kernel-security
5 posts
The kernel keeps its word
OpenBSD's use-after-free is not a bypass but the kernel honoring a reference it validated once and never rechecked, the same pattern behind X.509 certificate trust.
CVE-2023-2163 is now a config file away
Zeroserve exposes eBPF program loading through an HTTP scripting surface. The kernel verifier becomes the trust boundary for every web request.
A binary that hands kernel hooks to anyone
Zeroserve packages kernel-adjacent execution surface under userspace pipelines. The artifact crosses a privilege boundary the pipeline was not scoped to see.
Fragnesia is already loose
Fragnesia Linux privilege escalation has a public PoC. The kernel trust boundary is conditional on patch state. What must now be true.
Third party broke kernel LPE embargo
A kernel LPE entered public circulation when a third party broke the disclosure embargo. The control under review was the agreement, not the patch.