Linux Kernel Security @linkersec.bsky.social · 08/10/2026SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive Perspective Paper with analysis of 121 publicly documented exploits since 2015 and in-depth evaluation of 51 existing kernel defense mechanisms. www.ndss-symposium.org/ndss-paper/s... 000
Linux Kernel Security @linkersec.bsky.social · 29/09/2026PageJack in Action: CVE-2022-0995 exploit Article by Jean Vincent describing how a relatively old CVE can be exploited using the PageJack exploitation technique. blog.quarkslab.com/pagejack-in-... 001
Linux Kernel Security @linkersec.bsky.social · 21/09/2026CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel Paper by Dong-ok Kim, Juhyun Song, et al. documenting the steps for executing a cross-cache attacks for caches with min_partial >= cpu_partial_slabs. insuyun.github.io/pubs/2025/ki... 100
Linux Kernel Security @linkersec.bsky.social · 16/09/2026Testing race conditions with memory access tracing and stack-based delay injection Article by Jann Horn about MAccConc — a KCOV-based tool for exploring possible kernel code interleavings of a multi-threaded program. Article: projectzero.google/2026/09/macc... Tool: github.com/googleprojec... 000
Linux Kernel Security @linkersec.bsky.social · 09/09/2026SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free Article about exploiting CVE-2026-64564 in the implementation of the Stream Control Transmission Protocol (SCTP). Authors exploited a UAF in the kmalloc-1k cache to gain root and escape a container. matrix.tencent.com/en/2026/08/0... 000
Linux Kernel Security @linkersec.bsky.social · 15/08/2026Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Robert Herrera about fuzzing USB drivers with syzkaller and writing an exploit that gains code execution over USB on Ubuntu. Article: media.defcon.org/DEF%20CON%20... Slides: media.defcon.org/DEF%20CON%20... 000
Linux Kernel Security @linkersec.bsky.social · 11/08/2026IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of CVE-2026-43499 (kernel stack UAF) to Android. The researchers used KernelSnitch, ashmem fops overwriting, pipe_buffer corruption, and other tricks to perform LPE. nebusec.ai/research/ion... 000
Linux Kernel Security @linkersec.bsky.social · 23/07/2026I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android. guysrd.github.io/epoll-uaf-ag... 020
Linux Kernel Security @linkersec.bsky.social · 22/07/2026IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance. nebusec.ai/research/ion... 000
Linux Kernel Security @linkersec.bsky.social · 20/07/2026Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache. cyberstan.co.uk/fuse-readdir... 001
Linux Kernel Security @linkersec.bsky.social · 18/07/2026Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. github.com/V4bel/Janusc... 100
Linux Kernel Security @linkersec.bsky.social · 08/07/2026ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM. github.com/V4bel/ITScape 011
Linux Kernel Security @linkersec.bsky.social · 03/07/2026Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels. github.com/J-jaeyoung/b... 000
Linux Kernel Security @linkersec.bsky.social · 29/06/2026Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to perform the Dirty Pipe attack. cyberstan.co.uk/drm-lpe-linux/ 000
Linux Kernel Security @linkersec.bsky.social · 10/06/2026Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry. mohandacherir.github.io/Qdiv7/posts/... 000
Linux Kernel Security @linkersec.bsky.social · 03/06/2026Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios. cdn2.qualys.com/advisory/202... 010
Linux Kernel Security @linkersec.bsky.social · 01/06/2026StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs. www.cs.ucr.edu/%7Ezhiyunq/p... 000
Linux Kernel Security @linkersec.bsky.social · 29/05/2026Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF. lukasmaar.github.io/posts/qaic-p... 010
Linux Kernel Security @linkersec.bsky.social · 22/05/2026Discovery & Validation in the Linux Kernel Three-part article by @sam4k.com about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs. Final part: bynar.io/blog/discove... 020
Linux Kernel Security @linkersec.bsky.social · 20/05/2026Recent Page Cache Corruption Bugs All stem from code paths that allow in-place overwrites of user-supplied input pages without verifying they are writable. This enables overwriting page cache and thus changing in-memory contents of read-only files. Selected links below ⬇️ 122
