Difference between revisions of "KHeapChunkHeader"
Jump to navigation
Jump to search
m (moved KHeapHeader to KHeapChunkHeader) |
(Thanks! Added some tiny clarifications.) |
||
Line 1: | Line 1: | ||
[[Category:Kernel objects]] | [[Category:Kernel objects]] | ||
− | This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure. An attack like gspwn can overwrite this header | + | This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure. |
+ | |||
+ | An attack like gspwn can be used to overwrite instances of this header in order to exploit the ARM11 kernel on system versions below 9.3 ([[3DS_System_Flaws#Kernel11|memchunkhax]]). | ||
Revision as of 12:36, 27 September 2015
This is the header stored in FCRAM for each FCRAM heap chunk. The kernel maintains this structure.
An attack like gspwn can be used to overwrite instances of this header in order to exploit the ARM11 kernel on system versions below 9.3 (memchunkhax).
Size : 0xC bytes?
Offset | Type | Description |
---|---|---|
0x0 | u32 | Size (in 4K pages) |
0x4 | KHeapHeader* | Next |
0x8 | KHeapHeader* | Prev |