Sign in

Andrey Konovalov

@andreyknvl.bsky.social
170 followers 89 following 48 posts

Security engineer at xairy.io. Focusing on the Linux kernel. Maintaining @linkersec.bsky.social. Trainings at xairy.io/trainings.

PostsRepliesMedia
Andrey Konovalov @andreyknvl.bsky.social · 10/09/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
July/August updates · xairy/linux-kernel-exploitation@281f69d
011
Reposted by Andrey Konovalov
Andrey Konovalov @andreyknvl.bsky.social · 27/05/2026
Gonna be teaching Exploiting the Linux Kernel training at RomHack in Rome on September 28 — October 1st. Last planned session of this training for the year. Early Bird discount until the end of the week. romhack.io/training/202...
021
Andrey Konovalov @andreyknvl.bsky.social · 06/07/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
June updates · xairy/linux-kernel-exploitation@1120e9c
000
Andrey Konovalov @andreyknvl.bsky.social · 29/05/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
March/April/May updates · xairy/linux-kernel-exploitation@a8811cb
000
Andrey Konovalov @andreyknvl.bsky.social · 27/05/2026
Gonna be teaching Exploiting the Linux Kernel training at RomHack in Rome on September 28 — October 1st. Last planned session of this training for the year. Early Bird discount until the end of the week. romhack.io/training/202...
021
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 20/05/2026
Recent Page Cache Corruption Bugs All stem from code paths that allow in-place overwrites of user-supplied input pages without verifying they are writable. This enables overwriting page cache and thus changing in-memory contents of read-only files. Selected links below ⬇️
122
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 16/04/2026
From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android. lukasmaar.github.io/posts/heap-k...
112
Reposted by Andrey Konovalov
dmnk @dmnk.bsky.social · 11/04/2026
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
security.googleblog.com
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
49917
Reposted by Andrey Konovalov
0xor0ne @0xor0ne.bsky.social · 12/04/2026
Software-only timing side-channel leaking mm_struct without a memory-safety bug, pivoting via cross-cache reuse to msg_msg/pipe_buffer, effective even on MTE. lukasmaar.github.io/posts/heap-k... Credits: Lukas Maar #infosec
lukasmaar.github.io
Heap KASLR Leaks | Lukas Maar
Software-only KernelSnitch side channel plus cross-cache reuse leaks heap KASLR (msg_msg/pipe_buffer) across Linux environments and Android.
041
Reposted by Andrey Konovalov
BSides Canberra @bsidescbr.bsky.social · 16/03/2026
New BSides Canberra 2025 talk by Angus is now live: “Walkthrough of an N-day Android GPU driver vulnerability.” Watch here: youtu.be/G71dB0C4-dY
youtu.be
Walkthrough of an N-day Android GPU driver vulnerability - Angus Atkinson, BSides Canberra 2025
YouTube video by BSides Canberra
012
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 17/03/2026
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets Excellent article by Quang Le about exploiting CVE-2025-38617 — a race condition that leads to a use-after-free in the packet sockets implementation. blog.calif.io/p/a-race-wit...
112
Andrey Konovalov @andreyknvl.bsky.social · 11/03/2026
Extended the Pixel 8 KGDB article with the instructions on how to set up GEF. slub-dump, buddy-dump, and some other commands now work. Huge thanks to bata24 for implementing all required pieces. xairy.io/articles/pix...
xairy.io
📲 Debugging the Pixel 8 kernel via KGDB
Instructions for getting kernel log, building custom kernel, and enabling KGDB on Pixel 8
000
Andrey Konovalov @andreyknvl.bsky.social · 10/03/2026
Gonna be teaching Exploiting the Android Kernel training at Zer0Con 2026 on March 30th — April 1st. This is a new training focused on data-only Android kernel exploitation techniques. Just a bit of time left to sign up. Pay attention to the requirements. zer0con.org#training-sec...
