Sunday, October 4, 2026

linux-kernel-exploitation for tracking kernel security research and defensive study

linux-kernel-exploitation for tracking kernel security research and defensive study

xairy/linux-kernel-exploitation is a bimonthly-updated curated bibliography of Linux kernel security research, serving as a study map for authorized researchers and defensive engineers.

Toolxairy/linux-kernel-exploitation — a curated, bimonthly-updated collection of links on Linux kernel security and exploitation
CategoryCurated research bibliography / educational resource
Primary UseTracking and studying Linux kernel exploitation literature, techniques, CTF practice material, and Defensive countermeasures in one indexed README
Safe UseEducational and documentary reference for authorized security professionals, students in lab environments, kernel developers hardening subsystems, and defensive researchers studying mitigation bypass literature
Telemetry NotePurely a static README link list under CC-BY-4.0; it executes nothing, contacts nothing, and leaves no footprint — defenders benefit from it as a threat-research indexing aid

Some of the most durable value in security GitHub comes not from code but from curation, and xairy/linux-kernel-exploitation is arguably the canonical example in the kernel security niche. Maintained by Andrey Konovalov, the repository is a single dense README that functions as a continuously indexed bibliography of Linux kernel exploitation research. It is updated bimonthly, accepts pull requests from the community, and carries a CC-BY-4.0 license, which makes it a legitimately redistributable teaching asset. With over six and a half thousand stars and no code in the conventional sense, it occupies the role of a field library rather than a toolkit, and that is precisely why authorized professionals keep it bookmarked.

The table of contents reveals the editorial structure, and that structure is itself informative about how the discipline is organized. Top-level sections cover Books, Techniques (split into Exploitation and Protection Bypasses), Vulnerabilities (subdivided into Info-leaks, LPE, RCE, KVM, and Other), Finding Bugs, Defensive, Exploits, and Tools, followed by a substantial Practice branch with Workshops, CTF Tasks, Other Tasks, Playgrounds, and Infrastructure. This taxonomy mirrors the actual workflow of a kernel researcher: understand mitigations, study how they were bypassed, review real vulnerability classes, then practice against deliberately vulnerable targets.

The Techniques section is the heart of the collection and it is aggressively current. The 2026 entries alone include Fence2Pwn, which examines exploitation under KFENCE while bypassing slab hardening and memory tagging, CopyKat on controllable-copy objects for data-only attacks, a revival of the modprobe_path technique overcoming the search_binary_handler() patch, PhantomMap on GPU-assisted kernel exploitation, and Cross-Cache Attacks via PCP Massaging. For an analyst trying to understand where kernel attack surface research is heading, the recency of this list — maintained on a bimonthly cadence — makes it a better signal than most conference proceedings indexes.

What stands out across the technique entries is the shift from classic control-flow hijacking toward data-only and memory-layout attacks. Entries like DirtyFree on simplified data-oriented programming, Dirty Pagetable, PageJack with page-level use-after-free, SLUBStick on cross-cache attacks yielding arbitrary writes, and the Cross Cache Attack CheetSheet document a research community systematically working around KASLR, CFI, SMEP/SMAP, and slab hardening. The README does not teach these techniques itself; it indexes the primary papers, slides, and writeups, always linking to the original authors, which keeps it a documentary index rather than an operational manual.

The historical layer is equally valuable for newcomers building a mental timeline. The Techniques list reaches back through 2024 work like GhostRace on speculative race conditions, K-LEAK on automating multi-step infoleak chains, and RetSpill, into the 2023 wave of DirtyCred container-escape research, prctl anon_vma_name heap spraying, and KSMA GPU-MMU attacks on Android. Paired with the two anchor books — A Guide to Kernel Exploitation: Attacking the Core and the Android Hacker's Handbook — a reader can reconstruct a decade of the field's evolution from a single page.

The Practice section is where the collection earns its place in educational and lab contexts. It points to Workshops, curated CTF Tasks, and dedicated Playgrounds — deliberately vulnerable kernel environments built for legal training — alongside Infrastructure material for setting up kernel debugging and testing. For a professional preparing for authorized engagements involving Linux targets, or an instructor designing a course, this section provides a legitimate path from reading to hands-on skill without touching any production system.

Defensive readers are explicitly served, not just incidentally. The README carries a dedicated Defensive section, and the Protection Bypasses subsection is effectively a mitigation-coverage tracker: when a paper demonstrates bypassing a hardening feature, defenders gain a direct map of where their mitigations are weakest. Entries on KFENCE, memory tagging, TLB side-channel leaks that ironically amplify defenses, and RCU callback abuse of KASLR all translate directly into hardening priorities for kernel maintainers and blue teams monitoring Linux fleets.

Operationally, the repository is trivially safe to consume: it is a README of links under permissive licensing, updated via pull requests, with update notifications available through the maintainer's accounts and the linkersec channels on Telegram, X, Mastodon, Bluesky, and Reddit. Anyone can git clone https://github.com/xairy/linux-kernel-exploitation to keep a local snapshot of the bibliography. There is no telemetry, no build step, and no executable component — the entire artifact is prose and hyperlinks.

Where this fits in a professional workflow is straightforward. Threat researchers use it to correlate a new CVE with prior art on the affected subsystem; exploitation engineers use it to find the primary academic sources before writing anything; instructors use it as a syllabus backbone; and defenders use it to anticipate which technique classes will mature from papers into observed exploitation. The collection's honest scope — it indexes rather than instructs — is what keeps it a durable, policy-clean reference. For anyone serious about Linux kernel security on either side of the fence, xairy/linux-kernel-exploitation remains the field's shared reading list, and its bimonthly refresh cycle means the shelf is never stale.

Official project repository for xairy/linux-kernel-exploitation.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.