Linux Kernel Security @linkersec.bsky.social · 23/04/2026Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs Hyunwoo Kim published an article describing a complicated exploit of a race condition caused by a misuse of the cancel_work_sync() kernel API in the network subsystem. v4bel.github.io/linux/2026/0... 000
Linux Kernel Security @linkersec.bsky.social · 16/04/2026From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android. lukasmaar.github.io/posts/heap-k... 112
Linux Kernel Security @linkersec.bsky.social · 14/04/2026Assessing Claude Mythos Preview’s cybersecurity capabilities Article by Nicholas Carlini et. al about the security research capabilities of the new Anthropic's LLM called Claude Mythos Preview. red.anthropic.com/2026/mythos-... 100
Linux Kernel Security @linkersec.bsky.social · 13/04/2026slab: support for compiler-assisted type-based slab cache partitioning Marco Elver posted a kernel patch that provides an alternative mode to RANDOM_KMALLOC_CACHES called TYPED_KMALLOC_CACHES. lore.kernel.org/all/20260331... 100
Linux Kernel Security @linkersec.bsky.social · 11/04/2026CrackArmor: Multiple vulnerabilities in AppArmor Article about a variety of vulnerabilities found in the AppArmor LSM implementation, including a few kernel memory corruptions. Authors exploited them to achieve LPE on Ubuntu and Debian. cdn2.qualys.com/advisory/202... 010
Linux Kernel Security @linkersec.bsky.social · 17/03/2026A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets Excellent article by Quang Le about exploiting CVE-2025-38617 — a race condition that leads to a use-after-free in the packet sockets implementation. blog.calif.io/p/a-race-wit... 112
Linux Kernel Security @linkersec.bsky.social · 04/03/2026Analysis of Linux kernel bug fixes Jenny Guanni Qu posted a detailed analysis: — Kernel bugs hide for 2 years on average. Some hide for 20. pebblebed.com/blog/kernel-... — Who Writes the Bugs? A Deeper Look at 125,000 Kernel Vulnerabilities pebblebed.com/blog/kernel-... 000
Linux Kernel Security @linkersec.bsky.social · 28/01/2026A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave Article by Seth Jenkins about exploiting a use-after-free in the driver for BigWave — an AV1 decoding hardware component present on Pixel SOCs. projectzero.google/2026/01/pixe... 110
Linux Kernel Security @linkersec.bsky.social · 22/12/2025CVE-2025-68260: rust_binder: fix race condition on death_list First CVE was registered for the new Binder kernel driver written in Rust. The vulnerability is a race condition caused by a list operation in an unsafe code block. lore.kernel.org/linux-cve-an... 000
Linux Kernel Security @linkersec.bsky.social · 16/12/2025Extending Kernel Race Windows Using '/dev/shm' Article by Faith about extending race condition windows via FALLOC_FL_PUNCH_HOLE. The technique allows delaying user memory accesses from the kernel mode, similar to userfaultfd and FUSE. faith2dxy.xyz/2025-11-28/e... 000
Linux Kernel Security @linkersec.bsky.social · 25/11/2025Race Condition Symphony: From Tiny Idea to Pwnie Slides from a talk by Hyunwoo Kim and Wongi Lee about exploiting CVE-2024-50264 — a race condition in the vsock subsystem. powerofcommunity.net/2025/slide/h... 100
Linux Kernel Security @linkersec.bsky.social · 18/11/2025Slice: SAST + LLM Interprocedural Context Extractor Amazing article by Caleb Gross about combining the use of CodeQL and LLMs to reliably rediscover CVE-2025-37899 — a remotely-triggerable vulnerability in the ksmbd module. noperator.dev/posts/slice/ 000
Linux Kernel Security @linkersec.bsky.social · 14/11/2025Enhancing FineIBT @lwndotnet.bsky.social article that describes the talk by Scott Constable and Sebastian Österlund about the ongoing work to improve FineIBT (Fine-grain Control-flow Enforcement with Indirect Branch Tracking). lwn.net/Articles/103... 100
Linux Kernel Security @linkersec.bsky.social · 13/11/2025Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE Talk by Pan Zhenpeng and Jheng Bing Jhong about exploiting a logical bug in the Pixel GXP driver that allows overwriting read-only files. Video: www.youtube.com/watch?v=_iSw... Slides: hitcon.org/2025/slides/... 000
