Skip to content

glibc (ptmalloc)

Tcache

Used to speed up repeated small allocations in a single thread.

Exploit Techniques

Tcache Poisoning

  • Free two or more chunks of the same size. This will populate the next pointer of the second freed chunk.
  • Overwrite (poison) next pointer of the head of the list (last chunk freed), e.g. via UAF/overflow — not a second free().
  • Since glibc 2.32, next is mangled (safe-linking): stored value is target ^ (&next >> 12), needs a heap leak.
  • Allocate memory of the same size as previously freed. The second allocation will use the poisoned next pointer.

House of Spirit

  • Forge a fake chunk (valid size field) at a location which will be freed.
  • Freeing this location will put the memory location into the tcache.
  • Gives an arbitrary malloc'd chunk at a chosen address (e.g. stack) - arbitrary write.

Useful Structs

A collection of structs which might be useful to have at one place.

Tcache

typedef struct tcache_perthread_struct
{
  uint16_t num_slots[TCACHE_MAX_BINS];
  tcache_entry *entries[TCACHE_MAX_BINS];
} tcache_perthread_struct;

typedef struct tcache_entry
{
  struct tcache_entry *next;
  /* This field exists to detect double frees.  */
  uintptr_t key;
} tcache_entry;

Chunks