
One of the most fascinating bugs in Windows wasn't even in "win32k.sys", it was Double Fetch (CVE-2018-1038) - https://blog.xpnsec.com/total-meltdown-cve-2018-1038/ The kernel validated a user-supplied value, then fetched it again later assuming it hadn't changed. An attacker could race another thread to modify the value between the two accesses, turning a perfectly valid request into an invalid one after the check had already passed.
Post summary
The post highlights CVE‑2018‑1038, explains its double‑fetch race flaw, and includes a link that presumably hosts a proof‑of‑concept, but it offers no exploitation code, active usage reports, patches, or debunking statements.

