Exploit Development255 KERAT: Static Detection of Kernel TOCTOU Bugs Caused by Races
USENIX Security 2026: KERAT mines atomicity rules for check-use pairs on Linux and FreeBSD shared fields, then FSM-walks LLVM IR. 351 real…
Exploit Development255 USENIX Security 2026: KERAT mines atomicity rules for check-use pairs on Linux and FreeBSD shared fields, then FSM-walks LLVM IR. 351 real…
Linux241 How Singularity rootkit bypasses Elastic Defend 9.5's enhanced module load detection through source obfuscation, BPF hook manipulation, and exploitation of trusted process…
Exploit Development342 CVE-2026-53360 is a heap out-of-bounds read/write in KVM SEV-SNP Page State Change handler: the guest picks the scratch buffer size, the host…
Exploit Development399 Two nginx rewrite-engine bugs share one root cause: an is_args flag computed in one pass and consumed in another. Pointed at r->args…
Exploit Development720 GhostLock (CVE-2026-43499) is a 15-year-old use-after-free in the Linux kernel's rtmutex/futex requeue-PI code. When a proxy lock hits a deadlock and rolls…
Linux332 A kernel rootkit using ftrace hooks can selectively blind Falco, Tracee, GhostScan, and Decloaker simultaneously by intercepting the BPF iterator, ringbuffer, perf…
Linux287 CVE-2026-46215 is a use-after-free race in the Linux DRM GEM change_handle ioctl (v6.8–v6.14-rc2) that allows unprivileged LPE to root via pipe_buffer slab…
Linux328 Pack2TheRoot (CVE-2026-41651) is a high-severity local privilege escalation flaw in PackageKit that lets any unprivileged user win a race condition during InstallFiles…
Exploit Development309 DirtyClone (CVE-2026-43503) is a high-severity Linux LPE in the DirtyFrag family. A dropped SKBFL_SHARED_FRAG flag during __pskb_copy_fclone() skb cloning lets in-place IPsec…
Containers269 A deep technical walkthrough of ipv6_frag_escape, a public proof-of-concept exploit that converts a Linux kernel IPv6 fragmentation linear overflow into a reliable…
Linux297 Scales is a Linux supply-chain malware that pairs an embedded eBPF rootkit with a built-in Tor client and aggressive credential theft. This…
kernel225 Walk-through of Lukas Maar’s page-level use-after-free in the Linux kernel’s QAIC (Qualcomm AI Accelerator) DRM driver: the missing VMA boundary check in…