<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Race-Condition — PoC Archive</title><link>https://poc.intelseclab.com/tags/race-condition/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/race-condition/index.xml" rel="self" type="application/rss+xml"/><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-12_openssh-agent-lock-provider-bypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-12_openssh-agent-lock-provider-bypass/</guid><description>High severity — network. Status: PoC — reproducible against a signed, checksum/signature-verified stock OpenSSH 10.4p1 build; no weaponized payload beyond starting an allowed PKCS#11 provider. Affects: OpenSSH portable — ssh, sshd, ssh-agent. Tags: openssh, ssh-agent, agent-forwarding, pkcs11, race-condition, state-confusion, no-cve, local-provider-abuse.</description><category>network</category><category>High</category><category>openssh</category><category>ssh-agent</category><category>agent-forwarding</category><category>pkcs11</category><category>race-condition</category><category>state-confusion</category><category>no-cve</category><category>local-provider-abuse</category></item><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</guid><description>Critical severity — network · CVE-2026-11834. Status: Weaponized. Affects: TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6. Tags: tp-link, router, dhcp, command-injection, cwe-78, race-condition, rce, iot.</description><category>network</category><category>Critical</category><category>tp-link</category><category>router</category><category>dhcp</category><category>command-injection</category><category>cwe-78</category><category>race-condition</category><category>rce</category><category>iot</category></item><item><title>snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</guid><description>High severity — binary · CVE-2026-3888. Status: Weaponized. Affects: snapd (snap-confine writable-mimic / systemd-tmpfiles handling). Tags: snapd, snap-confine, linux, local-privilege-escalation, race-condition, systemd-tmpfiles, mount-namespace.</description><category>binary</category><category>High</category><category>snapd</category><category>snap-confine</category><category>linux</category><category>local-privilege-escalation</category><category>race-condition</category><category>systemd-tmpfiles</category><category>mount-namespace</category></item><item><title>PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</guid><description>High severity — binary · CVE-2026-41651. Status: PoC. Affects: PackageKit daemon (packagekitd). Tags: linux, packagekit, toctou, race-condition, lpe, polkit, privilege-escalation, dbus.</description><category>binary</category><category>High</category><category>linux</category><category>packagekit</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>polkit</category><category>privilege-escalation</category><category>dbus</category></item><item><title>npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</guid><description>Medium severity — misc · CVE-2026-2395. Status: PoC. Affects: tar npm package. Tags: tar, nodejs, npm, race-condition, unicode-normalization, file-collision, archive-extraction, data-corruption.</description><category>misc</category><category>Medium</category><category>tar</category><category>nodejs</category><category>npm</category><category>race-condition</category><category>unicode-normalization</category><category>file-collision</category><category>archive-extraction</category><category>data-corruption</category></item><item><title>FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</guid><description>Critical severity — binary · CVE-2026-7270. Status: Weaponized. Affects: FreeBSD kernel — sys/kern/kern_exec.c exec_args_adjust_args(). Tags: freebsd, kernel, lpe, memmove, oob, race-condition, ld_preload, sshd, cwe-190, cwe-787.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>memmove</category><category>oob</category><category>race-condition</category><category>ld_preload</category><category>sshd</category><category>cwe-190</category><category>cwe-787</category></item><item><title>Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</guid><description>Critical severity — web · CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11). Status: PoC. Affects: Discuz! X5.0 (PHP-based forum/CMS software). Tags: discuz, php, forum, race-condition, captcha-bypass, ocr, account-takeover, lfi, webshell, rce, pre-auth.</description><category>web</category><category>Critical</category><category>discuz</category><category>php</category><category>forum</category><category>race-condition</category><category>captcha-bypass</category><category>ocr</category><category>account-takeover</category><category>lfi</category><category>webshell</category><category>rce</category><category>pre-auth</category></item><item><title>Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</guid><description>High severity — binary · CVE-2026-30332. Status: Weaponized. Affects: Balena Etcher for Windows. Tags: toctou, windows, uac, privilege-escalation, balena-etcher, race-condition, temp-file.</description><category>binary</category><category>High</category><category>toctou</category><category>windows</category><category>uac</category><category>privilege-escalation</category><category>balena-etcher</category><category>race-condition</category><category>temp-file</category></item><item><title>ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</guid><description>Medium severity — binary · CVE-2026-1880. Status: PoC. Affects: ASUS DriverHub (driver update utility). Tags: windows, toctou, race-condition, lpe, driverhub, asus, local-privilege-escalation, shellexecute.