|
You are here |
blog.lexfo.fr | ||
| | | | |
a13xp0p0v.tech
|
|
| | | | | CVE-2021-26708 is assigned to five race condition bugs in the virtual socket implementation of the Linux kernel. I discovered and fixed them in January 2021. In this article I describe how to exploit them for local privilege escalation on Fedora 33 Server for x86_64, bypassing SMEP and SMAP. | |
| | | | |
googleprojectzero.blogspot.com
|
|
| | | | | Guest blog post, posted by Andrey Konovalov Introduction Lately I've been spending some time fuzzing network-related Linux kernel int... | |
| | | | |
allelesecurity.com
|
|
| | | | | In 2024, our research team noticed and wrote proofs of concept for a use-after-free vulnerability affecting the latest Red Hat Enterprise Linux 9 (RHEL 9). At the time, kernel version 5.14.0-503.15.1.el9_5. The vulnerability had been fixed on the Linux kernel upstream on July 17, 2023 [1][2]. After we reported it, it was backported to Red... | |
| | | | |
a13xp0p0v.github.io
|
|
| | | It's 2020. Quarantines are everywhere - and here I'm writing about one, too. But this quarantine is of a different kind. In this article I'll describe the Linux Kernel Heap Quarantine that I developed for mitigating kernel use-after-free exploitation. | ||