
rootkit
Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel AF_ALG memory corruption vulnerability. Uses splice to patch /usr/bin/su in page cache,…

Weaponized Python exploit for CVE-2026-31431, chaining Linux kernel privilege escalation to a daemonized root reverse shell with full PTY, patching…

GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel

From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)

CVE-2026-43499 GhostLock futex UAF LPE PoC for OPPO PCKM00 (SM6150) / Linux 4.14.180

Local privilege escalation proof-of-concept for CVE-2026-64531 abusing OVS kernel datapath to corrupt credentials and gain root via sudoers injection.

Exploits CVE-2026-43499 on Android GKI 6.12 devices: deterministic arbitrary kernel read/write, KASLR bypass, and full root via LD_PRELOAD payload.

encrypted-linux-kernel-modules

A rootkit for ubuntu-16.04.6 (Linux 4.4). Can hide a process, give root access and hide itself

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched…

CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

Report on Linux kernel privilege escalation vulnerability CVE-2019-13272, detailing the flaw and potential impact for security research and awareness.