TGViewer
Channel Public Channel
Linux Kernel Security

Linux Kernel Security

@linkersec

Links related to Linux kernel security and exploitation | Chat @linkersec_chat | @xairy @a13xp0p0v | Mirrors on https://xairy.io/linkersec
Subscribers
4.71K
Photos
122
Videos
0
Links
355

Showing posts older than #358 · Back to latest

Older Posts 20 shown
Post #357 6.54K
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit

MatheuZSec published a detailed article about Singularity — a loadable kernel module rootkit developed for 6.x Linux kernels. The rootkit uses ftrace for hooking syscalls and hiding itself.
blog.kyntra.io Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
  • 🔥 13
  • 👍 1
Post #356 3.99K
Extending Kernel Race Windows Using '/dev/shm'

Article by Faith about extending race condition windows via FALLOC_FL_PUNCH_HOLE. The technique allows delaying user memory accesses from the kernel mode, similar to userfaultfd and FUSE.
  • 🔥 12
Post #351 5.55K
LinkPro: eBPF rootkit analysis

Théo Letailleur published an article with a detailed description of an eBPF rootkit that hides itself on the compromised system and activates its features upon receiving a "magic packet".
Synacktiv LinkPro: eBPF rootkit analysis
  • 🔥 14
  • 👍 5
  • 👏 3
  • 🤔 1
Post #350 4.22K
Slice: SAST + LLM Interprocedural Context Extractor

Amazing article by Caleb Gross about combining the use of CodeQL and LLMs to reliably rediscover CVE-2025-37899 — a remotely-triggerable vulnerability in the ksmbd module.
  • 🔥 4
Post #349 4.55K
Enhancing FineIBT

LWN article that describes the talk by Scott Constable and Sebastian Österlund about the ongoing work to improve FineIBT (Fine-grain Control-flow Enforcement with Indirect Branch Tracking).

The article also refers to another post "A hole in FineIBT protection" about a method to bypass this CFI mechanism.
Post #348 4.1K
Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE

Talk (slides) by Pan Zhenpeng and Jheng Bing Jhong about exploiting a logical bug in the Pixel GXP driver that allows overwriting read-only files.
  • 🤔 4
  • 🔥 3
Post #347 3.88K
Exploiting CVE-2025-21479 on a Samsung S23

Article by XploitBengineer about exploiting a logical bug in the Qualcomm Adreno GPU firmware to take over the kernel on Samsung S23 via a combination of page table attacks.
  • 👏 11
  • 👎 5
  • 😱 4
  • 🤔 2
Post #346 3.65K
LPE via refcount imbalance in the af_unix of Ubuntu

Article and exploit by kylebot for a refcount imbalance bug in the Ubuntu kernel's Unix sockets implementation disclosed during the TyphoonPWN 2025 competition.
  • 👍 8
Post #345 3.81K
kernelCTF: CVE-2025-38477

kernelCTF entry for a race condition in the network scheduler subsystem.

Most notably, shows a technique of putting controlled data into unmapped sections of vmlinux.
  • 👍 13
Post #344 3.93K
Defeating KASLR by Doing Nothing at All

Article by Seth Jenkins about a few problems with physical memory KASLR on arm64 devices.
  • 🔥 11
  • 🤯 3
  • 👍 2
  • 🤔 2
Post #343 4.87K
Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers

Article by Robin Bastide about exploiting a NULL-pointer-dereference that led to a UAF access to the kernel stack in the NVIDIA GPU driver.

The article shows an interesting scenario of how a NULL-pointer-dereference can lead to a more severe memory corruption. It also demonstrates a few techniques of shaping vmalloc memory for exploitation.
  • 👍 5
  • 🤯 4
  • 🔥 1
Post #341 4.56K
Dirty Pageflags: Revisiting PTE Exploitation in Linux

Article by ptr-yudai on the exploitation technique of overwriting the R/W flag in a PTE entry to allow writing into read-only files.
  • 🔥 13
  • 👍 2
  • 👏 1
Post #340 3.98K
Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days

William Liu posted an article about exploiting a slab object overflow (CVE-2023-52440) and remote infoleak (CVE-2023-4130) in the kernel SMB3 daemon to gain RCE.
  • 🔥 10
  • 🤔 3
  • 👎 2
  • 👍 1
Post #339 3.02K
The anatomy of a bug: 6 Months at STAR Labs

Gerrard Tai posted an article describing their experience in finding kernel bugs and participating in the KernelCTF and Pwn2Own competitions.
  • 🔥 9
Post #338 3.41K
A Syzkaller Summer: Fixing False Positive Soft Lockups in net/sched Fuzzing

Article by Will's Root about fixing the soft lockup bug found when fuzzing the network scheduler subsystem with syzkaller.

The article also gives a summary about the exploitable bugs the author managed to find in the same subsystem.
  • 🔥 9
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →