Hasty Briefsbeta

Bilingual

The 40 Year Old Kernel Bug (iOS, macOS, XNU, etc.)

22 days ago
  • The author's demo at DEFCON crashed due to a bug in UNIX domain socket inode assignment in the XNU kernel.
  • The bug occurs because the global variable `unp_ino` is incremented postfix (`unp_ino++`), causing the first call to `fstat()` to return inode 0, which violates the check for uninitialized inodes.
  • This results in the inode changing on subsequent `fstat()` calls, breaking assumptions in the author's VM that tracks TTY file descriptors by inode.
  • The bug has existed since 1985 in BSD, persisting through NeXTSTEP and Apple's XNU kernel (macOS and iOS).
  • The fix is simple: use prefix increment (`++unp_ino`) or ensure the first inode is non-zero.
  • The author suggests adding a workaround in user code to handle the zero inode case for backward compatibility.