11 Aug 2026, 10:12 UTC667 views7 reactionsread 12 August 2026 Photo
IonStack part III: Rooting Android 17 with GhostLock
Article about adapting the exploit of CVE-2026-43499 (racy stack use-after-free in the futex implementation) to Android.
The researchers used KernelSnitch, ashmem fops overwriting, pipe_buffer corruption, and other tricks to perform LPE.
🔥7
Signed Alexander Popov
23 Jul 2026, 21:59 UTC≈1,990 views12 reactionsread 12 August 2026 Photo
I handed the epoll UAF to an agent
Article by Guy Beck about using Claude for porting an exploit for an eventpoll vulnerability to Android.
🔥8👍3🤔1
Signed Andrey Konovalov
21 Jul 2026, 23:12 UTC≈1,990 views17 reactionsread 12 August 2026 Photo
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years
Article about exploiting a racy stack use-after-free in the futex implementation. The bug was used to pwn a kernelCTF instance.
🔥15👍2
Signed Andrey Konovalov
20 Jul 2026, 22:44 UTC≈2,010 views9 reactionsread 12 August 2026 Photo
Unprivileged root via an out-of-bounds write in the FUSE readdir cache (CVE-2026-31694)
Article by Stan Shaw about exploiting a page OOB write bug in the FUSE subsystem by overwriting /etc/passwd in the page cache.
🔥5🤔3👍1
Signed Andrey Konovalov
18 Jul 2026, 06:15 UTC≈2,280 views19 reactionsread 12 August 2026 Photo
Januscape: Guest-to-Host Escape in KVM/x86
Hyunwoo Kim published an article about a use-after-free vulnerability in the shadow MMU emulation of KVM/x86 (CVE-2026-53359). Both Intel (VMX) and AMD (SVM) code is affected.
The article only covers achieving a kernel crash via this bug, but the vulnerability can also be exploited to escape the guest VM. The author used this bug to pwn a kvmCTF instance.
🔥13👍6
Signed Alexander Popov
8 Jul 2026, 12:39 UTC≈7,540 views19 reactionsread 12 August 2026 Photo
ITScape: Guest-to-Host Escape in KVM/arm64
Article by Hyunwoo Kim about exploiting a race condition bug in the KVM driver on the arm64 architecture to escape the guest VM.
🔥17🤔2
Signed Andrey Konovalov
3 Jul 2026, 14:50 UTC≈4,460 views25 reactionsread 12 August 2026 Photo
Bad Epoll: The bug missed by Mythos
Article by Jaeyoung Chung about exploiting CVE-2026-46242 — a race condition bug in the eventpoll subsystem. Jaeyoung exploited this bug to claim a kernelCTF entry, but the vulnerability also affects Android kernels.
🔥25
Signed Andrey Konovalov
27 Jun 2026, 14:55 UTC≈3,250 views10 reactionsread 12 August 2026 Photo
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215)
Stan Shaw published an article about exploiting UAF in a DRM GEM ioctl. The researcher reallocated freed memory as a pipe_buffer array to set PIPE_BUF_FLAG_CAN_MERGE and perform the Dirty Pipe attack.
🔥9👍1
Signed Alexander Popov
25 Jun 2026, 12:48 UTC≈2,940 views9 reactionsread 12 August 2026 Off By !: Exploiting a Use-after-Free in the Linux Kernel
Oliver Sieber published a write-up about CVE-2026-23111 in nftables, which they found in early 2025 and other researchers patched upstream in February 2026. The article describes exploiting this UAF on Debian and Ubuntu.
👍5🔥4
Signed Alexander Popov
22 Jun 2026, 11:37 UTC≈2,830 views11 reactionsread 12 August 2026 CIFSwitch: a non-universal Linux local root vulnerability
Asim Viladi Oglu Manizada posted an article about a nice logic bug in the interaction between the kernel CIFS subsystem and the userspace cifs-utils package.
An attacker can forge a "cifs.spnego" key in Linux keyring to make the kernel run a root userspace helper to escalate privileges of the attacker's process.
🔥9👍1🤔1
Signed Alexander Popov
10 Jun 2026, 18:43 UTC≈3,210 views7 reactionsread 12 August 2026 Photo
Unix GC Remastered
Article by Moe Acherir about the internals of the new Unix sockets garbage collector implementation and the analysis of CVE-2025-40214, which was used in a kernelCTF entry.
👏7
Signed Andrey Konovalov
9 Jun 2026, 17:55 UTC≈2,840 views3 reactionsread 12 August 2026 PinTheft Linux LPE
Aaron Esau published an LPE exploit for a page double-free bug in the RDS zerocopy implementation, which can be turned into a page-cache overwrite through io_uring.
👏2🤔1
Signed Alexander Popov
Showing the 12 most recent of 20 posts we hold for @linkersec. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.