ar
Feedback
Linux Kernel Security

Linux Kernel Security

الذهاب إلى القناة على Telegram

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec

إظهار المزيد
4 592
المشتركون
لا توجد بيانات24 ساعات
+17 أيام
+12630 أيام

جاري تحميل البيانات...

جذب المشتركين
يوليو '26
يوليو '26
+142
في 5 قنوات
يونيو '26
+163
في 0 قنوات
Get PRO
مايو '26
+124
في 0 قنوات
Get PRO
أبريل '26
+106
في 0 قنوات
Get PRO
مارس '26
+81
في 0 قنوات
Get PRO
فبراير '26
+107
في 1 قنوات
Get PRO
يناير '26
+124
في 4 قنوات
Get PRO
ديسمبر '25
+156
في 2 قنوات
Get PRO
نوفمبر '25
+120
في 1 قنوات
Get PRO
أكتوبر '25
+95
في 1 قنوات
Get PRO
سبتمبر '25
+102
في 2 قنوات
Get PRO
أغسطس '25
+52
في 1 قنوات
Get PRO
يوليو '25
+70
في 1 قنوات
Get PRO
يونيو '25
+51
في 1 قنوات
Get PRO
مايو '25
+65
في 2 قنوات
Get PRO
أبريل '25
+78
في 2 قنوات
Get PRO
مارس '25
+111
في 2 قنوات
Get PRO
فبراير '25
+53
في 0 قنوات
Get PRO
يناير '25
+52
في 1 قنوات
Get PRO
ديسمبر '24
+147
في 3 قنوات
Get PRO
نوفمبر '24
+93
في 0 قنوات
Get PRO
أكتوبر '24
+137
في 2 قنوات
Get PRO
سبتمبر '24
+134
في 2 قنوات
Get PRO
أغسطس '24
+111
في 2 قنوات
Get PRO
يوليو '24
+106
في 2 قنوات
Get PRO
يونيو '24
+127
في 0 قنوات
Get PRO
مايو '24
+77
في 0 قنوات
Get PRO
أبريل '24
+94
في 0 قنوات
Get PRO
مارس '24
+81
في 1 قنوات
Get PRO
فبراير '24
+96
في 0 قنوات
Get PRO
يناير '24
+104
في 0 قنوات
Get PRO
ديسمبر '23
+84
في 0 قنوات
Get PRO
نوفمبر '23
+150
في 0 قنوات
Get PRO
أكتوبر '23
+91
في 0 قنوات
Get PRO
سبتمبر '23
+134
في 0 قنوات
Get PRO
أغسطس '23
+92
في 0 قنوات
Get PRO
يوليو '23
+73
في 0 قنوات
Get PRO
يونيو '23
+100
في 0 قنوات
Get PRO
مايو '23
+144
في 0 قنوات
Get PRO
أبريل '23
+36
في 0 قنوات
Get PRO
مارس '23
+43
في 0 قنوات
Get PRO
فبراير '23
+73
في 0 قنوات
Get PRO
يناير '23
+67
في 0 قنوات
Get PRO
ديسمبر '22
+80
في 0 قنوات
Get PRO
نوفمبر '22
+85
في 0 قنوات
Get PRO
أكتوبر '22
+66
في 0 قنوات
Get PRO
سبتمبر '22
+77
في 0 قنوات
Get PRO
أغسطس '22
+109
في 0 قنوات
Get PRO
يوليو '22
+67
في 0 قنوات
Get PRO
يونيو '22
+84
في 0 قنوات
Get PRO
مايو '22
+142
في 0 قنوات
Get PRO
أبريل '22
+91
في 0 قنوات
Get PRO
مارس '22
+98
في 0 قنوات
Get PRO
فبراير '22
+68
في 0 قنوات
Get PRO
يناير '22
+128
في 0 قنوات
Get PRO
ديسمبر '21
+57
في 0 قنوات
Get PRO
نوفمبر '21
+149
في 0 قنوات
Get PRO
أكتوبر '21
+64
في 0 قنوات
Get PRO
سبتمبر '21
+111
في 0 قنوات
Get PRO
أغسطس '21
+123
في 0 قنوات
Get PRO
يوليو '21
+48
في 0 قنوات
Get PRO
يونيو '21
+23
في 0 قنوات
Get PRO
مايو '21
+29
في 0 قنوات
Get PRO
أبريل '21
+333
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
26 يوليو+1
25 يوليو+2
24 يوليو+3
23 يوليو+2
22 يوليو+2
21 يوليو+4
20 يوليو+3
19 يوليو+2
18 يوليو+1
17 يوليو+5
16 يوليو+2
15 يوليو+5
14 يوليو+5
13 يوليو+5
12 يوليو+7
11 يوليو+4
10 يوليو+9
09 يوليو+6
08 يوليو+20
07 يوليو+7
06 يوليو+12
05 يوليو+5
04 يوليو+13
03 يوليو+10
02 يوليو+4
01 يوليو+3
منشورات القناة
I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerabili
I handed the epoll UAF to an agent Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android.

2
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance.
1 072
3
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694) Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache.
1 299
4
Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shado
Januscape: Guest-to-Host Escape in KVM/x86 Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected. The article only covers achieving a kernel crash via this bug, but the vulnerability can also be exploited to escape the guest VM. The author used this bug to pwn a kvmCTF instance.
1 750
5
ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on
ITScape: Guest-to-Host Escape in KVM/arm64 Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM.
6 445
6
Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the e
Bad Epoll: The bug missed by Mythos Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels.
4 231
7
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploit
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to set PIPE_BUF_FLAG_CAN_MERGE and perform the Dirty Pipe attack.
3 072
8
Off By !: Exploiting a Use-after-Free in the Linux Kernel Oliver Sieber published a write-up about CVE-2026-23111 in nftables, which they found in early 2025 and other researchers patched upstream in February 2026. The article describes exploiting this UAF on Debian and Ubuntu.
2 785
9
CIFSwitch: a non-universal Linux local root vulnerability Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package. An attacker can forge a "cifs.spnego" key in Linux keyring to make the kernel run a root userspace helper to escalate privileges of the attacker's process.
2 656
10
Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and th
Unix GC Remastered Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry.
2 820
11
PinTheft Linux LPE Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring.
2 461
12
Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace imp
Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333) Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios.
2 923
13
StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for gen
StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs.
2 629
14
Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about e
Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF.
2 575
15
Discovery & Validation in the Linux Kernel Three-part article by Samuel Page about analyzing two vulnerabilities (in CAN sock
Discovery & Validation in the Linux Kernel Three-part article by Samuel Page about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs.
2 849
16
Recent Page Cache Corruption Bugs Multitude of vulnerabilities that allow overwriting the page cache and thus changing the in-memory contents of read-only files to gain LPE or escape a container in certain scenarios. All stem from kernel code paths that perform in-place overwrites of user-supplied input pages without verifying that the pages are writable. Copy Fail (CVE-2026-31431): — Announcement; — Better write-up. Dirty Frag (CVE-2026-43284 and CVE-2026-43500): — Covers two independent vulnerabilities that do not require chaining; — CVE-2026-43284 is alternatively titled Copy Fail 2; — Original write-up; — Avoiding bruteforcing for CVE-2026-43500. Fragnesia (CVE-2026-46300): — Original report; — Variant. DirtyCBC / DirtyDecrypt (CVE-2026-31635?): — Write-up; — Another exploit.
2 903
17
+1
لا يوجد نص...
1 998