Linux Kernel Security Profile
Linux Kernel Security

@linkersec

Followers
9K
Following
0
Media
82
Statuses
340

Links related to Linux kernel security and exploitation. Maintained by @andreyknvl and @a13xp0p0v. Also on https://t.co/GVE11dpBb8 and https://t.co/YpxPWXnA6Z.

Joined September 2021
Don't wanna be here? Send us removal request.
@linkersec
Linux Kernel Security
19 days
The researchers leaked the kernel base address using the EntryBleed side-channel attack and then turned the UAF on the vsock_sock structure into a RIP control primitive to execute a ROP-chain.
0
3
6
@linkersec
Linux Kernel Security
19 days
Exploiting the CVE-2025-21756 1-day vulnerability. @v4bel and @_qwerty_po posted a kernelCTF report about exploiting a UAF in the vsock subsystem of the Linux kernel:.
Tweet media one
1
39
168
@linkersec
Linux Kernel Security
20 days
Solo: A Pixel 6 Pro Story (When one bug is all you need). Awesome article by Lin Ze Wei about adapting the Pixel 7/8 exploit for a bug in the Mali GPU driver to Pixel 6 Pro.
Tweet media one
0
25
111
@linkersec
Linux Kernel Security
27 days
Author published an exploit for this bug that disable SELinux and gains root privileges on Pixel 8 running from the untrusted_app context. The exploit is not affected by MTE.
0
2
6
@linkersec
Linux Kernel Security
27 days
Bypassing MTE with CVE-2025-0072. Article by @mmolgtm about exploiting a page use-after-free vulnerability in the ARM's Mali GPU driver in the code that manages userspace-mapped pages.
Tweet media one
1
19
83
@linkersec
Linux Kernel Security
1 month
The researcher had to rerun the prompt multiple times before getting a true-positive result. The o3 model managed to find the 0-day vulnerability in only ~1 out of 50 runs.
0
1
2
@linkersec
Linux Kernel Security
1 month
How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel's SMB implementation. Article by @seanhn about rediscovering a bug in the ksmbd module via the OpenAI's o3 model and then finding a 0-day vulnerability as well.
Tweet media one
3
13
92
@linkersec
Linux Kernel Security
1 month
Based on a previously published article.
0
0
3
@linkersec
Linux Kernel Security
1 month
Android In-The-Wild: Unexpectedly Excavating a Kernel Exploit. Talk by @__sethjenkins about analyzing the traces of an In-The-Wild exploit that targeted the Qualcomm adsprpc driver.
1
35
129
@linkersec
Linux Kernel Security
1 month
KernelGP: Racing Against the Android Kernel. Talk by Chariton Karamitas about ways to use FUSE for kernel exploitation from unprivileged SELinux contexts on Android.
0
32
94
@linkersec
Linux Kernel Security
2 months
Kernel Exploitation Techniques: Turning The (Page) Tables. Article by @sam4k1 giving a great introduction to the page table attacks.
Tweet media one
1
24
92
@linkersec
Linux Kernel Security
2 months
Author exploited a severely-limited OOB side-effect of the bug to corrupt pipe_inode_info->tmp_page and gain a page UAF read/write primitive. Researcher then swapped the private_data and f_cred fields of a signalfd file structure and overwrote the credentials via signalfd_ctx.
0
1
2
@linkersec
Linux Kernel Security
2 months
[CVE-2025-37752] Two Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds. Great article by D3vil about exploiting a type confusion in the network scheduler subsystem and pwning all kernelCTF instances.
Tweet media one
1
53
200
@linkersec
Linux Kernel Security
2 months
A Quick Dive Into The Linux Kernel Page Allocator. Article by D3vil that explains the internals of the Page allocator.
Tweet media one
1
30
131
@linkersec
Linux Kernel Security
2 months
Comes with the reference exploit code.
1
3
11
@linkersec
Linux Kernel Security
2 months
Linux Kernel Exploitation series. Awesome series of articles by @ri5255 that outlines many commonly-used modern exploitation techniques.
Tweet media one
1
159
694
@linkersec
Linux Kernel Security
2 months
RISC-V support in kernel-hardening-checker!👇.
@a13xp0p0v
Alexander Popov
2 months
Big new feature in kernel-hardening-checker: now it supports checking the Linux kernel security parameters for RISC-V ⚡️ (in addition to X86_64, ARM64, X86_32, and ARM). I've spent many weekends on this. Thanks to @_bcoles for the contribution ⭐️.
0
1
7
@linkersec
Linux Kernel Security
2 months
With an advice from @h0mbre_, the researcher used brute force to bypass KASLR and hijacked the control flow for LPE.
Tweet media one
0
1
15
@linkersec
Linux Kernel Security
2 months
CVE-2025-21756: Attack of the Vsock. Michael Hoefler published an article about exploiting an incorrect reference counter decrement causing a UAF in the vsock subsystem.
Tweet media one
1
49
171
@linkersec
Linux Kernel Security
2 months
Guidance on how to use syzkaller to find bugs in USB drivers that can be exploited by a malicious USB device 👇.
@andreyknvl
Andrey Konovalov
2 months
Gave a talk on external fuzzing of Linux kernel USB drivers with syzkaller at SAFACon by @SAFATeamGmbH. Includes a demonstration of how to rediscover CVE-2024-53104, an out-of-bounds bug in the USB Video Class driver. Slides:
Tweet media one
Tweet media two
Tweet media three
0
13
79