BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: From Fuzzer Noise to a Weaponized PHP Exploit: Explo
 iting a\n   PHP Use-After-Free Vulnerability\n   Tags: DEF CON Official Ta
 lk | Demo 💻 | Exploit 🪲\n   When: Sunday\, Aug 9\, 11:30 - 12:30 PDT
 \n   Where: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\
 n   Description:\n   It started as fuzzer noise: an OSS-Fuzz crash in PHP'
 s\n   concat_function\, filed under a JIT target but with no JIT in the\n 
   stack. It is a core Zend Engine use-after-free\, reproducible with php\n
    -n and no extensions. This is an honest exploitability study on Linux\n
    x86-64: from the mistriaged crash to native command execution\n   (arbi
 trary read/write via stale DateInterval\, zif_system resolved\n   in-proce
 ss\, ASLR and PIE defeated at runtime) even where\n   disable_functions is
  set. It builds on the public exploitation\n   lineage\, with an SPL Array
 Object delivery trick as our own delta.\n\n     1. OSS-Fuzz Issue #4838565
 91 — Original crash report filed under\n       php-fuzz-function-jit tar
 get\n\n     2. PHP Source: Zend/zend_operators.c\, concat_function() —\n
        https://github.com/php/php-src/blob/master/Zend/zend_operators.c\n\
 n     3. php/php-src#16726 — Array-element UAF (second-chain\n       vul
 nerability used to bypass mod-16 alignment barrier)\n\n     4. Zend MM Int
 ernals:\n       https://www.phpinternalsbook.com/php7/memory_management/ze
 nd_memory_manager.html\n\n     5. CVE-2022-29072 — Prior 7-Zip zero-day 
 by the same researcher\n       (Kağan Çapar)\, demonstrating track recor
 d in vulnerability\n       research\n\n     6. CVE-2026-5201 — gdk-pixbu
 f heap buffer overflow discovered by\n       the same researcher\, acknowl
 edged by Red Hat (CVSS 7.5)\n\n     7. W3Techs PHP Usage Statistics —\n 
       https://w3techs.com/technologies/details/pl-php\n\n     8. V8 Sandbo
 x Design (2024) — Referenced in comparative\n       interpreter memory m
 odel analysis\n\n   Speakers:Can Oztas\,Kağan Çapar\n\n   SpeakerBio:  C
 an Oztas\n\n   Can Oztas is a security researcher with applied R&D experie
 nce across\n   several key sectors\, including defense\, finance\, and\n  
  telecommunications. His background encompasses AppSec\, vulnerability\n  
  research\, and offensive security engineering. He is currently a PhD\n   
 student focusing on the intersection of Artificial Intelligence and\n   cy
 bersecurity.\n\n   SpeakerBio:  Kağan Çapar\n\n   Kağan Çapar is a Vul
 nerability Researcher with over 15 years of\n   experience. His research f
 ocuses on binary exploitation\, fuzzing\, and\n   zero-day discovery acros
 s widely deployed software.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T193000Z
DTSTART:20260809T183000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use
 -After-Free Vulnerability
END:VEVENT
END:VCALENDAR
