Web appOpen in Telegram
LLinux Kernel Security

Linux Kernel Security

@linkersec · channel · Tech · indexed since 2026-04-17
4 745subscribers+9 in a week
363posts in the index
A
Andrey Konovalov
Photo
click to show
Assessing Claude Mythos Preview’s cybersecurity capabilities Article by Nicholas Carlini et. al about the security research capabilities of the new Anthropic's LLM called Claude Mythos Preview. The LLM was used to discover multiple 0-days in the Linux kernel and also write privilege escalation exploits for a few previously known vulnerabilities; the article provides a detailed write-up for two such exploits.
32 · 3.6K ·
A
Andrey Konovalov
Photo
click to show
From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android. The attack allows leaking addresses of exploitation-relevant kernel allocations. Lukas also published the source code for executing the attack.
24 · 3.9K ·
A
Andrey Konovalov
Link
click to show
Walkthrough of an N-day Android GPU driver vulnerability Talk by Angus about analyzing CVE-2022-22706 — a logical bug in the Mali GPU driver that allows getting write access to read-only memory.
30 · 4.3K ·
A
Alexander Popov
Photo
click to show
Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs Hyunwoo Kim published an article describing a complicated exploit of a race condition caused by a misuse of the cancel_work_sync() kernel API in the network subsystem.
22 · 4.2K ·
A
Alexander Popov
Link
click to show
Some notes on the security properties of the pipe_buffer kernel object a13xp0p0v (me) posted an article about a few experiments with the pipe_buffer kernel object within his kernel-hack-drill project. Alexander described multiple pipe_buffer features relevant for kernel exploits that rely on this object.
13 · 4.3K ·
A
Recent Page Cache Corruption Bugs Multitude of vulnerabilities that allow overwriting the page cache and thus changing the in-memory contents of read-only files to gain LPE or escape a container in certain scenarios. All stem from kernel code paths that perform in-place overwrites of user-supplied input pages without verifying that the pages are writable. Copy Fail (CVE-2026-31431): — Announcement; — Better write-up. Dirty Frag (CVE-2026-43284 and CVE-2026-43500): — Covers two independent vulnerabilities that do not require chaining; — CVE-2026-43284 is alternatively titled Copy Fail 2; — Original write-up; — Avoiding bruteforcing for CVE-2026-43500. Fragnesia (CVE-2026-46300): — Original report; — Variant. DirtyCBC / DirtyDecrypt (CVE-2026-31635?): — Write-up; — Another exploit.
39 · 4.4K ·
A
Andrey Konovalov
Photo
click to show
Discovery & Validation in the Linux Kernel Three-part article by Samuel Page about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs.
22 · 3.8K ·
A
Andrey Konovalov
Photo
click to show
Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF.
31 · 3.6K ·
A
Andrey Konovalov
Photo
click to show
StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs.
41 · 3.7K ·
A
Andrey Konovalov
Photo
click to show
Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios.
34 · 4.6K ·
A
Alexander Popov
Link
click to show
PinTheft Linux LPE Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring.
16 · 3.4K ·
A
Andrey Konovalov
Photo
click to show
Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry.
23 · 3.8K ·
A
Alexander Popov
Link
click to show
CIFSwitch: a non-universal Linux local root vulnerability Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package. An attacker can forge a "cifs.spnego" key in Linux keyring to make the kernel run a root userspace helper to escalate privileges of the attacker's process.
16 · 3.4K ·
A
Alexander Popov
Link
click to show
Off By !: Exploiting a Use-after-Free in the Linux Kernel Oliver Sieber published a write-up about CVE-2026-23111 in nftables, which they found in early 2025 and other researchers patched upstream in February 2026. The article describes exploiting this UAF on Debian and Ubuntu.
27 · 3.6K ·
A
Alexander Popov
Photo
click to show
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to set PIPE_BUF_FLAG_CAN_MERGE and perform the Dirty Pipe attack.
28 · 3.9K ·
A
Andrey Konovalov
Photo
click to show
Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels.
51 · 5K ·
A
Andrey Konovalov
Photo
click to show
ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM.
67 · 9.4K ·
A
Alexander Popov
Photo
click to show
Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. The article only covers achieving a kernel crash via this bug, but the vulnerability can also be exploited to escape the guest VM. The author used this bug to pwn a kvmCTF instance.
24 · 3.1K ·
A
Andrey Konovalov
Photo
click to show
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache.
30 · 3.1K ·
A
Andrey Konovalov
Photo
click to show
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance.
29 · 3.6K ·
A
Andrey Konovalov
Photo
click to show
I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android.
19 · 4K ·
A
Alexander Popov
Photo
click to show
IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of CVE-2026-43499 (racy stack use-after-free in the futex implementation) to Android. The researchers used KernelSnitch, ashmem fops overwriting, pipe_buffer corruption, and other tricks to perform LPE.
36 · 3.8K ·
A
Andrey Konovalov
Photo
click to show
Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Robert Herrera about fuzzing USB drivers with syzkaller and writing an exploit that gains code execution over USB on Ubuntu.
57 · 5.2K ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count