Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
kernel-exploit-factory — Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore. | Kitploit
Tools/GitHubGitHub/bsauce/kernel-exploit-factory
Privilege EscalationVulnerability AnalysisExploitationLearning & EducationCurated ResourcesBinary ExploitationLabs & Practice
GitHubbsauce/kernel-exploit-factory

kernel-exploit-factory

Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.

View Repository
1.3k196284 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

kernel-exploit-factory

Keep updating......

Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.

This repository is to extract all Linux kernel exploit and relative debug environment. You can use Qemu to boot the kernel and test the exploit.


Example```bash

Eg, test CVE-2017-11176, finally you levate privileges and get the shell

john@john-virtual-machine:~/Desktop/kernel-exploit-factory/CVE-2017-11176$ ./start.sh chmod: /dev/csaw: No such file or directory ifconfig: SIOCSIFADDR: No such device route: SIOCADDRT: No such device / $ uname -a Linux (none) 4.11.9 #1 SMP Sat Feb 20 21:52:39 CST 2021 x86_64 GNU/Linux / $ id uid=1000(chal) gid=1000(chal) groups=1000(chal) / $ cd exp /exp $ ./exp-slab-4119 [] sk_rmem_alloc > sk_rcvbuf ==> ok [] mq_notify start [*] wake up thread 1 ... ... /exp # id uid=0(root) gid=0(root) /exp #

---

## Catalog

1. CVE-2015-8550
2. CVE-2016-9793
3. 4-20-BPF-integer
4. CVE-2017-5123
5. CVE-2017-6074
6. CVE-2017-7308
7. CVE-2017-8890
8. CVE-2017-11176
9. CVE-2017-16995
10. CVE-2017-1000112
11. CVE-2018-5333
12. CVE-2019-9213 & CVE-2019-8956
13. CVE-2019-15666
14. CVE-2020-8835
15. CVE-2020-27194
16. CVE-2021-3156
17. CVE-2021-31440
18. CVE-2021-3490
19. CVE-2021-22555
20. CVE-2021-41073
21. CVE-2021-4154
22. CVE-2021-42008
23. CVE-2021-43267
24. CVE-2022-0185
25. CVE-2022-0847
26. CVE-2022-0995
27. CVE-2022-1015
28. CVE-2022-2588
29. CVE-2022-2602
30. CVE-2022-2639
31. CVE-2022-25636
32. CVE-2022-27666
33. CVE-2022-32250
34. CVE-2022-34918
35. CVE-2023-2598
36. CVE-2024-1086
37. CVE-2025-21702
38. CVE-2026-23271

---

## Detail

#### 1.CVE-2015-8550

[writeup](https://blog.csdn.net/panhewu9919/article/details/100891770) 

**Test version**: Linux-4.19.65

**Protection**: kaslr/SMEP enabled, SMAP disabled.

**Vulnerability**: A **double-fetch vulnerability** caused by gcc compiler optimization, which can directly hijack the control flow.

#### 2. CVE-2016-9793

[writeup](https://blog.csdn.net/panhewu9919/article/details/120164051) 

**Test version**: Linux-4.8.13

**Protection**: KASLR/SMAP/SMEP disabled. The forged [skb_shared_info](https://elixir.bootlin.com/linux/v4.8.13/source/include/linux/skbuff.h#L414) structure resides in user space, so it obviously cannot bypass SMAP.

**Vulnerability**: The [sock_setsockopt()](https://elixir.bootlin.com/linux/v4.8.13/source/net/core/sock.c#L658) function in `net/core/sock.c` **incorrectly handles negative values**, causing `sk_sndbuf` and `sk_rcvbuf` to become negative. When `write` is called, `skb->head` and `skb->end` are set incorrectly, and finally when `close` is called, the free operation accesses user space and triggers an error. A [skb_shared_info](https://elixir.bootlin.com/linux/v4.8.13/source/include/linux/skbuff.h#L414) structure is forged at user-space address `0xfffffed0`, and the control flow is hijacked via `skb_shared_info->destructor_arg->callback`.

#### 3. 4-20-BPF-integer

[writeup](https://www.cnblogs.com/bsauce/p/11560224.html) 

**Test version**: Linux-4.20.0-rc3

**Protection**: SMEP enabled, kaslr/SMAP disabled.

**Vulnerability**: An **integer overflow** vulnerability in `queue_stack_map_alloc()` in the Linux eBPF module leads to a heap overflow. The vtable pointer is overwritten to hijack the control flow to `xchg eax, esp`.

