If you see this, you know I'm still developing this site.
DirtyFree proposes a novel Data-Oriented Programming attack that achieves privilege escalation from a single partial-overwrite primitive, bypassing SLAB_VIRTUAL mitigations.
我爱魔改