Use-after-free in setsockopt IPV6_2292PKTOPTIONS (CVE-2020-7457)
High
P
PlayStation
Submitted None
Team Summary
Official summary from PlayStation
The PS5 is vulnerable to https://hackerone.com/reports/826026 which easily grants kernel access to an attacker. This vulnerability had been reported by me for the PS4 2 years ago when the PS5 did not yet exist, thus this should be considered as a new report and **not a duplicate**. I was able to use this vulnerability in conjunction with the bd-j exploit chain to gain kernel access. See https://www.freebsd.org/security/advisories/FreeBSD-SA-20:20.ipv6.asc for more details. ## Impact Gain kernel access on PS5.
Actions:
Reported by
theflow0
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$10000.00
Submitted
Weakness
Use After Free