TGViewer
Linux Kernel Security Linux Kernel Security @linkersec · 4.72K subscribers
Post #162 2.68K
Looking for Remote Code Execution bugs in the Linux kernel

I wrote an article about fuzzing the Linux kernel network stack externally with syzkaller.

The article covers:

🧰 Introduction to syzkaller
💉 Using TUN/TAP for injecting packets into the kernel
🚚 Patching TUN/TAP for collecting coverage via KCOV
👽 Adding pseudo-syscalls for network fuzzing
🗄 Describing packet structure in syzlang
🏆 Showcases of found bugs

In the article, I put a focus on the presentation: highlighted syzlang code, made interactive snippets, added side notes that are actually on the side. I also implemented a dynamic table of contents (only visible on large screens).

The described work was done a few years ago, but I consider it still relevant. The recent trend of looking for remote Linux kernel exploits is quite exciting! I hope to see even more research in this area.
Andrey Konovalov 🔍 Looking for Remote Code Execution bugs in the Linux kernel Using syzkaller to fuzz the Linux kernel network stack externally
  • 🔥 16
  • 👍 3
More from @linkersec
  1. Sep 28, 2026PageJack in Action: CVE-2022-0995 exploit Article by Jean Vincent describing how a relativ…
  2. Sep 21, 2026CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel Paper by Dong-ok Ki…
  3. Sep 16, 2026Testing race conditions with memory access tracing and stack-based delay injection Article…
  4. Sep 8, 2026SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free Article about exploiting C…
  5. Aug 14, 2026Gone in 60 Frames – USB Video Exploitation Article (and slides) by Alex Plaskett and Rober…
  6. Aug 11, 2026IonStack part III: Rooting Android 17 with GhostLock Article about adapting the exploit of…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →