Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits

·1 hr 35 min·5 clips
A char-sized length field lets the driver copy more data than the buffer can hold.
1. Critical Thinking - Bug Bounty Podcast episode 157 focuses on Enrique Hyperdude's CVE-2025-2742 work against MediaTek kernel drivers. 2. Enrique Hyperdude is the guest, and the hosts bring him on because of his HackerOne and Pwn2Own experience. 3. The episode asks how a heap overflow in a Netgear router's MediaTek driver turned into a working kernel exploit. 4. Enrique starts with the MediaTek Wi-Fi driver's complicated ioctl interface and its connection to user-land daemons for configuration. 5. He describes a structured request with a pointer field and a size field that gets copied into a kernel structure. 6. The size value is treated as a char, so the maximum value is 255. 7. The missing bounds check makes it possible to copy more data than the buffer can hold. 8. Enrique says the target was a random Netgear router with no practical debugging setup. 9. He explains that every kernel crash forced another reboot, which slowed iteration. 10. He says the exploit path ultimately relied on corrupting a slab free-list pointer in kernel memory. 11. That corruption let him obtain an arbitrary allocation primitive after overflowing slightly out of bounds. 12. He then ties that primitive to changing the modprobe path, a classic Linux kernel escalation technique. 13. Enrique explains that modprobe is the user-space binary the kernel invokes when it needs to load support dynamically. 14. He says overwriting that path can redirect the kernel toward a binary he controls. 15. He also explains that ioclt-style access matters because it can expose driver interfaces to user space without authentication in some cases. 16. He says the work forced him to read source code, study write-ups, and mentally model kernel behavior through repeated tests. 17. The conversation stays technical and explanatory, with long answers and follow-up questions about kernel context and IoT constraints. 18. The format mixes bug walkthrough, exploitation details, and practical questions about debugging and attack surface discovery. 19. Listeners who work on kernel exploitation, IoT routers, or bug bounty research will get the most from this episode. 20. Listeners wanting a polished general-audience tech story without deep exploitation detail may skip it.

As heard by us

A practical look at bug bounty work, Keycloak research, and the value of simple fuzzing.

The episode starts with bug bounty budget exhaustion, moves into a practical push for listener research submissions at lab.ctbb.show, and then lands on CVE-2025-13467 in Keycloak, found by ICARE and Truff.

Read the full review in PlayNext →

Why you'd press play

Rapid-fire bug bounty news, source review, and a listener research lab.

Read the full recommendation in PlayNext →
Listen to the show on