Sign in

Linux Kernel Security

@linkersec.bsky.social
203 followers 0 following 157 posts

Links related to Linux kernel security and exploitation. Maintained by @andreyknvl.bsky.social and Alexander Popov. See xairy.io/linkersec for mirrors.

PostsRepliesMedia
Linux Kernel Security @linkersec.bsky.social · 29/09/2026
PageJack in Action: CVE-2022-0995 exploit Article by Jean Vincent describing how a relatively old CVE can be exploited using the PageJack exploitation technique. blog.quarkslab.com/pagejack-in-...
001
Linux Kernel Security @linkersec.bsky.social · 21/09/2026
CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel Paper by Dong-ok Kim, Juhyun Song, et al. documenting the steps for executing a cross-cache attacks for caches with min_partial >= cpu_partial_slabs. insuyun.github.io/pubs/2025/ki...
100
Linux Kernel Security @linkersec.bsky.social · 16/09/2026
Testing race conditions with memory access tracing and stack-based delay injection Article by Jann Horn about MAccConc — a KCOV-based tool for exploring possible kernel code interleavings of a multi-threaded program. Article: projectzero.google/2026/09/macc... Tool: github.com/googleprojec...
000
Linux Kernel Security @linkersec.bsky.social · 09/09/2026
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free Article about exploiting CVE-2026-64564 in the implementation of the Stream Control Transmission Protocol (SCTP). Authors exploited a UAF in the kmalloc-1k cache to gain root and escape a container. matrix.tencent.com/en/2026/08/0...
000
Linux Kernel Security @linkersec.bsky.social · 15/08/2026
Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Robert Herrera about fuzzing USB drivers with syzkaller and writing an exploit that gains code execution over USB on Ubuntu. Article: media.defcon.org/DEF%20CON%20... Slides: media.defcon.org/DEF%20CON%20...
000
Linux Kernel Security @linkersec.bsky.social · 11/08/2026
IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of CVE-2026-43499 (kernel stack UAF) to Android. The researchers used KernelSnitch, ashmem fops overwriting, pipe_buffer corruption, and other tricks to perform LPE. nebusec.ai/research/ion...
000
Linux Kernel Security @linkersec.bsky.social · 23/07/2026
I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android. guysrd.github.io/epoll-uaf-ag...
020
Linux Kernel Security @linkersec.bsky.social · 22/07/2026
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance. nebusec.ai/research/ion...
000
Linux Kernel Security @linkersec.bsky.social · 20/07/2026
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache. cyberstan.co.uk/fuse-readdir...
001
Linux Kernel Security @linkersec.bsky.social · 18/07/2026
Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. github.com/V4bel/Janusc...
100
Linux Kernel Security @linkersec.bsky.social · 08/07/2026
ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM. github.com/V4bel/ITScape
011
Linux Kernel Security @linkersec.bsky.social · 03/07/2026
Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels. github.com/J-jaeyoung/b...
000
Linux Kernel Security @linkersec.bsky.social · 29/06/2026
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to perform the Dirty Pipe attack. cyberstan.co.uk/drm-lpe-linux/
000
Linux Kernel Security @linkersec.bsky.social · 25/06/2026
Off By !: Exploiting a Use-after-Free in the Linux Kernel Oliver Sieber published write-up on CVE-2026-23111 in nftables, found in early 2025, patched upstream by other researchers in Feb 2026. Article describes exploiting this UAF on Debian and Ubuntu. blog.exodusintel.com/2026/06/08/o...
blog.exodusintel.com
000
Linux Kernel Security @linkersec.bsky.social · 22/06/2026
CIFSwitch: a non-universal Linux local root vulnerability Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package. heyitsas.im/posts/cifswi...
heyitsas.im
CIFSwitch: a non-universal Linux local root vulnerability
Harnessing LLMs into composing complex, multihop vulnerability chains to discover CVE-2026-46243
110
Linux Kernel Security @linkersec.bsky.social · 10/06/2026
Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry. mohandacherir.github.io/Qdiv7/posts/...
000
Linux Kernel Security @linkersec.bsky.social · 09/06/2026
PinTheft Linux LPE Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring. github.com/v12-security...
github.com
pocs/pintheft at main · v12-security/pocs
poc it like it's hot. Contribute to v12-security/pocs development by creating an account on GitHub.
