Tag
The research introduces a generic exploitation strategy that leverages OEM-specific vulnerabilities in Android kernel drivers to achieve root access on devices from Samsung, Xiaomi, and others, focusing on reliability, portability, and universality.
This article explores static allocation strategies to prevent memory safety bugs such as use-after-free and type confusion, discussing object pools and generational indices, and introducing tricks from TigerStyle for avoiding dynamic memory allocation after initialization.
HackSys Extreme Vulnerable Driver (HEVD) is an intentionally vulnerable Windows kernel driver for learning kernel exploitation techniques, including use-after-free, stack overflows, and pool overflows. The tweet notes that a UAF exploit has been completed.
Tencent's Corvus AI research pipeline discovered SCTPhantom, an 18-year-old use-after-free vulnerability in Linux SCTP dynamic address reconfiguration (ASCONF) that enables local privilege escalation. The article details the discovery, root cause, exploitation chain, and upstream fix.
Zapscape (CVE-2026-64561) is a KVM/x86 shadow MMU use-after-free vulnerability that allows a guest VM to escape to the host and execute code with kernel privileges. The published PoC demonstrates a full guest-to-host escape targeting AMD SVM/NPT on Linux 7.1.3, posing a serious threat to multi-tenant public clouds.
An engineering blog post from Buildkite details how a flaky test led to the discovery of a use-after-free bug in the redis-client Ruby library, describing the debugging process and root cause analysis.
This article details the discovery and exploitation of a Linux kernel 0-day vulnerability in the network scheduler subsystem (red scheduler), turning a limited slab use-after-free into full physical memory read/write, ultimately achieving privilege escalation to root. The vulnerability existed for 2.5 years and was fixed in June 2026.
A use-after-free vulnerability in OpenBSD through version 7.9 allows local attackers to escalate privileges to root. The flaw exists in sysv_sem.c and is identified as CVE-2026-57589.
A use-after-free vulnerability in the DRM GEM core ioctl DRM_IOCTL_GEM_CHANGE_HANDLE allows unprivileged local users with render node access to escalate to root. The bug was fixed in the Linux kernel mainline in May 2026.
CVE-2026-42530 discloses a use-after-free vulnerability in nginx's HTTP/3 QUIC module.
A detailed walkthrough of the Linux kernel's AF_UNIX garbage collector rewrite, explaining the background, the new graph-based model, and a Use-After-Free bug.
A single faulty character in the Linux kernel introduced a use-after-free vulnerability (CVE-2026-53111) allowing unprivileged users to escalate privileges to root on Debian and Ubuntu systems; the bug has been fixed and backported.
A detailed analysis of a use-after-free vulnerability in the Linux kernel's epoll subsystem, fixed by switching to RCU, and the author's failed attempts at exploiting it on a modern device.