Difference between revisions of "KHeapChunkHeader"

From 3dbrew
Jump to navigation Jump to search
(Thanks! Added some tiny clarifications.)
Line 1: Line 1:
 
[[Category:Kernel objects]]
 
[[Category:Kernel objects]]
  
This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure. An attack like gspwn can overwrite this header, and exploit the kernel pre 9.3 (memchunkhax).
+
This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure.
 +
 
 +
An attack like gspwn can be used to overwrite instances of this header in order to exploit the ARM11 kernel on system versions below 9.3 ([[3DS_System_Flaws#Kernel11|memchunkhax]]).
  
  

Revision as of 12:36, 27 September 2015


This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure.

An attack like gspwn can be used to overwrite instances of this header in order to exploit the ARM11 kernel on system versions below 9.3 (memchunkhax).


Size : 0xC bytes?

Offset Type Description
0x0 u32 Size (in 4K pages)
0x4 KHeapHeader* Next
0x8 KHeapHeader* Prev