SHA-256/SHA-384 Type Confusion OOB Write Explained: When a struct Lies About Its Age, the Kernel Believes It
From 15 out-of-bounds bytes to full root and a walk out of a chroot jail: a technical teardown of a Linux kernel exploit chain that starts with a size mix-up between SHA-256 and SHA-384 inside a custom crypto module, travels through MSG_COPY, pipe_buffer, and struct page, and ends with a data-only write into cred followed by swapping task->fs for init_fs.