<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Page-Cache — PoC Archive</title><link>https://poc.intelseclab.com/tags/page-cache/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/page-cache/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</guid><description>High severity — binary · CVE-2026-31694. Status: Weaponized. Affects: Linux kernel — fs/fuse/readdir.c (fuse_add_dirent_to_cache()). Tags: linux-kernel, fuse, oob-write, page-cache, lpe, groom, unprivileged, qemu-kvm.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>fuse</category><category>oob-write</category><category>page-cache</category><category>lpe</category><category>groom</category><category>unprivileged</category><category>qemu-kvm</category></item><item><title>DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</guid><description>High severity — binary · CVE-2026-31635. Status: Weaponized. Affects: Linux kernel — net/rxrpc/rxgk_common.h (rxgk_decrypt_skb()). Tags: linux-kernel, lpe, rxrpc, rxgk, page-cache, dirty-pipe-variant, splice, golang, unprivileged.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>rxrpc</category><category>rxgk</category><category>page-cache</category><category>dirty-pipe-variant</category><category>splice</category><category>golang</category><category>unprivileged</category></item><item><title>Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46331. Status: PoC. Affects: Linux Kernel — net/sched/act_pedit (traffic control packet editing). Tags: LPE, Linux kernel, COW, page-cache, act_pedit, tc, netlink, traffic-control, privilege-escalation, userns, C, DirtyFrag.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>COW</category><category>page-cache</category><category>act_pedit</category><category>tc</category><category>netlink</category><category>traffic-control</category><category>privilege-escalation</category><category>userns</category><category>C</category><category>DirtyFrag</category></item><item><title>DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-43503. Status: Weaponized. Affects: Linux kernel (netfilter TEE / __pskb_copy_fclone()). Tags: LPE, Linux kernel, netfilter, TEE, IPsec, XFRM, page-cache, file-backed memory, DirtyFrag, skb, privilege escalation, C, in-the-wild.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>netfilter</category><category>TEE</category><category>IPsec</category><category>XFRM</category><category>page-cache</category><category>file-backed memory</category><category>DirtyFrag</category><category>skb</category><category>privilege escalation</category><category>C</category><category>in-the-wild</category></item><item><title>DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</guid><description>High severity — binary · N/A (reported as duplicate by kernel maintainers; patched on mainline). Status: Weaponized. Affects: Linux kernel — net/rxrpc (rxgk_decrypt_skb). Tags: LPE, Linux kernel, page-cache, rxgk, RxRPC, COW, write-primitive, unprivileged, Dirty-Pipe-variant, splice, MSG_SPLICE_PAGES.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>rxgk</category><category>RxRPC</category><category>COW</category><category>write-primitive</category><category>unprivileged</category><category>Dirty-Pipe-variant</category><category>splice</category><category>MSG_SPLICE_PAGES</category></item><item><title>Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46300. Status: Weaponized. Affects: Linux kernel (XFRM ESP-in-TCP subsystem). Tags: LPE, privilege-escalation, kernel, XFRM, ESP-in-TCP, page-cache, write-primitive, unprivileged.</description><category>binary</category><category>High</category><category>LPE</category><category>privilege-escalation</category><category>kernel</category><category>XFRM</category><category>ESP-in-TCP</category><category>page-cache</category><category>write-primitive</category><category>unprivileged</category></item><item><title>Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</guid><description>Critical severity (CVSS 7.8) — binary · CVE-2026-43500, CVE-2026-43284. Status: Weaponized. Affects: Linux kernel. Tags: LPE, Linux kernel, page-cache, xfrm, RxRPC, local, unauthenticated, Dirty Pipe variant.</description><category>binary</category><category>Critical</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>xfrm</category><category>RxRPC</category><category>local</category><category>unauthenticated</category><category>Dirty Pipe variant</category></item></channel></rss>