Back to Skills

kernel-exploitation

Linux kernel exploitation playbook. Use when exploiting kernel vulnerabilities (UAF, OOB, race condition, type confusion) for privilege escalation via commit_creds, modprobe_path overwrite, or kernel ROP chains in CTF and real-world scenarios.

1,292stars177forksUpdated 7/6/2026

Security Assessment

Low Risk(80/100)

Detected risks:

Privilege Escalation([SKILL.md] chmod 777)
Security Score80/100

About kernel-exploitation

A neutral, technical playbook for Linux kernel exploitation, aimed at capture-the-flag challenges and authorized real-world security research. It walks the full exploitation model, from finding a vulnerability, to building read/write or RIP-control primitives, bypassing mitigations, escalating privileges, and returning cleanly to userspace. The material is distilled from public CTF references and real kernel CVEs, and it is careful to distinguish kernel-mode constraints from userspace ones, particularly around SMEP, SMAP, and KPTI.

Environment setup covers building a custom kernel and booting it under QEMU, attaching GDB to the emulator's built-in gdbserver, loading kernel symbols, and repacking an initramfs with cpio to include an exploit binary. Vulnerability classes are catalogued with representative CVEs: use-after-free, out-of-bounds read/write, race conditions, integer overflow, type confusion, double free, and the rare kernel stack overflow.

Privilege-escalation targets include the classic commit_creds(prepare_kernel_cred(0)) call and its ROP-chain equivalent, overwriting modprobe_path to run an attacker script as root, direct overwrite of a task's cred structure, and namespace escape for container scenarios. Sections on kernel ROP explain controlled-RIP sources such as corrupted function pointers and the seq_operations hijack pattern, plus stack-pivoting gadgets, while a ret2usr section notes why SMEP blocks executing user pages. Returning to userspace is covered through swapgs and iretq and, when KPTI is enabled, the kernel's own return trampoline. Companion reference files detail mitigation bypasses (KASLR, SMEP, SMAP, KPTI, FG-KASLR, CFI) and SLUB heap techniques, and related skills connect it to userspace ROP and heap exploitation.

FAQ

What environment does it use for building and debugging exploits?

It boots a custom-compiled kernel under QEMU with a GDB server on port 1234, loads kernel symbols in GDB, and modifies the initramfs with cpio to add an exploit binary.

Which privilege-escalation techniques are covered?

It covers commit_creds(prepare_kernel_cred(0)), overwriting modprobe_path to run a script as root, directly overwriting the current task's cred structure, and namespace escape for containers.

What vulnerability classes does it address?

Use-after-free, out-of-bounds read/write, race conditions (TOCTOU), integer overflow, type confusion, double free, and kernel stack overflow, each with representative kernel CVEs.

How do you return to userspace after escalating privileges?

Traditionally via swapgs followed by iretq using saved userspace state, or, when KPTI is enabled, through the kernel's own KPTI return trampoline because user pages are not directly mapped.

Which mitigations does it discuss bypassing?

KASLR, SMEP, SMAP, and KPTI are discussed in the main flow, with FG-KASLR and CFI covered in the referenced KERNEL_MITIGATION_BYPASS.md file.

All Files

3 files
SKILL.md10.4 KB
View
KERNEL_HEAP_TECHNIQUES.md9.8 KB
View
KERNEL_MITIGATION_BYPASS.md8.3 KB
View

Install kernel-exploitation

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill