<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-416 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-416/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-416/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</guid><description>Critical severity (CVSS 9.9) — binary · CVE-2025-49844. Status: Weaponized. Affects: Redis (embedded Lua scripting engine). Tags: redis, lua, use-after-free, uaf, memory-corruption, jop, jump-oriented-programming, shellcode, iced-x86, docker, cwe-416, rce.</description><category>binary</category><category>Critical</category><category>redis</category><category>lua</category><category>use-after-free</category><category>uaf</category><category>memory-corruption</category><category>jop</category><category>jump-oriented-programming</category><category>shellcode</category><category>iced-x86</category><category>docker</category><category>cwe-416</category><category>rce</category></item><item><title>curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-3805-curl-smb-use-after-free/</guid><description>High severity — network · CVE-2026-3805. Status: PoC. Affects: curl / libcurl. Tags: curl, libcurl, use-after-free, smb, cwe-416, memory-corruption, asan.</description><category>network</category><category>High</category><category>curl</category><category>libcurl</category><category>use-after-free</category><category>smb</category><category>cwe-416</category><category>memory-corruption</category><category>asan</category></item></channel></rss>