Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-53365 — Local privilege escalation exploit targeting a Linux kernel io_uring AF_VSOCK reference-count bug, using page-cache manipulation to overwrite /usr/bin/su and obtain a root shell. Intended for authorized security research and testing. | Kitploit
Tools/GitHubGitHub/hackspeak/cve-2026-53365
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingBinary Exploitation
GitHubhackspeak/cve-2026-53365

CVE-2026-53365

Local privilege escalation exploit targeting a Linux kernel io_uring AF_VSOCK reference-count bug, using page-cache manipulation to overwrite /usr/bin/su and obtain a root shell. Intended for authorized security research and testing.

View Repository
42191 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-53365 — VsockDrop:io_uring + AF_VSOCK Zero-Copy Reference Count Underflow, Page-Cache Overwrite Privilege Escalation

HackSpeak distribution mirror. This repository is a distribution mirror of MaherAzzouzi/vsockdrop, with code identical to upstream; upstream does not include a LICENSE, so the mirror follows distribution convention and adopts MIT License, Copyright (c) 2026 HackSpeak, with source code copyright belonging to the original author MaherAzzouzi.

⚠️ Contains a full Local Privilege Escalation (LPE) exploit — it modifies the page-cache of /usr/bin/su (may persist to disk on CoW filesystems); for security research, vulnerability validation, and authorized testing only. Run it only in isolated environments you own or are explicitly authorized to test, do not use it against unauthorized systems.

Vulnerability Summary

VsockDrop (CVE-2026-53365) is a reference count mishandling vulnerability in the Linux kernel's io_uring zero-copy send path (AF_VSOCK), which can lead to unprivileged local privilege escalation (LPE).

  • Root cause: during multi-skb sends over vsock, io_uring uses SKBFL_MANAGED_FRAG_REFS but the vsock path does not honor this flag → __skb_frag_unref() calls put_page() on the managed page → one extra put_page per send, directly decrementing the pin count;
  • Exploit chain:
    1. Reference count underflow: after 1024 SEND_ZC calls, refcount = 1 + 1024 is drained to 0 → the still-pinned page is freed to the PCP freelist;
    2. Page-cache reclaim: a single cold pread of page 0 of /usr/bin/su retrieves the just-freed PFN from the LIFO freelist → the page is now aliased between the io_uring fixed buffer and the su page-cache;
    3. PT_INTERP overwrite: use write_fixed/read_fixed to overwrite the PT_INTERP string in the su page with the attacker's loader path;
    4. Data-only privilege escalation: exec("/usr/bin/su") (setuid-root) → the kernel maps the attacker's loader as the interpreter → enters with root credentials → root shell.
  • Affected versions: Linux 6.7 → 7.0.10; fixed in: 7.0.11 and corresponding stable branches;
  • Exploitation requirements: no user namespaces needed, single static binary;
  • CVSS: NVD score 5.5 (availability impact), but the author believes it should be 7.8 (LPE).

Usage

make
./exploit

⚠️ Dangerous operation: the exploit modifies the content of /usr/bin/su in page-cache; on CoW filesystems (such as Btrfs, ZFS), this modification may persist to disk. Run it only in disposable isolated environments.

Disclaimer

  • For security research, vulnerability validation, and defensive testing only; run it in disposable environments, do not use it against unauthorized systems.
  • This exploit is for defensive research and has been responsibly disclosed to [email protected]; before use, confirm that the target system is owned by you or that you have explicit authorization.

References

  • Upstream source repository (source of this exploit): https://github.com/MaherAzzouzi/vsockdrop
  • NVD: CVE-2026-53365
  • Example upstream patches:
    • https://git.kernel.org/stable/c/ae38d9179190a956e2a87a69ef1dd6f451b51c4d
    • https://git.kernel.org/stable/c/76b995bc57bd90cb6e954e1966fbd8786da47f0d
    • https://git.kernel.org/stable/c/b3155f2b78db21e99256bcf7eb902f24ff6d5338
  • Ubuntu Security Notice: https://ubuntu.com/security/CVE-2026-53365
  • Author's demo: https://x.com/maherazz2/status/2088233024424919395
Download Tool