<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux-Kernel — PoC Archive</title><link>https://poc.intelseclab.com/tags/linux-kernel/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/linux-kernel/index.xml" rel="self" type="application/rss+xml"/><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499 (aka "GhostLock"). Status: Weaponized (per Nebula Security disclosure); no exploit code mirrored into this repo, see Notes. Affects: Linux kernel — rtmutex priority-inheritance (futex-PI) subsystem, CONFIG_FUTEX_PI. Tags: linux-kernel, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, container-escape, kernelctf, ghostlock.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>container-escape</category><category>kernelctf</category><category>ghostlock</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53075-ppp-userns-probe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53075-ppp-userns-probe/</guid><description>Info severity — binary · CVE-2026-53075. Status: PoC. Affects: Linux kernel, PPP (/dev/ppp) subsystem. Tags: linux-kernel, ppp, user-namespace, unshare, ioctl, privilege-check, cwe-284.</description><category>binary</category><category>Info</category><category>linux-kernel</category><category>ppp</category><category>user-namespace</category><category>unshare</category><category>ioctl</category><category>privilege-check</category><category>cwe-284</category></item><item><title>Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-23416-linux-kernel-mseal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-23416-linux-kernel-mseal/</guid><description>Medium severity — binary · CVE-2026-23416. Status: PoC. Affects: Linux kernel, mm/mseal.c / mm/vma.c (mseal_apply() / vma_merge_existing_range()). Tags: linux-kernel, mseal, mm-subsystem, vma, logic-error, unprivileged, security-feature-bypass, memfd.</description><category>binary</category><category>Medium</category><category>linux-kernel</category><category>mseal</category><category>mm-subsystem</category><category>vma</category><category>logic-error</category><category>unprivileged</category><category>security-feature-bypass</category><category>memfd</category></item><item><title>Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31429-linux-kfence-skb-crosscache/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31429-linux-kfence-skb-crosscache/</guid><description>Medium severity — binary · CVE-2026-31429. Status: PoC. Affects: Linux kernel — net/core/skbuff.c (skb_kfree_head()) via bpf_prog_test_run_skb. Tags: linux-kernel, kfence, cross-cache, slab-corruption, ebpf, skb, cwe-763, use-after-free-adjacent.</description><category>binary</category><category>Medium</category><category>linux-kernel</category><category>kfence</category><category>cross-cache</category><category>slab-corruption</category><category>ebpf</category><category>skb</category><category>cwe-763</category><category>use-after-free-adjacent</category></item><item><title>Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23398-icmp-frag-needed/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23398-icmp-frag-needed/</guid><description>High severity — network · CVE-2026-23398. Status: PoC. Affects: Linux kernel, icmp_tag_validation() / icmp_unreach() in net/ipv4/icmp.c. Tags: linux-kernel, icmp, denial-of-service, null-pointer-dereference, kernel-panic, pmtu, scapy, remote-dos.</description><category>network</category><category>High</category><category>linux-kernel</category><category>icmp</category><category>denial-of-service</category><category>null-pointer-dereference</category><category>kernel-panic</category><category>pmtu</category><category>scapy</category><category>remote-dos</category></item><item><title>Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499. Status: PoC. Affects: Linux kernel — kernel/locking/rtmutex.c, futex-PI subsystem (futex_requeue() / rt_mutex_start_proxy_lock()). Tags: linux-kernel, android, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, kernel-panic, ndk.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>android</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>kernel-panic</category><category>ndk</category></item><item><title>Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</guid><description>High severity — binary · CVE-2026-31694. Status: Weaponized. Affects: Linux kernel — fs/fuse/readdir.c (fuse_add_dirent_to_cache()). Tags: linux-kernel, fuse, oob-write, page-cache, lpe, groom, unprivileged, qemu-kvm.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>fuse</category><category>oob-write</category><category>page-cache</category><category>lpe</category><category>groom</category><category>unprivileged</category><category>qemu-kvm</category></item><item><title>Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31413-bpf-verifier-container-escape/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31413-bpf-verifier-container-escape/</guid><description>Critical severity — binary · CVE-2026-31413. Status: Weaponized. Affects: Linux kernel — BPF verifier (maybe_fork_scalars()). Tags: linux-kernel, ebpf, bpf-verifier, container-escape, modprobe-path, gke, lpe, vtable-hijack.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>ebpf</category><category>bpf-verifier</category><category>container-escape</category><category>modprobe-path</category><category>gke</category><category>lpe</category><category>vtable-hijack</category></item><item><title>KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</guid><description>High severity — binary · CVE-2026-53360. Status: PoC. Affects: Linux KVM host, SEV-SNP support (arch/x86/kvm/svm/sev.c, snp_begin_psc() / setup_vmgexit_scratch()). Tags: kvm, sev-snp, kernel, heap-oob, kasan, guest-escape, slab, kmalloc-cg, linux-kernel, cwe-125, cwe-787.