Linux Kernel Security
رفتن به کانال در Telegram
Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
نمایش بیشتر4 591
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+17 روز
+12830 روز
در حال بارگیری داده...
کانالهای مشابه
ابر برچسبها
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
ژوئیه '26
ژوئیه '26
+140
در 5 کانالها
ژوئن '26
+163
در 0 کانالها
Get PRO
مه '26
+124
در 0 کانالها
Get PRO
آوریل '26
+106
در 0 کانالها
Get PRO
مارس '26
+81
در 0 کانالها
Get PRO
فوریه '26
+107
در 1 کانالها
Get PRO
ژانویه '26
+124
در 4 کانالها
Get PRO
دسامبر '25
+156
در 2 کانالها
Get PRO
نوامبر '25
+120
در 1 کانالها
Get PRO
اکتبر '25
+95
در 1 کانالها
Get PRO
سپتامبر '25
+102
در 2 کانالها
Get PRO
اوت '25
+52
در 1 کانالها
Get PRO
ژوئیه '25
+70
در 1 کانالها
Get PRO
ژوئن '25
+51
در 1 کانالها
Get PRO
مه '25
+65
در 2 کانالها
Get PRO
آوریل '25
+78
در 2 کانالها
Get PRO
مارس '25
+111
در 2 کانالها
Get PRO
فوریه '25
+53
در 0 کانالها
Get PRO
ژانویه '25
+52
در 1 کانالها
Get PRO
دسامبر '24
+147
در 3 کانالها
Get PRO
نوامبر '24
+93
در 0 کانالها
Get PRO
اکتبر '24
+137
در 2 کانالها
Get PRO
سپتامبر '24
+134
در 2 کانالها
Get PRO
اوت '24
+111
در 2 کانالها
Get PRO
ژوئیه '24
+106
در 2 کانالها
Get PRO
ژوئن '24
+127
در 0 کانالها
Get PRO
مه '24
+77
در 0 کانالها
Get PRO
آوریل '24
+94
در 0 کانالها
Get PRO
مارس '24
+81
در 1 کانالها
Get PRO
فوریه '24
+96
در 0 کانالها
Get PRO
ژانویه '24
+104
در 0 کانالها
Get PRO
دسامبر '23
+84
در 0 کانالها
Get PRO
نوامبر '23
+150
در 0 کانالها
Get PRO
اکتبر '23
+91
در 0 کانالها
Get PRO
سپتامبر '23
+134
در 0 کانالها
Get PRO
اوت '23
+92
در 0 کانالها
Get PRO
ژوئیه '23
+73
در 0 کانالها
Get PRO
ژوئن '23
+100
در 0 کانالها
Get PRO
مه '23
+144
در 0 کانالها
Get PRO
آوریل '23
+36
در 0 کانالها
Get PRO
مارس '23
+43
در 0 کانالها
Get PRO
فوریه '23
+73
در 0 کانالها
Get PRO
ژانویه '23
+67
در 0 کانالها
Get PRO
دسامبر '22
+80
در 0 کانالها
Get PRO
نوامبر '22
+85
در 0 کانالها
Get PRO
اکتبر '22
+66
در 0 کانالها
Get PRO
سپتامبر '22
+77
در 0 کانالها
Get PRO
اوت '22
+109
در 0 کانالها
Get PRO
ژوئیه '22
+67
در 0 کانالها
Get PRO
ژوئن '22
+84
در 0 کانالها
Get PRO
مه '22
+142
در 0 کانالها
Get PRO
آوریل '22
+91
در 0 کانالها
Get PRO
مارس '22
+98
در 0 کانالها
Get PRO
فوریه '22
+68
در 0 کانالها
Get PRO
ژانویه '22
+128
در 0 کانالها
Get PRO
دسامبر '21
+57
در 0 کانالها
Get PRO
نوامبر '21
+149
در 0 کانالها
Get PRO
اکتبر '21
+64
در 0 کانالها
Get PRO
سپتامبر '21
+111
در 0 کانالها
Get PRO
اوت '21
+123
در 0 کانالها
Get PRO
ژوئیه '21
+48
در 0 کانالها
Get PRO
ژوئن '21
+23
در 0 کانالها
Get PRO
مه '21
+29
در 0 کانالها
Get PRO
آوریل '21
+333
در 0 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 25 ژوئیه | +1 | |||
| 24 ژوئیه | +3 | |||
| 23 ژوئیه | +2 | |||
| 22 ژوئیه | +2 | |||
| 21 ژوئیه | +4 | |||
| 20 ژوئیه | +3 | |||
| 19 ژوئیه | +2 | |||
| 18 ژوئیه | +1 | |||
| 17 ژوئیه | +5 | |||
| 16 ژوئیه | +2 | |||
| 15 ژوئیه | +5 | |||
| 14 ژوئیه | +5 | |||
| 13 ژوئیه | +5 | |||
| 12 ژوئیه | +7 | |||
| 11 ژوئیه | +4 | |||
| 10 ژوئیه | +9 | |||
| 09 ژوئیه | +6 | |||
| 08 ژوئیه | +20 | |||
| 07 ژوئیه | +7 | |||
| 06 ژوئیه | +12 | |||
| 05 ژوئیه | +5 | |||
| 04 ژوئیه | +13 | |||
| 03 ژوئیه | +10 | |||
| 02 ژوئیه | +4 | |||
| 01 ژوئیه | +3 |
پستهای کانال
I handed the epoll UAF to an agent
Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android.
| 2 | IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance. | 993 |
| 3 | Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694)
Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache. | 1 251 |
| 4 | Januscape: Guest-to-Host Escape in KVM/x86
Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected.
The article only covers achieving a kernel crash via this bug, but the vulnerability can also be exploited to escape the guest VM. The author used this bug to pwn a kvmCTF instance. | 1 687 |
| 5 | ITScape: Guest-to-Host Escape in KVM/arm64
Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM. | 6 411 |
| 6 | Bad Epoll: The bug missed by Mythos
Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels. | 4 217 |
| 7 | Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215)
Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to set PIPE_BUF_FLAG_CAN_MERGE and perform the Dirty Pipe attack. | 3 061 |
| 8 | Off By !: Exploiting a Use-after-Free in the Linux Kernel
Oliver Sieber published a write-up about CVE-2026-23111 in nftables, which they found in early 2025 and other researchers patched upstream in February 2026. The article describes exploiting this UAF on Debian and Ubuntu. | 2 785 |
| 9 | CIFSwitch: a non-universal Linux local root vulnerability
Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package.
An attacker can forge a "cifs.spnego" key in Linux keyring to make the kernel run a root userspace helper to escalate privileges of the attacker's process. | 2 656 |
| 10 | Unix GC Remastered
Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry. | 2 820 |
| 11 | PinTheft Linux LPE
Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring. | 2 461 |
| 12 | Logic bug in the Linux kernel's __ptrace_may_access() function (CVE-2026-46333)
Article about a logical bug in the ptrace implementation that allows getting access to file descriptors of other processes and thus escalating privileges in certain scenarios. | 2 923 |
| 13 | StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries
Paper by Xiaochen Zou et. al about using LLMs for generating syzkaller descriptions for fuzzing GPU drivers via their userspace libraries APIs. | 2 629 |
| 14 | Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver
Article by Lukas Maar about exploiting a bug in the mmap handler of the QAIC driver that causes a page UAF. | 2 575 |
| 15 | Discovery & Validation in the Linux Kernel
Three-part article by Samuel Page about analyzing two vulnerabilities (in CAN sockets and FUSE) and attempting to use local LLMs to rediscover the bugs. | 2 849 |
| 16 | Recent Page Cache Corruption Bugs
Multitude of vulnerabilities that allow overwriting the page cache and thus changing the in-memory contents of read-only files to gain LPE or escape a container in certain scenarios.
All stem from kernel code paths that perform in-place overwrites of user-supplied input pages without verifying that the pages are writable.
Copy Fail (CVE-2026-31431):
— Announcement;
— Better write-up.
Dirty Frag (CVE-2026-43284 and CVE-2026-43500):
— Covers two independent vulnerabilities that do not require chaining;
— CVE-2026-43284 is alternatively titled Copy Fail 2;
— Original write-up;
— Avoiding bruteforcing for CVE-2026-43500.
Fragnesia (CVE-2026-46300):
— Original report;
— Variant.
DirtyCBC / DirtyDecrypt (CVE-2026-31635?):
— Write-up;
— Another exploit. | 2 903 |
| 17 | بدون متن... | 1 998 |
