The Good, the Bug and the Ugly - Dissecting a USB n-Day in the Linux Kernel
It remains a booming business to sell exploitation of 0-days to governmental law-enforcement agencies, mainly to catch bad guys. Sometimes, however, these capabilities are not-so-lawfully misused against other actors, such as activists.
Building on a report of Amnesty International's Security Lab, we investigate one such misuse that utilized several 0-days in the USB-stack of an Android phone's Linux kernel, connect the dots between device logs, CVE entries and Kernel source code, and create a working and portable exploit for affected Linux Kernels ourselves.
The talk builds on a report by Amnesty International's Security Lab published on 28th February 2025 that details how an activist's Android phone was accessed by exploitation of multiple 0-days in the USB-stack of the Linux kernel. By analyzing their forensic report, assigned CVEs and kernel patches, we investigate what makes specifically CVE-2024-53104 exploitable, and how it can be done.
The talk will outline the (mostly manual) journey from a reported CVE to a working n-day exploit, analyzing the vulnerability, the circumstances under which it can be exploited, its limitations and limitation-bypasses, as well as some exploit techniques for the Linux kernel.
Ferdinand is a security researcher and penetration tester working at Fraunhofer Institute AISEC in Munich, Germany. His main focus lies with automotive security, but he takes a detour every now and then to explore other targets such as NFC and RF communication, exploit development or cracking crypto.