tgindex
Linux Kernel Security

Linux Kernel Security

Статистика

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec

Последний пост
15 авг.
Последнее чтение
15:38
Постов за неделю
2
Всего постов
21
Тип
открытый
Язык
английский
Категория
Новости и СМИ (по похожим)
В каталоге с
12 авг.
Подписчики
4 636
+7 за 4 дн.
Сутки
+1
+0,02%
Неделя
 
Месяц
 
Просмотров на пост
3 193
21 постов
Вовлечённость
68,9%
к подписчикам
Постов в день
0,3
всего 21
Упоминаний
3
каналов
Охват размещения
оценка
1/24сутки в ленте
1 040
1/48двое суток
1 191
1/72трое суток
1 285

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • 15 авг.7911439

    Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Robert Herrera about fuzzing USB drivers with syzkaller and writing an exploit that gains code execution over USB on Ubuntu.

  • 11 авг.1 5561330

    IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of CVE-2026-43499 (racy stack use-after-free in the futex implementation) to Android. The researchers used KernelSnitch, ashmem fops overwriting, pipe_buffer corruption, and other tricks to perform LPE.

  • 23 июл.2 5671319

    I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android.

  • 22 июл.2 4511728

    IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance.

  • 21 июл.2 274927

    Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache.

  • 18 июл.2 4381922

    Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. The article only covers achieving a kernel crash via this bug, but the vulnerability can also be exploited to escape the guest VM. The author used this bug to pwn a kvmCTF instance.

  • 8 июл.7 7201962

    ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM.

  • 3 июл.4 5682550

    Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels.

  • 27 июн.3 3211028

    Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to set PIPE_BUF_FLAG_CAN_MERGE and perform the Dirty Pipe attack.

  • 25 июн.2 988926

    Off By !: Exploiting a Use-after-Free in the Linux Kernel Oliver Sieber published a write-up about CVE-2026-23111 in nftables, which they found in early 2025 and other researchers patched upstream in February 2026. The article describes exploiting this UAF on Debian and Ubuntu.

  • 22 июн.2 8631116

    CIFSwitch: a non-universal Linux local root vulnerability Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package. An attacker can forge a "cifs.spnego" key in Linux keyring to make the kernel run a root userspace helper to escalate privileges of the attacker's process.

  • 10 июн.3 253723

    Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry.

  • 9 июн.3 065316

    PinTheft Linux LPE Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring.

  • 3 июн.3 8741933

    Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios.

  • 1 июн.3 4351340

    StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs.

  • 29 мая3 3991230

    Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF.

  • 22 мая3 690921

    Discovery & Validation in the Linux Kernel Three-part article by Samuel Page about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs.

  • 20 мая4 1621639

    Recent Page Cache Corruption Bugs Multitude of vulnerabilities that allow overwriting the page cache and thus changing the in-memory contents of read-only files to gain LPE or escape a container in certain scenarios. All stem from kernel code paths that perform in-place overwrites of user-supplied input pages without verifying that the pages are writable. Copy Fail (CVE-2026-31431): — Announcement; — Better write-up. Dirty Frag (CVE-2026-43284 and CVE-2026-43500): — Covers two independent vulnerabilities that do not require chaining; — CVE-2026-43284 is alternatively titled Copy Fail 2; — Original write-up; — Avoiding bruteforcing for CVE-2026-43500. Fragnesia (CVE-2026-46300): — Original report; — Variant. DirtyCBC / DirtyDecrypt (CVE-2026-31635?): — Write-up; — Another exploit.

  • 20 мая2 5052

    видео или голосовое, без подписи

  • 20 мая2 9342

    видео или голосовое, без подписи

Linux Kernel Security — tgindex