Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gemini-2.5-pro-nf-tables-red-teaming — Gemini 2.5 Pro nf_tables Red Teaming Case Study (CVE-2023-32233) — LLM Safety Alignment & Responsible Disclosure | Kitploit
Tools/GitHubGitHub/destawell/gemini-2.5-pro-nf-tables-red-teaming
Vulnerability AnalysisExploitationPapers & ResearchLearning & EducationRed TeamingAI Security
GitHubdestawell/gemini-2.5-pro-nf-tables-red-teaming

gemini-2.5-pro-nf-tables-red-teaming

Gemini 2.5 Pro nf_tables Red Teaming Case Study (CVE-2023-32233) — LLM Safety Alignment & Responsible Disclosure

View Repository
131 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Gemini 2.5 Pro nf_tables Red Teaming Case Study (CVE-2023-32233)

LLM Safety Research | Responsible Disclosure | AI Alignment Evaluation

Researcher: Niranj R Mahaswar (Destawell)
Google AI Vulnerability Reward Program: #889286 — Out of Scope

Summary

This repository documents a comparative LLM red teaming experiment on frontier models regarding technical primitives for the Linux kernel vulnerability CVE-2023-32233 (nf_tables race condition / Use-After-Free).

Key Result (April 27, 2026):
Gemini 2.5 Pro generated relevant technical output, while Claude, GPT-4o, Llama 3, and Microsoft Copilot refused the request. By May 16, 2026, Gemini also began refusing similar queries following a safety update.


Timeline & Model Behavior

DateEventOutcome
April 27, 2026Initial testing on Gemini 2.5 ProTechnical output provided
April 27, 2026Responsible disclosure to Google AI VRP (#889286)Submitted
April 30, 2026Google ResponseOut of Scope
May 16, 2026Post-safety update testingRefusal on Gemini
May 20, 2026Tested on Gemini FlashFull refusal

Model Comparison (April 27, 2026 Test)

ModelResponse TypeSafety Decision
Gemini 2.5 ProTechnical details providedPassed (no block)
Anthropic ClaudeRefusedBlocked
OpenAI GPT-4oRefusedBlocked
Meta Llama 3RefusedBlocked
Microsoft CopilotRefusedBlocked

Current Status (May 20, 2026)

Gemini Flash now refuses requests for functional C code, multi-threaded harnesses, or detailed exploit primitives for CVE-2023-32233, citing risks related to race conditions, memory management, and potential denial-of-service.


Purpose of This Repository

  • Document rapid evolution of LLM safety alignment in dual-use cybersecurity topics
  • Provide a public case study on responsible disclosure for AI red teaming
  • Highlight differences in safety policies across major AI providers
  • Serve as educational reference for AI safety researchers and red teamers

This repo contains no prompts, no generated code, and no exploit details.


Keywords

llm-red-teaming ai-safety gemini-2.5-pro gemini-safety cve-2023-32233 nf_tables responsible-disclosure google-vrp ai-alignment kernel-exploit use-after-free race-condition llm-safety red-teaming gemini-red-teaming ai-security-research llm-jailbreak ai-vulnerability gemini-2.5 linux-kernel-exploit nf_tables-race-condition dual-use-ai ai-red-teaming model-alignment google-ai-safety anthropic-claude openai-gpt4o meta-llama microsoft-copilot destawell niranj-mahaswar


Disclaimer
This repository is for educational and research purposes only. It documents observed model behavior to contribute to the public discussion on LLM safety.

Last updated: May 20, 2026
Researcher: github.com/Destawell

Download Tool