<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Double-Free — PoC Archive</title><link>https://poc.intelseclab.com/tags/double-free/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/double-free/index.xml" rel="self" type="application/rss+xml"/><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</guid><description>Critical severity — network · CVE-2026-33824. Status: Weaponized. Affects: Windows IKEv2 IPsec driver (ikeext.dll). Tags: ikev2, windows-kernel, double-free, ikeext, rop-chain, heap-grooming, reverse-shell, anti-debug, packet-fragmentation.</description><category>network</category><category>Critical</category><category>ikev2</category><category>windows-kernel</category><category>double-free</category><category>ikeext</category><category>rop-chain</category><category>heap-grooming</category><category>reverse-shell</category><category>anti-debug</category><category>packet-fragmentation</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>PinTheft: RDS Double-Free → LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</guid><description>High severity — binary. Status: Weaponized. Affects: Linux kernel (RDS subsystem + io_uring). Tags: LPE, double-free, use-after-free, Linux kernel, RDS, io_uring, page-cache-overwrite, x86_64, local.</description><category>binary</category><category>High</category><category>LPE</category><category>double-free</category><category>use-after-free</category><category>Linux kernel</category><category>RDS</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>local</category></item><item><title>Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</guid><description>High severity (CVSS 7) — binary · CVE-2025-62215. Status: Weaponized. Affects: Windows Kernel (ntoskrnl.exe / kernel resource synchronization). Tags: EoP, Windows kernel, race condition, double-free, heap corruption, 0day, SYSTEM, Windows 10, Windows 11.</description><category>binary</category><category>High</category><category>EoP</category><category>Windows kernel</category><category>race condition</category><category>double-free</category><category>heap corruption</category><category>0day</category><category>SYSTEM</category><category>Windows 10</category><category>Windows 11</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>