000
Andrey Konovalov @andreyknvl.bsky.social · 04/03/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
January/February updates · xairy/linux-kernel-exploitation@80d541e
000
Andrey Konovalov @andreyknvl.bsky.social · 13/02/2026
Gonna be teaching Fuzzing the Linux Kernel training online via Ringzer0 on March 20–25. Covers using/extending syzkaller and KASAN and related areas. I don't deliver this training often, so don't miss the opportunity. ringzer0.training/countermeasu...
ringzer0.training
Fuzzing the Linux Kernel
This training guides security researchers and software engineers through the field of Linux kernel fuzzing. In a series of lectures and practical labs, the training explores using fuzzing for finding ...
000
Reposted by Andrey Konovalov
Anderson Nascimento @andersonc0d3.bsky.social · 12/02/2026
The end of a good time slab: remove struct kmem_cache_cpu git.kernel.org/pub/scm/linu... slab: remove cpu (partial) slabs usage from allocation paths git.kernel.org/pub/scm/linu...
111
Andrey Konovalov @andreyknvl.bsky.social · 26/01/2026
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
November/December updates · xairy/linux-kernel-exploitation@50a2069
011
Reposted by Andrey Konovalov
Natalie Silvanovich @natashenka.bsky.social · 15/01/2026
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixe...
projectzero.google
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
15733
Reposted by Andrey Konovalov
Recon @reconmtl.bsky.social · 13/01/2026
🚨 REcon 2026 is LIVE! 🚀 Call for papers and registration are now open! Join the world's top reverse engineers & exploit devs in Montreal: 🛠 Trainings: June 15-18 📅 Conference: June 19-21 Tickets & early bird now open → recon.cx Limited spots – see you in MTL! #REcon2026 #ReverseEngineering
recon.cx
REcon 2026 - Premier Reverse Engineering Conference
REcon 2026 - Premier reverse engineering and cybersecurity conference in Montreal
083
Reposted by Andrey Konovalov
parkerlreed.bsky.social @parkerlreed.bsky.social · 13/01/2026
@andreyknvl.bsky.social I don't know if this ever got brought up, but for a much more convenient way of doing this, Steam Deck supports this out of the box. You flip the toggle in BIOS, which is exposed by default, and then you can use the gadget directly within the OS. xairy.io/articles/thi...
xairy.io
🤫 Unlocking secret ThinkPad functionality for emulating USB devices
Enabling and using xDCI controller on ThinkPad X1 Carbon 6th Gen
131
Andrey Konovalov @andreyknvl.bsky.social · 23/12/2025
Gonna be teaching Exploiting the Linux Kernel training at @offensivecon.bsky.social in Berlin on May 11–14th. Half of the spots already taken, so don't miss out. Also note that you can get a conference ticket as a bundle with a training.
010
Reposted by Andrey Konovalov
OffensiveCon @offensivecon.bsky.social · 20/12/2025
🚨 In 2026, Andrey Konovalov - @andreyknvl.bsky.social - returns to OffensiveCon with a training on "Exploiting the Linux Kernel". Find more details here🔗https://buff.ly/dKDboYt 🚀 Don't miss this chance to improve your skills—sign up now!
031
Reposted by Andrey Konovalov
OffensiveCon @offensivecon.bsky.social · 16/12/2025
The trainings' content is unique and exclusive to #offensivecon26, so don’t miss out! NEW: Get your training + conference ticket bundle and secure a conference ticket before the conference ticket shop opens! Tickets: buff.ly/z8YNgoY Don't worry, the conference ticket shop will open…at some point
032
Andrey Konovalov @andreyknvl.bsky.social · 08/11/2025
This is still not fixed btw.
000
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 07/11/2025
kernelCTF: CVE-2025-38477 kernelCTF entry for a race condition in the network scheduler subsystem. Most notably, shows a technique of putting controlled data into unmapped sections of vmlinux. github.com/n132/securit...
021
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 06/11/2025
Defeating KASLR by Doing Nothing at All Article by Seth Jenkins about a few problems with physical memory KASLR on arm64 devices. googleprojectzero.blogspot.com/2025/11/defe...
