<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux — PoC Archive</title><link>https://poc.intelseclab.com/tags/linux/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/linux/index.xml" rel="self" type="application/rss+xml"/><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-23111. Status: Patched. Affects: Linux kernel (nf_tables subsystem). Tags: linux, kernel, nftables, nf-tables, uaf, catchall, lpe, privilege-escalation, slab-spray, kaslr-bypass, rop, namespace, CVE-2026-23111.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>nftables</category><category>nf-tables</category><category>uaf</category><category>catchall</category><category>lpe</category><category>privilege-escalation</category><category>slab-spray</category><category>kaslr-bypass</category><category>rop</category><category>namespace</category><category>CVE-2026-23111</category></item><item><title>Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-53361. Status: Patched. Affects: Linux Kernel (AF_UNIX socket garbage collector). Tags: linux, kernel, af-unix, garbage-collector, msg-peek, uaf, container-escape, lpe, slub, dirty-pagetable, CVE-2026-53361.</description><category>binary</category><category>Critical</category><category>linux</category><category>kernel</category><category>af-unix</category><category>garbage-collector</category><category>msg-peek</category><category>uaf</category><category>container-escape</category><category>lpe</category><category>slub</category><category>dirty-pagetable</category><category>CVE-2026-53361</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64531. Status: Patched. Affects: Linux kernel, Open vSwitch (OVS) kernel module, conntrack subsystem. Tags: linux, kernel, lpe, openvswitch, ovs, conntrack, netlink, memory-corruption, sudoers, CVE-2026-64531.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>openvswitch</category><category>ovs</category><category>conntrack</category><category>netlink</category><category>memory-corruption</category><category>sudoers</category><category>CVE-2026-64531</category></item><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2025-32463. Status: Weaponized. Affects: sudo (-R / --chroot option). Tags: sudo, chroot, privilege-escalation, nsswitch, nss-module, local-privesc, linux, shell, c.</description><category>binary</category><category>Critical</category><category>sudo</category><category>chroot</category><category>privilege-escalation</category><category>nsswitch</category><category>nss-module</category><category>local-privesc</category><category>linux</category><category>shell</category><category>c</category></item><item><title>snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</guid><description>High severity — binary · CVE-2026-3888. Status: Weaponized. Affects: snapd (snap-confine writable-mimic / systemd-tmpfiles handling). Tags: snapd, snap-confine, linux, local-privilege-escalation, race-condition, systemd-tmpfiles, mount-namespace.</description><category>binary</category><category>High</category><category>snapd</category><category>snap-confine</category><category>linux</category><category>local-privilege-escalation</category><category>race-condition</category><category>systemd-tmpfiles</category><category>mount-namespace</category></item><item><title>Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-14459 (also covers CVE-2026-14460). Status: Weaponized. Affects: pardus-software (Pardus Software Center). Tags: linux, pardus, privilege-escalation, polkit, pkexec, apt-injection, argument-injection, local-dos.</description><category>binary</category><category>High</category><category>linux</category><category>pardus</category><category>privilege-escalation</category><category>polkit</category><category>pkexec</category><category>apt-injection</category><category>argument-injection</category><category>local-dos</category></item><item><title>PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</guid><description>High severity — binary · CVE-2026-41651. Status: PoC. Affects: PackageKit daemon (packagekitd). Tags: linux, packagekit, toctou, race-condition, lpe, polkit, privilege-escalation, dbus.</description><category>binary</category><category>High</category><category>linux</category><category>packagekit</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>polkit</category><category>privilege-escalation</category><category>dbus</category></item><item><title>Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-24018-forticlient-symlink-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-24018-forticlient-symlink-lpe/</guid><description>High severity — binary · CVE-2026-24018. Status: Weaponized. Affects: Fortinet FortiClientLinux. Tags: forticlient, linux, symlink-following, local-privilege-escalation, setuid, shared-object-injection, vpn-config, cwe-61.</description><category>binary</category><category>High</category><category>forticlient</category><category>linux</category><category>symlink-following</category><category>local-privilege-escalation</category><category>setuid</category><category>shared-object-injection</category><category>vpn-config</category><category>cwe-61</category></item><item><title>BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_blueducky-cve-2023-45866/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_blueducky-cve-2023-45866/</guid><description>High severity (CVSS 8.8) — network · CVE-2023-45866. Status: Weaponized. Affects: Bluetooth HID host implementations vulnerable to CVE-2023-45866. Tags: Bluetooth, HID, keystroke-injection, unauthenticated, Android, Linux.</description><category>network</category><category>High</category><category>Bluetooth</category><category>HID</category><category>keystroke-injection</category><category>unauthenticated</category><category>Android</category><category>Linux</category></item></channel></rss>