SECCON-2020-kstack:userfaultfd + setxattr + double free
启动脚本#!/bin/shqemu-system-x86_64\-m128M\-kernel./bzImage\-initrd./rootfs.cpio\-append"root=/dev/ramrwconsole=ttyS0oops=panicpanic=1kaslrquiet"\-cpukvm64,+smep\-netuser-netnic-devicee1000\-no-reboot\-s\