011
Andrey Konovalov @andreyknvl.bsky.social · 06/11/2025
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
September/October updates · xairy/linux-kernel-exploitation@b26cc4a
021
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 25/10/2025
Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers Article by Robin Bastide about exploiting a NULL-pointer-dereference that led to a UAF access to the kernel stack in the NVIDIA GPU driver. blog.quarkslab.com/nvidia_gpu_k...
111
Andrey Konovalov @andreyknvl.bsky.social · 24/10/2025
Sheaves support has been merged into SLUB. Opt-in for now, but planned to replace the per-CPU partial slab layer for all caches in the future. Gonna have to revise the slab shaping strategies once this happens.
100
Andrey Konovalov @andreyknvl.bsky.social · 23/09/2025
Delivered a workshop at BalcCon this weekend on emulating/sniffing/MitM'ing USB devices with Raw Gadget and a Raspberry Pi. All materials are public, so can go through the workshop on your own if you're interested. github.com/xairy/raw-ga...
github.com
raw-gadget/workshop at master · xairy/raw-gadget
USB Raw Gadget — a low-level interface for the Linux USB Gadget subsystem - xairy/raw-gadget
010
Andrey Konovalov @andreyknvl.bsky.social · 23/09/2025
Updated syzkaller documentation on USB fuzzing to explain how to handle certain tricky cases (e.g. driver quirks applied based on Vendor/Product IDs). github.com/google/syzka...
github.com
docs: update USB documentation · google/syzkaller@e2beed9
021
Andrey Konovalov @andreyknvl.bsky.social · 11/09/2025
Wrote a trigger for CVE-2025-38494/5 (an integer underflow in the HID subsystem) that leaks 64 KB of OOB memory over USB. Still works on Pixels and Ubuntus (but the bug is fixed in stable kernels). github.com/xairy/kernel...
1204
Andrey Konovalov @andreyknvl.bsky.social · 08/09/2025
Updated the collection of USB hacking links. github.com/xairy/usb-ha...
github.com
readme: new links · xairy/usb-hacking@4661f45
000
Andrey Konovalov @andreyknvl.bsky.social · 08/09/2025
Whoever is coming to BalCCon: I will be teaching a workshop Attacking USB with Raw Gadget (covering basics of USB emulation and sniffing). If you wish to attend, you must bring Raspberry Pi 5 along with a few other things, see the workshop description. github.com/xairy/raw-ga...
github.com
raw-gadget/workshop at master · xairy/raw-gadget
USB Raw Gadget — a low-level interface for the Linux USB Gadget subsystem - xairy/raw-gadget
020
Andrey Konovalov @andreyknvl.bsky.social · 04/09/2025
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
July/August updates · xairy/linux-kernel-exploitation@3dbd2d4
010
Reposted by Andrey Konovalov
Anderson Nascimento @andersonc0d3.bsky.social · 13/08/2025
Linux Kernel netfilter: ipset: Missing Range Check LPE ssd-disclosure.com/linux-kernel...
ssd-disclosure.com
Linux Kernel netfilter: ipset: Missing Range Check LPE - SSD Secure Disclosure
Affected Versions Vendor Response Linux kernel release the patch (https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=35f56c554eb1b56b77b3cf197a6b00922d49033d) Background The...
021
Reposted by Andrey Konovalov
TrendAI Zero Day Initiative @thezdi.bsky.social · 31/07/2025
Announcing #Pwn2Own Ireland for 2025! We return to the Emerald Isle with our new partner #Meta & a $1,000,000 WhatsApp bounty. Plus new USB vectors on phones & more. Read the details www.zerodayinitiative.com/blog/2025…
164
Andrey Konovalov @andreyknvl.bsky.social · 28/07/2025
Documented instructions for setting up KGDB on Pixel 8. Including getting kernel log over UART via USB-Cereal, building/flashing custom kernel, breaking into KGDB via /proc/sysrq-trigger or by sending SysRq-G over serial, dealing with watchdogs, etc. xairy.io/articles/pix...
xairy.io
📲 Debugging the Pixel 8 kernel via KGDB
Instructions for getting kernel log, building custom kernel, and enabling KGDB on Pixel 8
043
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 15/07/2025
Linux Kernel Hardening: Ten Years Deep Talk by Kees Cook about the relevance of various Linux kernel vulnerability classes and the mitigations that address them. Video: www.youtube.com/watch?v=c_Nx... Slides: static.sched.com/hosted_files...
