<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Kernel — PoC Archive</title><link>https://poc.intelseclab.com/tags/kernel/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/kernel/index.xml" rel="self" type="application/rss+xml"/><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-23111. Status: Patched. Affects: Linux kernel (nf_tables subsystem). Tags: linux, kernel, nftables, nf-tables, uaf, catchall, lpe, privilege-escalation, slab-spray, kaslr-bypass, rop, namespace, CVE-2026-23111.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>nftables</category><category>nf-tables</category><category>uaf</category><category>catchall</category><category>lpe</category><category>privilege-escalation</category><category>slab-spray</category><category>kaslr-bypass</category><category>rop</category><category>namespace</category><category>CVE-2026-23111</category></item><item><title>Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-53361. Status: Patched. Affects: Linux Kernel (AF_UNIX socket garbage collector). Tags: linux, kernel, af-unix, garbage-collector, msg-peek, uaf, container-escape, lpe, slub, dirty-pagetable, CVE-2026-53361.</description><category>binary</category><category>Critical</category><category>linux</category><category>kernel</category><category>af-unix</category><category>garbage-collector</category><category>msg-peek</category><category>uaf</category><category>container-escape</category><category>lpe</category><category>slub</category><category>dirty-pagetable</category><category>CVE-2026-53361</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64531. Status: Patched. Affects: Linux kernel, Open vSwitch (OVS) kernel module, conntrack subsystem. Tags: linux, kernel, lpe, openvswitch, ovs, conntrack, netlink, memory-corruption, sudoers, CVE-2026-64531.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>openvswitch</category><category>ovs</category><category>conntrack</category><category>netlink</category><category>memory-corruption</category><category>sudoers</category><category>CVE-2026-64531</category></item><item><title>XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</guid><description>High severity — binary · CVE-2026-20698. Status: PoC. Affects: XNU kernel routing socket subsystem (PF_ROUTE, bsd/net/rtsock.c / bsd/net/radix.c). Tags: xnu, kernel, ios, macos, pf_route, routing-socket, heap-overflow, radix-tree, kernel-panic, bounds-safety.</description><category>binary</category><category>High</category><category>xnu</category><category>kernel</category><category>ios</category><category>macos</category><category>pf_route</category><category>routing-socket</category><category>heap-overflow</category><category>radix-tree</category><category>kernel-panic</category><category>bounds-safety</category></item><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</guid><description>High severity — binary · CVE-2026-40369. Status: PoC. Affects: Windows kernel (ntoskrnl.exe). Tags: windows, kernel, lpe, privilege-escalation, token-stealing, sedebugprivilege, ntoskrnl, local.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>token-stealing</category><category>sedebugprivilege</category><category>ntoskrnl</category><category>local</category></item><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</guid><description>High severity — binary · CVE-2026-3437. Status: PoC. Affects: Portwell Engineering Toolkits driver, portwell.sys (v4.8.2). Tags: byovd, windows-driver, kernel, lpe, physical-memory, ioctl, privilege-escalation.</description><category>binary</category><category>High</category><category>byovd</category><category>windows-driver</category><category>kernel</category><category>lpe</category><category>physical-memory</category><category>ioctl</category><category>privilege-escalation</category></item><item><title>KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</guid><description>High severity — binary · CVE-2026-53360. Status: PoC. Affects: Linux KVM host, SEV-SNP support (arch/x86/kvm/svm/sev.c, snp_begin_psc() / setup_vmgexit_scratch()). Tags: kvm, sev-snp, kernel, heap-oob, kasan, guest-escape, slab, kmalloc-cg, linux-kernel, cwe-125, cwe-787.</description><category>binary</category><category>High</category><category>kvm</category><category>sev-snp</category><category>kernel</category><category>heap-oob</category><category>kasan</category><category>guest-escape</category><category>slab</category><category>kmalloc-cg</category><category>linux-kernel</category><category>cwe-125</category><category>cwe-787</category></item><item><title>FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45250-setcred-freebsd-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45250-setcred-freebsd-lpe/</guid><description>Critical severity — binary · CVE-2026-45250. Status: PoC. Affects: FreeBSD kernel — setcred(2) system call (sys/kern/kern_prot.c). Tags: freebsd, kernel, lpe, privilege-escalation, stack-overflow, setcred, smap-bypass, smep-bypass, zfs, kernel-exploit.