010
Linux Kernel Security @linkersec.bsky.social · 03/06/2026
Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios. cdn2.qualys.com/advisory/202...
010
Linux Kernel Security @linkersec.bsky.social · 01/06/2026
StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs. www.cs.ucr.edu/%7Ezhiyunq/p...
000
Linux Kernel Security @linkersec.bsky.social · 29/05/2026
Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF. lukasmaar.github.io/posts/qaic-p...
010
Linux Kernel Security @linkersec.bsky.social · 22/05/2026
Discovery & Validation in the Linux Kernel Three-part article by @sam4k.com about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs. Final part: bynar.io/blog/discove...
020
Linux Kernel Security @linkersec.bsky.social · 20/05/2026
Recent Page Cache Corruption Bugs All stem from code paths that allow in-place overwrites of user-supplied input pages without verifying they are writable. This enables overwriting page cache and thus changing in-memory contents of read-only files. Selected links below ⬇️
122
Linux Kernel Security @linkersec.bsky.social · 28/04/2026
Some notes on the security properties of the pipe_buffer kernel object Alexander Popov posted an article about a few experiments with the pipe_buffer kernel object within his kernel-hack-drill project. a13xp0p0v.github.io/2026/04/20/p...
a13xp0p0v.github.io
Some notes on the security properties of the pipe_buffer kernel object
Many exploits of Linux kernel vulnerabilities use the pipe_buffer kernel object to build strong exploit primitives. When I was experimenting with my personal project kernel-hack-drill, I discovered so...
100
Linux Kernel Security @linkersec.bsky.social · 23/04/2026
Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs Hyunwoo Kim published an article describing a complicated exploit of a race condition caused by a misuse of the cancel_work_sync() kernel API in the network subsystem. v4bel.github.io/linux/2026/0...
000
Linux Kernel Security @linkersec.bsky.social · 17/04/2026
Walkthrough of an N-day Android GPU driver vulnerability Talk by Angus about analyzing CVE-2022-22706 — a logical bug in the Mali GPU driver that allows getting write access to read-only memory. www.youtube.com/watch?v=G71d...
youtube.com
Walkthrough of an N-day Android GPU driver vulnerability - Angus, BSides Canberra 2025
YouTube video by BSides Canberra
000
Linux Kernel Security @linkersec.bsky.social · 16/04/2026
From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android. lukasmaar.github.io/posts/heap-k...
112
Linux Kernel Security @linkersec.bsky.social · 14/04/2026
Assessing Claude Mythos Preview’s cybersecurity capabilities Article by Nicholas Carlini et. al about the security research capabilities of the new Anthropic's LLM called Claude Mythos Preview. red.anthropic.com/2026/mythos-...
100
Linux Kernel Security @linkersec.bsky.social · 13/04/2026
slab: support for compiler-assisted type-based slab cache partitioning Marco Elver posted a kernel patch that provides an alternative mode to RANDOM_KMALLOC_CACHES called TYPED_KMALLOC_CACHES. lore.kernel.org/all/20260331...
100
Linux Kernel Security @linkersec.bsky.social · 11/04/2026
CrackArmor: Multiple vulnerabilities in AppArmor Article about a variety of vulnerabilities found in the AppArmor LSM implementation, including a few kernel memory corruptions. Authors exploited them to achieve LPE on Ubuntu and Debian. cdn2.qualys.com/advisory/202...
010
Linux Kernel Security @linkersec.bsky.social · 17/03/2026
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets Excellent article by Quang Le about exploiting CVE-2025-38617 — a race condition that leads to a use-after-free in the packet sockets implementation. blog.calif.io/p/a-race-wit...
112
Linux Kernel Security @linkersec.bsky.social · 04/03/2026
Analysis of Linux kernel bug fixes Jenny Guanni Qu posted a detailed analysis: — Kernel bugs hide for 2 years on average. Some hide for 20. pebblebed.com/blog/kernel-... — Who Writes the Bugs? A Deeper Look at 125,000 Kernel Vulnerabilities pebblebed.com/blog/kernel-...