073
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 10/07/2025
Bypass Kernel Barriers: Fuzzing Linux Kernel in Userspace With LKL Xuan Xing & Eugene Rodionov gave a talk about fuzzing the Linux kernel interfaces fully in user space using LKL (Linux Kernel Library). Video: www.youtube.com/watch?v=Wxmi... Slides: static.sched.com/hosted_files...
youtube.com
Bypass Kernel Barriers: Fuzzing Linux Kernel in Userspace With LKL - Xuan Xing & Eugene Rodionov
YouTube video by The Linux Foundation
011
Andrey Konovalov @andreyknvl.bsky.social · 01/07/2025
Schedule for my Fuzzing/Exploiting the Linux Kernel trainings for the rest of the year ⬇️
110
Andrey Konovalov @andreyknvl.bsky.social · 01/07/2025
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
May/June updates · xairy/linux-kernel-exploitation@e4d394c
011
Reposted by Andrey Konovalov
Anderson Nascimento @andersonc0d3.bsky.social · 30/06/2025
RVAsec 2025: Kevin Massey - Linux Kernel Exploitation for Beginners youtu.be/YfjHCt4SzQc Linux Kernel Exploitation For Beginners rvasec.com/slides/2025/...
youtu.be
RVAsec 2025: Kevin Massey - Linux Kernel Exploitation for Beginners
YouTube video by RVAsec
011
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 04/06/2025
KernelGP: Racing Against the Android Kernel Talk by Chariton Karamitas about ways to use FUSE for kernel exploitation from unprivileged SELinux contexts on Android. www.youtube.com/watch?v=DJBG...
youtube.com
OffensiveCon25 - Chariton Karamitas - KernelGP: Racing Against the Android Kernel
YouTube video by OffensiveCon
011
Reposted by Andrey Konovalov
Linux Kernel Security @linkersec.bsky.social · 12/05/2025
Linux Kernel Exploitation series Awesome series of articles by r1ru that outlines many commonly-used modern exploitation techniques. r1ru.github.io/categories/l...
121
Reposted by Andrey Konovalov
sam4k @sam4k.com · 08/05/2025
with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓 sam4k.com/page-table-k...
sam4k.com
Kernel Exploitation Techniques: Turning The (Page) Tables
This post explores attacking page tables as a Linux kernel exploitation technique for gaining powerful read/write primitives.
1134
Andrey Konovalov @andreyknvl.bsky.social · 07/05/2025
Updates for the Linux kernel exploitation collection 😋 github.com/xairy/linux-...
github.com
March/April updates · xairy/linux-kernel-exploitation@7c1b77c
010
Andrey Konovalov @andreyknvl.bsky.social · 06/05/2025
Gave a talk on external fuzzing of Linux kernel USB drivers with syzkaller at SAFACon. Includes a demonstration of how to rediscover CVE-2024-53104, an out-of-bounds bug in the USB Video Class driver. Slides: docs.google.com/presentation...
122
Reposted by Andrey Konovalov
Binni Shah @binitamshah.bsky.social · 19/04/2025
Unlocking secret ThinkPad functionality for emulating USB devices : xairy.io/articles/thi... credits @andreyknvl.bsky.social
xairy.io
🤫 Unlocking secret ThinkPad functionality for emulating USB devices
Enabling and using xDCI controller on ThinkPad X1 Carbon 6th Gen
173
Reposted by Andrey Konovalov
Hexacon @hexacon.bsky.social · 16/04/2025
Exploiting the Linux Kernel by Andrey Konovalov (@andreyknvl.bsky.social) www.hexacon.fr/trainer/kono...
021