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>stack-overflow</category><category>setcred</category><category>smap-bypass</category><category>smep-bypass</category><category>zfs</category><category>kernel-exploit</category></item><item><title>FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</guid><description>High severity — binary · CVE-2026-49417. Status: PoC. Affects: FreeBSD kernel — OSS audio driver (/dev/dsp) buffer allocation / thread-stack recycling. Tags: freebsd, kernel, oss, dev-dsp, kernel-stack-leak, rop, smep-bypass, cr4, local-privilege-escalation, c.</description><category>binary</category><category>High</category><category>freebsd</category><category>kernel</category><category>oss</category><category>dev-dsp</category><category>kernel-stack-leak</category><category>rop</category><category>smep-bypass</category><category>cr4</category><category>local-privilege-escalation</category><category>c</category></item><item><title>FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</guid><description>Critical severity — binary · CVE-2026-7270. Status: Weaponized. Affects: FreeBSD kernel — sys/kern/kern_exec.c exec_args_adjust_args(). Tags: freebsd, kernel, lpe, memmove, oob, race-condition, ld_preload, sshd, cwe-190, cwe-787.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>memmove</category><category>oob</category><category>race-condition</category><category>ld_preload</category><category>sshd</category><category>cwe-190</category><category>cwe-787</category></item><item><title>FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45258-1day-lpe-exploit/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45258-1day-lpe-exploit/</guid><description>Critical severity — binary · CVE-2026-45258. Status: PoC. Affects: FreeBSD kernel (OSS//dev/dsp sound driver mmap handling). Tags: freebsd, kernel, lpe, privilege-escalation, oss, dev-dsp, mmap, setuid, 1day.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>oss</category><category>dev-dsp</category><category>mmap</category><category>setuid</category><category>1day</category></item><item><title>AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</guid><description>High severity — binary · CVE-2026-20637. Status: PoC. Affects: AppleSEPKeyStore driver (com.apple.driver.AppleSEPKeyStore, exposed as IOKit service AppleKeyStore). Tags: ios, macos, kernel, iokit, use-after-free, race-condition, aksepkeystore, xnu, kernel-panic.</description><category>binary</category><category>High</category><category>ios</category><category>macos</category><category>kernel</category><category>iokit</category><category>use-after-free</category><category>race-condition</category><category>aksepkeystore</category><category>xnu</category><category>kernel-panic</category></item><item><title>AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43655-apple-m2-scalercscdriver-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43655-apple-m2-scalercscdriver-uaf/</guid><description>High severity — binary · CVE-2026-43655. Status: PoC. Affects: Apple AppleM2ScalerCSCDriver kext / IOSurfaceAcceleratorClient user-client (iOS, iPadOS, macOS on Apple M2-family scaler hardware). Tags: use-after-free, ios, ipados, macos, kernel, iokit, iosurface, kext, sandbox-escape-adjacent, memory-corruption.</description><category>binary</category><category>High</category><category>use-after-free</category><category>ios</category><category>ipados</category><category>macos</category><category>kernel</category><category>iokit</category><category>iosurface</category><category>kext</category><category>sandbox-escape-adjacent</category><category>memory-corruption</category></item><item><title>AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20687-applejpegdriver-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20687-applejpegdriver-uaf/</guid><description>High severity — binary · CVE-2026-20687. Status: PoC. Affects: AppleJPEGDriver kernel extension. Tags: ios, kernel, applejpegdriver, use-after-free, mte, iokit, kernel-panic, camera.</description><category>binary</category><category>High</category><category>ios</category><category>kernel</category><category>applejpegdriver</category><category>use-after-free</category><category>mte</category><category>iokit</category><category>kernel-panic</category><category>camera</category></item><item><title>HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2021-31166. Status: Weaponized. Affects: Microsoft Windows HTTP Protocol Stack (http.sys). Tags: HTTP.sys, use-after-free, RCE, Windows, kernel, unauthenticated.</description><category>network</category><category>Critical</category><category>HTTP.sys</category><category>use-after-free</category><category>RCE</category><category>Windows</category><category>kernel</category><category>unauthenticated</category></item><item><title>Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46300. Status: Weaponized. Affects: Linux kernel (XFRM ESP-in-TCP subsystem). Tags: LPE, privilege-escalation, kernel, XFRM, ESP-in-TCP, page-cache, write-primitive, unprivileged.</description><category>binary</category><category>High</category><category>LPE</category><category>privilege-escalation</category><category>kernel</category><category>XFRM</category><category>ESP-in-TCP</category><category>page-cache</category><category>write-primitive</category><category>unprivileged</category></item></channel></rss>