Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
uaf-exploit-cve-2026-23415 — Proof-of-concept exploit for CVE-2026-23415, a use-after-free in the Linux kernel futex subsystem, demonstrating a race condition between futex_key_to_node_opt() and vma_replace_policy(). | Kitploit
Tools/GitHubGitHub/addman2/uaf-exploit-cve-2026-23415
Vulnerability AnalysisExploitationLearning & EducationBinary Exploitation
GitHubaddman2/uaf-exploit-cve-2026-23415

uaf-exploit-cve-2026-23415

Proof-of-concept exploit for CVE-2026-23415, a use-after-free in the Linux kernel futex subsystem, demonstrating a race condition between futex_key_to_node_opt() and vma_replace_policy().

View Repository
22 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-23415 PoC

CVE-2026-23415 PoC

Proof of concept for CVE-2026-23415, a use-after-free vulnerability in the Linux kernel futex subsystem.

About the vulnerability

A race condition exists between futex_key_to_node_opt() and vma_replace_policy().

While the futex code reads a virtual memory area's NUMA memory policy, another thread can replace and free that policy through mbind(). The kernel may then dereference the freed policy pointer, resulting in a use-after-free read.

Usage

Run the proof of concept:

bash poc-cve-2026-23415.sh

No compilation or additional setup is required.

Disclaimer

This project is provided for educational, research, and authorized security-testing purposes only.

Run it only on systems you own or have explicit permission to test. The script may cause instability or crash a vulnerable system. Using this project against systems without authorization may be illegal.

References

  • CVE-2026-23415
  • Linux kernel futex subsystem
  • Linux kernel security advisories
Download Tool