#### 4.CVE-2017-5123

[writeup](https://www.jianshu.com/p/90a040114188) 

**Test version**: Linux 4.14-rc4

**Protection**: SMEP/SMAP enabled, KASLR disabled.

**Vulnerability**: The `waitid` implementation in `/kernel/exit.c` does not call `access_ok()` to validate the user-space address when calling `unsafe_put_user()` to copy kernel data to a user-space address, which means data can actually be copied to kernel-space addresses. **waitid fails to validate the user address, resulting in a null arbitrary-address write.** Privilege escalation can be achieved by executing shellcode at address 0 or by overwriting a cred structure within a guessed range.

#### 5.CVE-2017-6074

[writeup](https://bsauce.github.io/2021/09/17/CVE-2017-6074/)      [reference](https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-6074)

**Test version**: Linux-4.9.12

**Protection**: SMEP/SMAP enabled, kASLR disabled.

**Vulnerability**: In the DCCP (Datagram Congestion Control Protocol) of the Linux kernel's IPv6 protocol family, the [dccp_rcv_state_process()](https://elixir.bootlin.com/linux/v4.9.12/source/net/dccp/input.c#L574) function in `net/dccp/input.c` incorrectly handles the `DCCP_PKT_REQUEST` packet data structure in the `LISTEN` state. When a user calls `setsockopt()` with the `IPV6_RECVPKTINFO` option, a **double-free of the `sk_buff` structure** is triggered. The exploitation method is similar to CVE-2016-8655. The first trigger of the vulnerability uses heap spraying to forge the `po->rx_ring->prb_bdqc->retire_blk_timer` structure and executes `native_write_cr4(0x406e0)` to disable SMEP/SMAP; the second trigger uses heap spraying to forge the `skb->...->destructor_arg` structure and executes `commit_creds(prepare_kernel_cred(0))` for privilege escalation.

#### 6.CVE-2017-7308

[writeup](https://www.jianshu.com/p/b53862cd64a6)      [reference](https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-7308)

**Test version**: Linux-4.10.6

**Protection**: SMEP/SMAP enabled, KASLR disabled.

**Vulnerability**: The [`packet_set_ring()`](https://elixir.bootlin.com/linux/v4.10.6/source/net/packet/af_packet.c#L4181) function in `net/packet/af_packet.c` does not correctly check the block size; the length validation condition is wrong, leading to a **heap overflow**. It requires `CAP_NET_RAW` privileges. The function pointer is hijacked twice: first to disable SMEP/SMAP protections, then to escalate privileges.

#### 7.CVE-2017-8890

[writeup](https://www.jianshu.com/p/699de662f567)      [reference](https://xz.aliyun.com/t/2383)

**Test version**: Linux-4.10.15

**Protection**: SMEP enabled, kASLR/SMAP disabled.

**Vulnerability**: The [`inet_csk_clone_lock()`](https://elixir.bootlin.com/linux/v4.10.15/source/net/ipv4/inet_connection_sock.c#L652) function in `net/ipv4/inet_connection_sock.c` has a **double-free** vulnerability. The double-free is used to tamper with the RCU callback function pointer, disable SMEP, and jump to shellcode to modify cred.

#### 8.CVE-2017-11176

[writeup](https://www.jianshu.com/p/76041ec5c59f) 

**Test version**: Linux-4.11.9

**Protection**: SMEP enabled, kASLR/SMAP disabled.

**Vulnerability**: In the POSIX message queue implementation in the Linux kernel, the `mq_notify()` function does not set the sock pointer to null, leading to UAF. Actually, this is a **race-condition-induced double-free vulnerability**, but the race window can be extended indefinitely.

#### 9.CVE-2017-16995

[writeup](https://www.cnblogs.com/bsauce/p/11583310.html) 

**Test version**: Linux-4.4.110

**Protection**: SMEP/SMAP/kaslr enabled.

**Vulnerability**: The Linux eBPF module has an **integer extension** problem. The main issue is that the register value types of the two differ, causing the check function and the actual execution function to behave inconsistently. This vulnerability does not involve stack attacks or control-flow hijacking; it only uses syscall data for privilege escalation, making it a typical application of data-oriented attacks on the Linux kernel.

#### 10. CVE-2017-1000112

[writeup](https://www.jianshu.com/p/1fa163fd5b82)  	  [reference](https://bbs.pediy.com/thread-265319.htm)

**Test version**: Linux-4.12.6

**Protection**: SMEP enabled, SMAP/kaslr disabled.
Download Tool