<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>C — PoC Archive</title><link>https://poc.intelseclab.com/tags/c/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/c/index.xml" rel="self" type="application/rss+xml"/><item><title>Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2025-32463. Status: Weaponized. Affects: sudo (-R / --chroot option). Tags: sudo, chroot, privilege-escalation, nsswitch, nss-module, local-privesc, linux, shell, c.</description><category>binary</category><category>Critical</category><category>sudo</category><category>chroot</category><category>privilege-escalation</category><category>nsswitch</category><category>nss-module</category><category>local-privesc</category><category>linux</category><category>shell</category><category>c</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</guid><description>High severity — binary · CVE-2026-49417. Status: PoC. Affects: FreeBSD kernel — OSS audio driver (/dev/dsp) buffer allocation / thread-stack recycling. Tags: freebsd, kernel, oss, dev-dsp, kernel-stack-leak, rop, smep-bypass, cr4, local-privilege-escalation, c.</description><category>binary</category><category>High</category><category>freebsd</category><category>kernel</category><category>oss</category><category>dev-dsp</category><category>kernel-stack-leak</category><category>rop</category><category>smep-bypass</category><category>cr4</category><category>local-privilege-escalation</category><category>c</category></item><item><title>FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49413-freebsd-linuxulator-atsecure-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49413-freebsd-linuxulator-atsecure-lpe/</guid><description>High severity — binary · CVE-2026-49413. Status: PoC. Affects: FreeBSD Linux compatibility layer ("Linuxulator", linux/linux64 kernel module) executing Linux setuid-root binaries under /compat/linux/. Tags: freebsd, linuxulator, at_secure, ld_preload, setuid, local-privilege-escalation, c.</description><category>binary</category><category>High</category><category>freebsd</category><category>linuxulator</category><category>at_secure</category><category>ld_preload</category><category>setuid</category><category>local-privilege-escalation</category><category>c</category></item><item><title>Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46331. Status: PoC. Affects: Linux Kernel — net/sched/act_pedit (traffic control packet editing). Tags: LPE, Linux kernel, COW, page-cache, act_pedit, tc, netlink, traffic-control, privilege-escalation, userns, C, DirtyFrag.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>COW</category><category>page-cache</category><category>act_pedit</category><category>tc</category><category>netlink</category><category>traffic-control</category><category>privilege-escalation</category><category>userns</category><category>C</category><category>DirtyFrag</category></item><item><title>libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-55200. Status: PoC. Affects: libssh2 (SSH client library). Tags: RCE, OOB-write, heap-corruption, libssh2, SSH, integer-overflow, unauthenticated, C, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>OOB-write</category><category>heap-corruption</category><category>libssh2</category><category>SSH</category><category>integer-overflow</category><category>unauthenticated</category><category>C</category><category>network</category></item><item><title>libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-8932-libcurl-mtls-auth-bypass/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-8932-libcurl-mtls-auth-bypass/</guid><description>Low severity — network · CVE-2026-8932. Status: PoC. Affects: libcurl (embedded library; standalone curl CLI unaffected). Tags: authentication-bypass, mTLS, TLS, libcurl, connection-reuse, client-certificate, C, Low.</description><category>network</category><category>Low</category><category>authentication-bypass</category><category>mTLS</category><category>TLS</category><category>libcurl</category><category>connection-reuse</category><category>client-certificate</category><category>C</category><category>Low</category></item><item><title>DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-43503. Status: Weaponized. Affects: Linux kernel (netfilter TEE / __pskb_copy_fclone()). Tags: LPE, Linux kernel, netfilter, TEE, IPsec, XFRM, page-cache, file-backed memory, DirtyFrag, skb, privilege escalation, C, in-the-wild.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>netfilter</category><category>TEE</category><category>IPsec</category><category>XFRM</category><category>page-cache</category><category>file-backed memory</category><category>DirtyFrag</category><category>skb</category><category>privilege escalation</category><category>C</category><category>in-the-wild</category></item></channel></rss>