000
Linux Kernel Security @linkersec.bsky.social · 07/02/2026
setresuid(⚡): Glitching Google's TV Streamer from adb to root. Talk by Niek Timmers about glitching the kernel of the Android-based Google TV Streamer device to escalate privileges via Electromagnetic Fault Injection. Video: www.youtube.com/watch?v=-w5m... Slides: hardwear.io/netherlands-...
youtube.com
Hardwear.io NL 2025: Glitching Google's TV Streamer From Adb To Root - Niek Timmers
YouTube video by hardwear.io
110
Linux Kernel Security @linkersec.bsky.social · 05/02/2026
[Cryptodev-linux] Page-level UAF exploitation nasm_re posted an article about exploiting a page-level UAF in the out-of-tree cryptodev-linux driver. The researcher modified struct file sprayed into a freed page to escalate privileges. nasm.re/posts/crypto...
nasm.re
[Cryptodev-linux] Page-level UAF exploitation
IntroductionIn november 2025 I started a fuzzing campaign against cryptodev-linux as part of a school project. I found +10 bugs (UAF, NULL pointer dereferences and integer overflows) and among all of
031
Linux Kernel Security @linkersec.bsky.social · 03/02/2026
Dirty Ptrace: Exploiting Undocumented Behaviors in Kernel mmap Handlers Talk by Xingyu Jin & Martijn Bogaard about a new type of logical bugs in kernel driver mmap handlers exploitable via the ptrace functionality. Video: www.youtube.com/watch?v=yAUJ... Slides: powerofcommunity.net/2025/slide/x...
youtube.com
POC2025 | Dirty Ptrace: Exploiting Undocumented Behaviors in Kernel mmap Handlers
YouTube video by POC2026
110
Linux Kernel Security @linkersec.bsky.social · 28/01/2026
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave Article by Seth Jenkins about exploiting a use-after-free in the driver for BigWave — an AV1 decoding hardware component present on Pixel SOCs. projectzero.google/2026/01/pixe...
110
Linux Kernel Security @linkersec.bsky.social · 19/01/2026
Article series about exploiting CVE-2025-38352 Faith posted three articles about exploiting a race condition in the implementation of POSIX CPU timers. Part 1️⃣ describes reproducing this race condition: faith2dxy.xyz/2025-12-22/c...
faith2dxy.xyz
CVE-2025-38352 (Part 1) - In-the-wild Android Kernel Vulnerability Analysis + PoC
Analyzing and writing a PoC for CVE-2025-38352.
100
Linux Kernel Security @linkersec.bsky.social · 09/01/2026
Dangling pointers, fragile memory — from an undisclosed vulnerability to Pixel 9 Pro privilege escalation Article about analyzing and exploiting a race condition that leads to a double-free in the Arm Mali GPU driver. dawnslab.jd.com/Pixel_9_Pro_...
dawnslab.jd.com
悬挂的指针、脆弱的内存──从一个未公开的漏洞到 Pixel 9 Pro 提权
GPU 驱动由于其与内存管理的紧密联系,已经成为近年来 Android Kernel 中一个比较有价值的攻击面,与 GPU 相关的 CVE 不算少,但是只有很少数漏洞被公开分析,安全公告中也不会谈及漏洞细节,因此每个版本的 patch 就成了分析漏洞的重要线索。
020
Linux Kernel Security @linkersec.bsky.social · 05/01/2026
mediatek? more like media-rekt, amirite. Article by hypr covering an assortment of bugs the author found in the MediaTek MT76xx and MT7915 Wi-Fi drivers. blog.coffinsec.com/0days/2025/1...
blog.coffinsec.com
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
100
Linux Kernel Security @linkersec.bsky.social · 22/12/2025
CVE-2025-68260: rust_binder: fix race condition on death_list First CVE was registered for the new Binder kernel driver written in Rust. The vulnerability is a race condition caused by a list operation in an unsafe code block. lore.kernel.org/linux-cve-an...
