Linux Kernel Security

400 posts

Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation. Maintained by @andreyknvl and @a13xp0p0v. Also on https://t.co/GVE11dpBb8 and https://t.co/YpxPWXnA6Z.

Beigetreten Eylül 2021
0 Folgt9.9K Follower
Linux Kernel Security
Linux Kernel Security@linkersec·
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets Excellent article by Quang Le about exploiting CVE-2025-38617 — a race condition that leads to a use-after-free in the packet sockets implementation. blog.calif.io/p/a-race-withi…
Linux Kernel Security tweet media
English
2
22
114
6K
Linux Kernel Security
Linux Kernel Security@linkersec·
The researcher glitched the setresuid syscall handler to bypass its checks and obtain the UID of 0. Bypassing SELinux via glitching remains to be investigated.
English
0
0
1
860
Linux Kernel Security
Linux Kernel Security@linkersec·
[Cryptodev-linux] Page-level UAF exploitation @nasm_re posted an article about exploiting a page-level UAF in the out-of-tree cryptodev-linux driver. The researcher modified struct file sprayed into a freed page to escalate privileges. nasm.re/posts/cryptode…
English
0
13
81
4K
Linux Kernel Security
Linux Kernel Security@linkersec·
Authors found multiple Android vendor drivers affected by the issue. They also wrote an exploit for the IMG DXT GPU driver to escalate privileges on Pixel 10.
English
0
0
3
1.1K
Linux Kernel Security
Linux Kernel Security@linkersec·
Dangling pointers, fragile memory — from an undisclosed vulnerability to Pixel 9 Pro privilege escalation Article about analyzing and exploiting a race condition that leads to a double-free in the Arm Mali GPU driver. dawnslab.jd.com/Pixel_9_Pro_Eo…
English
0
27
140
8.7K
Linux Kernel Security
Linux Kernel Security@linkersec·
The article also describes the nonsensical responses MediaTek gave to the bug reports, seemingly trying to weasel out of assigning a High impact rating to the reported bugs.
English
0
0
2
827
Linux Kernel Security
Linux Kernel Security@linkersec·
CVE-2025-68260: rust_binder: fix race condition on death_list First CVE was registered for the new Binder kernel driver written in Rust. The vulnerability is a race condition caused by a list operation in an unsafe code block. @gregkh/T/#u" target="_blank" rel="nofollow noopener">lore.kernel.org/linux-cve-anno…
Linux Kernel Security tweet media
English
0
8
51
5K
Linux Kernel Security
Linux Kernel Security@linkersec·
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit @MatheuzSecurity published an article about Singularity — a loadable kernel module rootkit developed for 6.x Linux kernels. The rootkit uses ftrace for hooking syscalls and hiding itself. blog.kyntra.io/Singularity-A-…
English
1
16
105
5.7K
Linux Kernel Security
Linux Kernel Security@linkersec·
Extending Kernel Race Windows Using '/dev/shm' Article by @farazsth98 about extending race condition windows via FALLOC_FL_PUNCH_HOLE. The technique allows delaying user memory accesses from the kernel mode, similar to userfaultfd and FUSE. faith2dxy.xyz/2025-11-28/ext…
Linux Kernel Security tweet media
English
1
12
95
5K