Linux Kernel Security @linkersec.bsky.social · 11/11/2025Exploiting CVE-2025-21479 on a Samsung S23 Article by XploitBengineer about exploiting a logical bug in the Qualcomm Adreno GPU firmware to take over the kernel on Samsung S23 via a combination of page table attacks. xploitbengineer.github.io/CVE-2025-21479 000
Linux Kernel Security @linkersec.bsky.social · 11/11/2025LPE via refcount imbalance in the af_unix of Ubuntu Article and exploit by kylebot for a refcount imbalance bug in the Ubuntu kernel's Unix sockets implementation disclosed during the TyphoonPWN 2025 competition. ssd-disclosure.com/lpe-via-refc... 010
Linux Kernel Security @linkersec.bsky.social · 07/11/2025kernelCTF: CVE-2025-38477 kernelCTF entry for a race condition in the network scheduler subsystem. Most notably, shows a technique of putting controlled data into unmapped sections of vmlinux. github.com/n132/securit... 021
Linux Kernel Security @linkersec.bsky.social · 06/11/2025Defeating KASLR by Doing Nothing at All Article by Seth Jenkins about a few problems with physical memory KASLR on arm64 devices. googleprojectzero.blogspot.com/2025/11/defe... 011
Linux Kernel Security @linkersec.bsky.social · 25/10/2025Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers Article by Robin Bastide about exploiting a NULL-pointer-dereference that led to a UAF access to the kernel stack in the NVIDIA GPU driver. blog.quarkslab.com/nvidia_gpu_k... 111
Linux Kernel Security @linkersec.bsky.social · 24/10/2025ksmbd - Exploiting CVE-2025-37947 Article by Norbert Szetei about locally exploiting CVE-2025-37947 — a page OOB write in the ksmbd module. Article: blog.doyensec.com/2025/10/08/k... Exploit: github.com/doyensec/KSM... 020
Linux Kernel Security @linkersec.bsky.social · 02/10/2025Dirty Pageflags: Revisiting PTE Exploitation in Linux Article by ptr-yudai on the exploitation technique of overwriting the R/W flag in a PTE entry to allow writing into read-only files. ptr-yudai.hatenablog.com/entry/2025/0... 010
Linux Kernel Security @linkersec.bsky.social · 02/10/2025Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days William Liu posted an article about exploiting a slab object overflow (CVE-2023-52440) and remote infoleak (CVE-2023-4130) in the kernel SMB3 daemon to gain RCE. www.willsroot.io/2025/09/ksmb... 000
Linux Kernel Security @linkersec.bsky.social · 30/09/2025The anatomy of a bug: 6 Months at STAR Labs Gerrard Tai posted an article describing their experience in finding kernel bugs and participating in the KernelCTF and Pwn2Own competitions. gerrardtai.com/anatomy-of-a... 011
Linux Kernel Security @linkersec.bsky.social · 26/09/2025A Syzkaller Summer: Fixing False Positive Soft Lockups in net/sched Fuzzing Article by Will's Root about fixing the soft lockup bug found when fuzzing the network scheduler subsystem with syzkaller. www.willsroot.io/2025/09/syz-... 100
Linux Kernel Security @linkersec.bsky.social · 24/09/2025corCTF 2025 - corphone Article by Pumpkin about exploiting a UAF in a custom Android kernel module created for a CTF task. u1f383.github.io/android/2025... 100
Linux Kernel Security @linkersec.bsky.social · 10/09/2025ksmbd - Fuzzing Improvements and Vulnerability Discovery Another article by Norbert Szetei about fuzzing the ksmbd module with syzkaller. blog.doyensec.com/2025/09/02/k... 100
Linux Kernel Security @linkersec.bsky.social · 10/09/2025arm64: Linear mapping is mapped at the same static virtual address Bug report by Seth Jenkins and Jann Horn showing that the physmap region is mapped at a fixed virtual address on Android despite KASLR. project-zero.issues.chromium.org/issues/43420... 010
Linux Kernel Security @linkersec.bsky.social · 04/09/2025Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel Alexander Popov published an article about exploiting a race condition in AF_VSOCK subsystem, the bug that received a Pwnie Award 2025. a13xp0p0v.github.io/2025/09/02/k... 100
Linux Kernel Security @linkersec.bsky.social · 04/09/2025Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel Alexander Popov published an article about exploiting a race condition in AF_VSOCK subsystem, the bug that received a Pwnie Award 2025. a13xp0p0v.github.io/2025/09/02/k... 100
Linux Kernel Security @linkersec.bsky.social · 24/08/2025From Chrome renderer code exec to kernel with MSG_OOB Jann Horn posted an article about exploiting CVE-2025-38236, a UAF in the UNIX domain sockets. googleprojectzero.blogspot.com/2025/08/from... 110