000
Linux Kernel Security @linkersec.bsky.social · 18/12/2025
MatheuZSec published a detailed article about Singularity — a loadable kernel module rootkit developed for 6.x Linux kernels. The rootkit uses ftrace for hooking syscalls and hiding itself. Article: blog.kyntra.io/Singularity-... Code: github.com/MatheuZSecur...
blog.kyntra.io
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
010
Linux Kernel Security @linkersec.bsky.social · 16/12/2025
Extending Kernel Race Windows Using '/dev/shm' Article by Faith about extending race condition windows via FALLOC_FL_PUNCH_HOLE. The technique allows delaying user memory accesses from the kernel mode, similar to userfaultfd and FUSE. faith2dxy.xyz/2025-11-28/e...
000
Linux Kernel Security @linkersec.bsky.social · 10/12/2025
An RbTree Family Drama Talk by William Liu and Savino Dicanosa @cor_ctf about exploiting CVE-2025-38001 — a use-after-free in the network packet scheduler. Video: www.youtube.com/watch?v=C-52... Slides: storage.googleapis.com/static.cor.t...
youtube.com
HEXACON 2025 - An RbTree Family Drama by William Liu & Savino Dicanosa
YouTube video by Hexacon
100
Linux Kernel Security @linkersec.bsky.social · 06/12/2025
Déjà Vu in Linux io_uring Talk by Pumpkin about exploiting CVE-2025-21836 — a race condition that leads to a use-after-free in the io_uring subsystem. Video: www.youtube.com/watch?v=Ry4e... Slides: u1f383.github.io/slides/talks...
youtube.com
HEXACON 2025 - Déjà Vu in Linux io_uring by Pumpkin
YouTube video by Hexacon
000
Linux Kernel Security @linkersec.bsky.social · 05/12/2025
CUDA de Grâce Talk by @chompie.rip and Samuel Lovejoy about exploiting a race condition that leads to a double-free in the NVIDIA GPU driver to escape a container created with NVIDIA Container Toolkit. Video: www.youtube.com/watch?v=Lvz2... Slides: docs.google.com/presentation...
youtube.com
HEXACON 2025 - CUDA de Grâce by Valentina Palmiotti & Samuel Lovejoy
YouTube video by Hexacon
000
Linux Kernel Security @linkersec.bsky.social · 25/11/2025
Race Condition Symphony: From Tiny Idea to Pwnie Slides from a talk by Hyunwoo Kim and Wongi Lee about exploiting CVE-2024-50264 — a race condition in the vsock subsystem. powerofcommunity.net/2025/slide/h...
100
Linux Kernel Security @linkersec.bsky.social · 21/11/2025
LinkPro: eBPF rootkit analysis Théo Letailleur published an article with a detailed description of an eBPF rootkit that hides itself on the compromised system and activates its features upon receiving a "magic packet". www.synacktiv.com/en/publicati...
synacktiv.com
LinkPro: eBPF rootkit analysis
LinkPro: eBPF rootkit analysis
000
Linux Kernel Security @linkersec.bsky.social · 18/11/2025
Slice: SAST + LLM Interprocedural Context Extractor Amazing article by Caleb Gross about combining the use of CodeQL and LLMs to reliably rediscover CVE-2025-37899 — a remotely-triggerable vulnerability in the ksmbd module. noperator.dev/posts/slice/
000
Linux Kernel Security @linkersec.bsky.social · 14/11/2025
Enhancing FineIBT @lwndotnet.bsky.social article that describes the talk by Scott Constable and Sebastian Österlund about the ongoing work to improve FineIBT (Fine-grain Control-flow Enforcement with Indirect Branch Tracking). lwn.net/Articles/103...
100
Linux Kernel Security @linkersec.bsky.social · 13/11/2025
Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE Talk by Pan Zhenpeng and Jheng Bing Jhong about exploiting a logical bug in the Pixel GXP driver that allows overwriting read-only files. Video: www.youtube.com/watch?v=_iSw... Slides: hitcon.org/2025/slides/...
000
Linux Kernel Security @linkersec.bsky.social · 11/11/2025
Exploiting CVE-2025-21479 on a Samsung S23 Article by XploitBengineer about exploiting a logical bug in the Qualcomm Adreno GPU firmware to take over the kernel on Samsung S23 via a combination of page table attacks. xploitbengineer.github.io/CVE-2025-21479
000