Pinned Tweet
Here is the writeup for CVE-2023-3389, a Use-After-Free on an hrtimer in io_uring, which I exploited for the kCTF VRP qyn.app/posts/CVE-2023-3389/
5
53
208
23,242
For this (maybe last) year of SekaiCTF I made a fullchain challenge, chaining together an 0-day in ladybird/libjs, an 0-day qemu TCG LPE and a n-day qemu escape: qyn.app/blog/sekaictf-2026-3… We also re-released another challenge with a running bounty until next week!
1
25
129
12,192
The re-released challenge involves breaking Pointer Authentication Code Cryptographically
8
710