not a secondfree(). - Since glibc 2.32,
nextis mangled (safe-linking): stored value istarget ^ (&next >> 12), needs a heap leak. - Allocate memory of the same size as previously freed. The second allocation will use the poisoned
nextpointer.
House of Spirit¶
- Forge a fake chunk (valid
sizefield) at a location which will be freed. - Freeing this location will put the memory location into the tcache.
- Gives an arbitrary malloc'd chunk at a chosen address (e.g. stack) - arbitrary write.
Useful Structs¶
A collection of structs which might be useful to have at one place.
Tcache¶
typedef struct tcache_perthread_struct
{
uint16_t num_slots[TCACHE_MAX_BINS];
tcache_entry *entries[TCACHE_MAX_BINS];
} tcache_perthread_struct;
typedef struct tcache_entry
{
struct tcache_entry *next;
/* This field exists to detect double frees. */
uintptr_t key;
} tcache_entry;