Where to Find the QEMU CXL Type-3 Mailbox Escape PoC: Complete Exploitarium Guide

The QEMU CXL Type-3 Mailbox Escape proof-of-concept is located in the qemu-cxl-type3-mailbox-escape-poc directory of the Exploitarium repository on GitHub.

The Exploitarium repository by bikini hosts a reproducible memory-corruption exploit chain targeting QEMU's CXL Type-3 mailbox implementation. This PoC demonstrates a guest-to-host escape vulnerability using a crafted BIOS image and PCI configuration space manipulation.

Repository Location and Directory Structure

The PoC resides in a dedicated subdirectory within the main Exploitarium repository.

Main Directory Path

All source code, build scripts, and documentation are stored under:


exploitarium/qemu-cxl-type3-mailbox-escape-poc/

The full repository URL is github.com/bikini/exploitarium, with the PoC accessible directly via the path qemu-cxl-type3-mailbox-escape-poc/.

Core Source Files

The directory contains seven primary files that constitute the complete exploit environment:

  • README.md – Comprehensive documentation covering build requirements, exploit flow, and execution instructions
  • stage2.c – Freestanding 32-bit guest code that drives PCI config space and the CXL mailbox interface
  • stage2.ld – Linker script defining the flat protected-mode memory layout for the stage2 payload
  • boot.asm – 16-bit real-mode loader that reads the protected-mode stage from the floppy image
  • build.sh – Shell script that compiles sources and produces the poc.img binary
  • run.sh – Launch wrapper that configures QEMU with CXL Type-3 support and executes the exploit
  • poc.img – Pre-built BIOS floppy image ready for immediate testing

Key Components of the Exploit Chain

The PoC implements a multi-stage boot process to establish the guest environment and trigger the vulnerability.

stage2.c - The Memory Corruption Payload

The file stage2.c contains the core exploit logic. This freestanding C code runs in 32-bit protected mode and performs the following operations:

  1. Initializes PCI configuration space access
  2. Communicates with the CXL Type-3 mailbox interface
  3. Leaks host heap pointers through the vulnerability
  4. Crafts forged memory objects to achieve arbitrary code execution
  5. Invokes the host's system() function to demonstrate the escape

According to the source analysis, successful execution creates a marker file at /tmp/qemu_cxl_escape_marker confirming the guest payload escaped to the host environment.

Build and Execution Scripts

The build.sh script automates compilation of boot.asm, stage2.c, and linking via stage2.ld to regenerate poc.img. The run.sh script handles QEMU orchestration, configuring a Q35 machine with CXL Type-3 enabled, attaching volatile memory and dynamic-capacity regions, and managing execution timeouts.

Running the QEMU CXL Type-3 Mailbox Escape PoC

Clone the repository and execute the following commands to reproduce the vulnerability:


# Clone the Exploitarium repository

git clone https://github.com/bikini/exploitarium.git
cd exploitarium/qemu-cxl-type3-mailbox-escape-poc

# Optional: Rebuild the guest image from source

sh build.sh

# Execute the PoC against your QEMU binary

sh run.sh /path/to/qemu-system-x86_64

Upon successful exploitation, the console output will display:

stage2 start
pci done
handler=0x00005d41f6d636f0
...
system=0x000077f60c858750
...
stage2 done

The presence of /tmp/qemu_cxl_escape_marker on the host filesystem confirms the mailbox escape succeeded.

Summary

  • The QEMU CXL Type-3 Mailbox Escape PoC is housed in the qemu-cxl-type3-mailbox-escape-poc/ directory of the bikini/exploitarium repository
  • stage2.c implements the core vulnerability trigger using the CXL mailbox interface and PCI config space
  • build.sh and run.sh provide fully automated compilation and execution workflows
  • The exploit demonstrates a complete guest-to-host escape chain resulting in arbitrary system() calls on the host
  • Pre-built artifacts (poc.img) allow immediate testing, while full source enables custom modification and analysis

Frequently Asked Questions

What is the QEMU CXL Type-3 Mailbox Escape PoC?

The QEMU CXL Type-3 Mailbox Escape PoC is a security research artifact that demonstrates a memory-corruption vulnerability in QEMU's implementation of the Compute Express Link (CXL) Type-3 mailbox interface. According to the Exploitarium source code, the proof-of-concept exploits improper validation in mailbox command handling to achieve arbitrary code execution inside the QEMU process from a guest virtual machine.

How do I build the PoC from source?

Execute the build.sh script in the qemu-cxl-type3-mailbox-escape-poc/ directory. This script compiles boot.asm into 16-bit bootloader code, compiles stage2.c using the freestanding 32-bit target, and links the objects using stage2.ld to produce the flat binary poc.img.

What files are included in the qemu-cxl-type3-mailbox-escape-poc directory?

The directory contains README.md (documentation), stage2.c (exploit payload), stage2.ld (linker script), boot.asm (bootloader), build.sh (compilation script), run.sh (QEMU launch wrapper), and poc.img (pre-built BIOS floppy image). Each file serves a specific function in the boot chain and exploit execution pipeline.

How does the exploit demonstrate host escape?

The guest-side code in stage2.c interacts with the CXL Type-3 mailbox to corrupt QEMU's heap metadata, forge memory objects, and leak host pointers. This corruption chain ultimately redirects execution to the host's libc system() function, which executes touch /tmp/qemu_cxl_escape_marker on the host filesystem, proving the guest escaped the virtual machine boundary.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →