
Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.
Keep updating......
Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.
This repository is to extract all Linux kernel exploit and relative debug environment. You can use Qemu to boot the kernel and test the exploit.
john@john-virtual-machine:~/Desktop/kernel-exploit-factory/CVE-2017-11176$ ./start.sh chmod: /dev/csaw: No such file or directory ifconfig: SIOCSIFADDR: No such device route: SIOCADDRT: No such device / $ uname -a Linux (none) 4.11.9 #1 SMP Sat Feb 20 21:52:39 CST 2021 x86_64 GNU/Linux / $ id uid=1000(chal) gid=1000(chal) groups=1000(chal) / $ cd exp /exp $ ./exp-slab-4119 [] sk_rmem_alloc > sk_rcvbuf ==> ok [] mq_notify start [*] wake up thread 1 ... ... /exp # id uid=0(root) gid=0(root) /exp #
---
## Catalog
1. CVE-2015-8550
2. CVE-2016-9793
3. 4-20-BPF-integer
4. CVE-2017-5123
5. CVE-2017-6074
6. CVE-2017-7308
7. CVE-2017-8890
8. CVE-2017-11176
9. CVE-2017-16995
10. CVE-2017-1000112
11. CVE-2018-5333
12. CVE-2019-9213 & CVE-2019-8956
13. CVE-2019-15666
14. CVE-2020-8835
15. CVE-2020-27194
16. CVE-2021-3156
17. CVE-2021-31440
18. CVE-2021-3490
19. CVE-2021-22555
20. CVE-2021-41073
21. CVE-2021-4154
22. CVE-2021-42008
23. CVE-2021-43267
24. CVE-2022-0185
25. CVE-2022-0847
26. CVE-2022-0995
27. CVE-2022-1015
28. CVE-2022-2588
29. CVE-2022-2602
30. CVE-2022-2639
31. CVE-2022-25636
32. CVE-2022-27666
33. CVE-2022-32250
34. CVE-2022-34918
35. CVE-2023-2598
36. CVE-2024-1086
37. CVE-2025-21702
38. CVE-2026-23271
---
## Detail
#### 1.CVE-2015-8550
[writeup](https://blog.csdn.net/panhewu9919/article/details/100891770)
**Test version**: Linux-4.19.65
**Protection**: kaslr/SMEP enabled, SMAP disabled.
**Vulnerability**: A **double-fetch vulnerability** caused by gcc compiler optimization, which can directly hijack the control flow.
#### 2. CVE-2016-9793
[writeup](https://blog.csdn.net/panhewu9919/article/details/120164051)
**Test version**: Linux-4.8.13
**Protection**: KASLR/SMAP/SMEP disabled. The forged [skb_shared_info](https://elixir.bootlin.com/linux/v4.8.13/source/include/linux/skbuff.h#L414) structure resides in user space, so it obviously cannot bypass SMAP.
**Vulnerability**: The [sock_setsockopt()](https://elixir.bootlin.com/linux/v4.8.13/source/net/core/sock.c#L658) function in `net/core/sock.c` **incorrectly handles negative values**, causing `sk_sndbuf` and `sk_rcvbuf` to become negative. When `write` is called, `skb->head` and `skb->end` are set incorrectly, and finally when `close` is called, the free operation accesses user space and triggers an error. A [skb_shared_info](https://elixir.bootlin.com/linux/v4.8.13/source/include/linux/skbuff.h#L414) structure is forged at user-space address `0xfffffed0`, and the control flow is hijacked via `skb_shared_info->destructor_arg->callback`.
#### 3. 4-20-BPF-integer
[writeup](https://www.cnblogs.com/bsauce/p/11560224.html)
**Test version**: Linux-4.20.0-rc3
**Protection**: SMEP enabled, kaslr/SMAP disabled.
**Vulnerability**: An **integer overflow** vulnerability in `queue_stack_map_alloc()` in the Linux eBPF module leads to a heap overflow. The vtable pointer is overwritten to hijack the control flow to `xchg eax, esp`.
#### 4.CVE-2017-5123
[writeup](https://www.jianshu.com/p/90a040114188)
**Test version**: Linux 4.14-rc4
**Protection**: SMEP/SMAP enabled, KASLR disabled.
**Vulnerability**: The `waitid` implementation in `/kernel/exit.c` does not call `access_ok()` to validate the user-space address when calling `unsafe_put_user()` to copy kernel data to a user-space address, which means data can actually be copied to kernel-space addresses. **waitid fails to validate the user address, resulting in a null arbitrary-address write.** Privilege escalation can be achieved by executing shellcode at address 0 or by overwriting a cred structure within a guessed range.
#### 5.CVE-2017-6074
[writeup](https://bsauce.github.io/2021/09/17/CVE-2017-6074/) [reference](https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-6074)
**Test version**: Linux-4.9.12
**Protection**: SMEP/SMAP enabled, kASLR disabled.
**Vulnerability**: In the DCCP (Datagram Congestion Control Protocol) of the Linux kernel's IPv6 protocol family, the [dccp_rcv_state_process()](https://elixir.bootlin.com/linux/v4.9.12/source/net/dccp/input.c#L574) function in `net/dccp/input.c` incorrectly handles the `DCCP_PKT_REQUEST` packet data structure in the `LISTEN` state. When a user calls `setsockopt()` with the `IPV6_RECVPKTINFO` option, a **double-free of the `sk_buff` structure** is triggered. The exploitation method is similar to CVE-2016-8655. The first trigger of the vulnerability uses heap spraying to forge the `po->rx_ring->prb_bdqc->retire_blk_timer` structure and executes `native_write_cr4(0x406e0)` to disable SMEP/SMAP; the second trigger uses heap spraying to forge the `skb->...->destructor_arg` structure and executes `commit_creds(prepare_kernel_cred(0))` for privilege escalation.
#### 6.CVE-2017-7308
[writeup](https://www.jianshu.com/p/b53862cd64a6) [reference](https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-7308)
**Test version**: Linux-4.10.6
**Protection**: SMEP/SMAP enabled, KASLR disabled.
**Vulnerability**: The [`packet_set_ring()`](https://elixir.bootlin.com/linux/v4.10.6/source/net/packet/af_packet.c#L4181) function in `net/packet/af_packet.c` does not correctly check the block size; the length validation condition is wrong, leading to a **heap overflow**. It requires `CAP_NET_RAW` privileges. The function pointer is hijacked twice: first to disable SMEP/SMAP protections, then to escalate privileges.
#### 7.CVE-2017-8890
[writeup](https://www.jianshu.com/p/699de662f567) [reference](https://xz.aliyun.com/t/2383)
**Test version**: Linux-4.10.15
**Protection**: SMEP enabled, kASLR/SMAP disabled.
**Vulnerability**: The [`inet_csk_clone_lock()`](https://elixir.bootlin.com/linux/v4.10.15/source/net/ipv4/inet_connection_sock.c#L652) function in `net/ipv4/inet_connection_sock.c` has a **double-free** vulnerability. The double-free is used to tamper with the RCU callback function pointer, disable SMEP, and jump to shellcode to modify cred.
#### 8.CVE-2017-11176
[writeup](https://www.jianshu.com/p/76041ec5c59f)
**Test version**: Linux-4.11.9
**Protection**: SMEP enabled, kASLR/SMAP disabled.
**Vulnerability**: In the POSIX message queue implementation in the Linux kernel, the `mq_notify()` function does not set the sock pointer to null, leading to UAF. Actually, this is a **race-condition-induced double-free vulnerability**, but the race window can be extended indefinitely.
#### 9.CVE-2017-16995
[writeup](https://www.cnblogs.com/bsauce/p/11583310.html)
**Test version**: Linux-4.4.110
**Protection**: SMEP/SMAP/kaslr enabled.
**Vulnerability**: The Linux eBPF module has an **integer extension** problem. The main issue is that the register value types of the two differ, causing the check function and the actual execution function to behave inconsistently. This vulnerability does not involve stack attacks or control-flow hijacking; it only uses syscall data for privilege escalation, making it a typical application of data-oriented attacks on the Linux kernel.
#### 10. CVE-2017-1000112
[writeup](https://www.jianshu.com/p/1fa163fd5b82) [reference](https://bbs.pediy.com/thread-265319.htm)
**Test version**: Linux-4.12.6
**Protection**: SMEP enabled, SMAP/kaslr disabled.