
Local privilege escalation exploit targeting a Linux kernel io_uring AF_VSOCK reference-count bug, using page-cache manipulation to overwrite /usr/bin/su and obtain a root shell. Intended for authorized security research and testing.
HackSpeak distribution mirror. This repository is a distribution mirror of MaherAzzouzi/vsockdrop, with code identical to upstream; upstream does not include a LICENSE, so the mirror follows distribution convention and adopts MIT License, Copyright (c) 2026 HackSpeak, with source code copyright belonging to the original author MaherAzzouzi.
⚠️ Contains a full Local Privilege Escalation (LPE) exploit — it modifies the page-cache of
/usr/bin/su(may persist to disk on CoW filesystems); for security research, vulnerability validation, and authorized testing only. Run it only in isolated environments you own or are explicitly authorized to test, do not use it against unauthorized systems.
VsockDrop (CVE-2026-53365) is a reference count mishandling vulnerability in the Linux kernel's io_uring zero-copy send path (AF_VSOCK), which can lead to unprivileged local privilege escalation (LPE).
io_uring uses SKBFL_MANAGED_FRAG_REFS but the vsock path does not honor this flag → __skb_frag_unref() calls put_page() on the managed page → one extra put_page per send, directly decrementing the pin count;SEND_ZC calls, refcount = 1 + 1024 is drained to 0 → the still-pinned page is freed to the PCP freelist;pread of page 0 of /usr/bin/su retrieves the just-freed PFN from the LIFO freelist → the page is now aliased between the io_uring fixed buffer and the su page-cache;write_fixed/read_fixed to overwrite the PT_INTERP string in the su page with the attacker's loader path;exec("/usr/bin/su") (setuid-root) → the kernel maps the attacker's loader as the interpreter → enters with root credentials → root shell.make
./exploit
⚠️ Dangerous operation: the exploit modifies the content of /usr/bin/su in page-cache; on CoW filesystems (such as Btrfs, ZFS), this modification may persist to disk. Run it only in disposable isolated environments.