</description><category>binary</category><category>High</category><category>kvm</category><category>sev-snp</category><category>kernel</category><category>heap-oob</category><category>kasan</category><category>guest-escape</category><category>slab</category><category>kmalloc-cg</category><category>linux-kernel</category><category>cwe-125</category><category>cwe-787</category></item><item><title>DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</guid><description>High severity — binary · CVE-2026-31635. Status: Weaponized. Affects: Linux kernel — net/rxrpc/rxgk_common.h (rxgk_decrypt_skb()). Tags: linux-kernel, lpe, rxrpc, rxgk, page-cache, dirty-pipe-variant, splice, golang, unprivileged.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>rxrpc</category><category>rxgk</category><category>page-cache</category><category>dirty-pipe-variant</category><category>splice</category><category>golang</category><category>unprivileged</category></item><item><title>Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46331. Status: PoC. Affects: Linux Kernel — net/sched/act_pedit (traffic control packet editing). Tags: LPE, Linux kernel, COW, page-cache, act_pedit, tc, netlink, traffic-control, privilege-escalation, userns, C, DirtyFrag.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>COW</category><category>page-cache</category><category>act_pedit</category><category>tc</category><category>netlink</category><category>traffic-control</category><category>privilege-escalation</category><category>userns</category><category>C</category><category>DirtyFrag</category></item><item><title>DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-43503. Status: Weaponized. Affects: Linux kernel (netfilter TEE / __pskb_copy_fclone()). Tags: LPE, Linux kernel, netfilter, TEE, IPsec, XFRM, page-cache, file-backed memory, DirtyFrag, skb, privilege escalation, C, in-the-wild.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>netfilter</category><category>TEE</category><category>IPsec</category><category>XFRM</category><category>page-cache</category><category>file-backed memory</category><category>DirtyFrag</category><category>skb</category><category>privilege escalation</category><category>C</category><category>in-the-wild</category></item><item><title>ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-05_ssh-keysign-pwn/</link><pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-05_ssh-keysign-pwn/</guid><description>High severity — binary · CVE-2026-46333. Status: Patched. Affects: Linux kernel plus privileged userland binaries (ssh-keysign, chage). Tags: LPE, Linux kernel, pidfd_getfd, ptrace, ssh-keysign, chage, fd-theft.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>pidfd_getfd</category><category>ptrace</category><category>ssh-keysign</category><category>chage</category><category>fd-theft</category></item><item><title>PinTheft: RDS Double-Free → LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</guid><description>High severity — binary. Status: Weaponized. Affects: Linux kernel (RDS subsystem + io_uring). Tags: LPE, double-free, use-after-free, Linux kernel, RDS, io_uring, page-cache-overwrite, x86_64, local.</description><category>binary</category><category>High</category><category>LPE</category><category>double-free</category><category>use-after-free</category><category>Linux kernel</category><category>RDS</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>local</category></item><item><title>DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</guid><description>High severity — binary · N/A (reported as duplicate by kernel maintainers; patched on mainline). Status: Weaponized. Affects: Linux kernel — net/rxrpc (rxgk_decrypt_skb). Tags: LPE, Linux kernel, page-cache, rxgk, RxRPC, COW, write-primitive, unprivileged, Dirty-Pipe-variant, splice, MSG_SPLICE_PAGES.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>rxgk</category><category>RxRPC</category><category>COW</category><category>write-primitive</category><category>unprivileged</category><category>Dirty-Pipe-variant</category><category>splice</category><category>MSG_SPLICE_PAGES</category></item><item><title>Linux vsock Use-After-Free VM Escape (CVE-2025-21756)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-vsock-vm-escape/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-vsock-vm-escape/</guid><description>High severity (CVSS 7.8) — binary · CVE-2025-21756. Status: Weaponized. Affects: Linux kernel (vsock / virtual socket subsystem). Tags: UAF, Linux kernel, vsock, VM escape, container escape, virtualization, LPE, x64.</description><category>binary</category><category>High</category><category>UAF</category><category>Linux kernel</category><category>vsock</category><category>VM escape</category><category>container escape</category><category>virtualization</category><category>LPE</category><category>x64</category></item><item><title>Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-1086. Status: Weaponized. Affects: Linux kernel (netfilter nf_tables subsystem). Tags: LPE, UAF, Linux kernel, nf_tables, netfilter, CISA KEV, ransomware, x64.</description><category>binary</category><category>High</category><category>LPE</category><category>UAF</category><category>Linux kernel</category><category>nf_tables</category><category>netfilter</category><category>CISA KEV</category><category>ransomware</category><category>x64</category></item><item><title>Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</guid><description>High severity — binary · CVE-2026-31431. Status: Weaponized. Affects: Linux kernel (crypto / AF_ALG AEAD path). Tags: LPE, Linux kernel, AF_ALG, authenc, splice, local, Python.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>AF_ALG</category><category>authenc</category><category>splice</category><category>local</category><category>Python</category></item><item><title>Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</guid><description>Critical severity (CVSS 7.8) — binary · CVE-2026-43500, CVE-2026-43284. Status: Weaponized. Affects: Linux kernel. Tags: LPE, Linux kernel, page-cache, xfrm, RxRPC, local, unauthenticated, Dirty Pipe variant.</description><category>binary</category><category>Critical</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>xfrm</category><category>RxRPC</category><category>local</category><category>unauthenticated</category><category>Dirty Pipe variant</category></item></channel></rss>