</description><category>binary</category><category>Medium</category><category>windows</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>driverhub</category><category>asus</category><category>local-privilege-escalation</category><category>shellexecute</category></item><item><title>AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20637-applesepkeystore-uaf/</guid><description>High severity — binary · CVE-2026-20637. Status: PoC. Affects: AppleSEPKeyStore driver (com.apple.driver.AppleSEPKeyStore, exposed as IOKit service AppleKeyStore). Tags: ios, macos, kernel, iokit, use-after-free, race-condition, aksepkeystore, xnu, kernel-panic.</description><category>binary</category><category>High</category><category>ios</category><category>macos</category><category>kernel</category><category>iokit</category><category>use-after-free</category><category>race-condition</category><category>aksepkeystore</category><category>xnu</category><category>kernel-panic</category></item><item><title>RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Weaponized. Affects: Microsoft Windows Defender / Windows Error Reporting Task Scheduler. Tags: LPE, Windows Defender, race-condition, TOCTOU, ISO-mount, VirtualDisk, Task-Scheduler, WER, EICAR, SYSTEM-shell, Windows-10, Windows-11, local.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>race-condition</category><category>TOCTOU</category><category>ISO-mount</category><category>VirtualDisk</category><category>Task-Scheduler</category><category>WER</category><category>EICAR</category><category>SYSTEM-shell</category><category>Windows-10</category><category>Windows-11</category><category>local</category></item><item><title>FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition</title><link>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</guid><description>Critical severity (CVSS 9.3) — web. Status: Unpatched. Affects: Firefox Focus for iOS. Tags: UXSS, XSS, race-condition, TOCTOU, redirect-validation, javascript-scheme, iOS, Firefox Focus.</description><category>web</category><category>Critical</category><category>UXSS</category><category>XSS</category><category>race-condition</category><category>TOCTOU</category><category>redirect-validation</category><category>javascript-scheme</category><category>iOS</category><category>Firefox Focus</category></item><item><title>Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</guid><description>High severity (CVSS 7) — binary · CVE-2025-62215. Status: Weaponized. Affects: Windows Kernel (ntoskrnl.exe / kernel resource synchronization). Tags: EoP, Windows kernel, race condition, double-free, heap corruption, 0day, SYSTEM, Windows 10, Windows 11.</description><category>binary</category><category>High</category><category>EoP</category><category>Windows kernel</category><category>race condition</category><category>double-free</category><category>heap corruption</category><category>0day</category><category>SYSTEM</category><category>Windows 10</category><category>Windows 11</category></item><item><title>OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-16_openssh-regresshion-signal-handler-race/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-16_openssh-regresshion-signal-handler-race/</guid><description>High severity (CVSS 8.1) — network · CVE-2024-6387. Status: Weaponized. Affects: OpenSSH server daemon (sshd) on glibc-based Linux. Tags: RCE, OpenSSH, sshd, glibc, race-condition, SIGALRM, unauthenticated.</description><category>network</category><category>High</category><category>RCE</category><category>OpenSSH</category><category>sshd</category><category>glibc</category><category>race-condition</category><category>SIGALRM</category><category>unauthenticated</category></item><item><title>Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2024-55591 (Fortinet FG-IR-24-535). Status: Weaponized — public PoC exploit code available, listed in CISA KEV (added 2025-01-14), confirmed used in ransomware intrusions. Affects: Fortinet FortiOS/FortiProxy management interfaces. Tags: auth-bypass, websocket, race-condition, FortiOS, FortiProxy, unauthenticated, super-admin, kev, known-ransomware-use, cwe-288.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>websocket</category><category>race-condition</category><category>FortiOS</category><category>FortiProxy</category><category>unauthenticated</category><category>super-admin</category><category>kev</category><category>known-ransomware-use</category><category>cwe-288</category></item><item><title>MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</guid><description>High severity (CVSS 7.8) — binary · CVE-2020-17103. Status: Weaponized. Affects: Windows Cloud Files Mini Filter Driver (cldflt.sys) / cldapi.dll. Tags: LPE, Windows, cldflt.sys, Cloud Files API, registry-symlink, race-condition, WER-hijack, SYSTEM-shell, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows</category><category>cldflt.sys</category><category>Cloud Files API</category><category>registry-symlink</category><category>race-condition</category><category>WER-hijack</category><category>SYSTEM-shell</category><category>local-user</category></item></channel></rss>