Tagged articles

local privilege escalation

9 articles · Page 1 of 1
Black & White Path
Black & White Path
Aug 14, 2026 · Information Security

CVE-2026-68138: Linux Kernel qdisc Rate‑Table Race Condition Allows Local Privilege Escalation (PoC Included)

Security researchers disclosed CVE‑2026‑68138, a race‑condition flaw in the Linux kernel’s qdisc rate‑table code that lets an unprivileged user gain a root shell within seconds; it affects Linux 5.1‑7.1.5, has a publicly available PoC, and can be mitigated by applying upstream patches or disabling unprivileged namespaces.

CVE-2026-68138Linux Kernellocal privilege escalation
0 likes · 9 min read
CVE-2026-68138: Linux Kernel qdisc Rate‑Table Race Condition Allows Local Privilege Escalation (PoC Included)
Black & White Path
Black & White Path
Aug 6, 2026 · Information Security

OVSwrap: A 13-Year-Old Linux Kernel Flaw That Lets Any Local User Escalate to Root

OVSwrap (CVE‑2026‑64531) is a memory‑corruption bug in the Open vSwitch kernel data‑path that has lingered for 13 years; a low‑privilege local user can trigger a length‑wrap overflow to leak pointers, read kernel memory, and decrement fsuid/fsgid to gain root across dozens of major Linux distributions, with a publicly released PoC covering ~800 x86‑64 kernel versions and detailed mitigation steps.

CVE-2026-64531Linux KernelOVSwrap
0 likes · 16 min read
OVSwrap: A 13-Year-Old Linux Kernel Flaw That Lets Any Local User Escalate to Root
Black & White Path
Black & White Path
Jun 11, 2026 · Information Security

Nightmare Eclipse Returns: RoguePlanet Zero‑Day Grants SYSTEM on Patched Windows

On June 9, 2026, security researcher Nightmare Eclipse released the RoguePlanet zero‑day exploit that leverages a race condition in Microsoft Defender to spawn a SYSTEM‑level command prompt on Windows 10/11 machines fully patched with the June updates, while also hinting at a possible BitLocker bypass.

BitLocker bypassMicrosoft DefenderRoguePlanet
0 likes · 10 min read
Nightmare Eclipse Returns: RoguePlanet Zero‑Day Grants SYSTEM on Patched Windows
Black & White Path
Black & White Path
May 18, 2026 · Information Security

Windows Kernel LPE (CVE‑2026‑40369) PoC: Privilege Escalation from Chrome Sandbox

CVE‑2026‑40369 is an arbitrary kernel‑address write bug in ntoskrnl.exe that lets a low‑privilege attacker invoke NtQuerySystemInformation from the Chrome sandbox to gain SYSTEM rights on vulnerable Windows 11 and Server 2025 builds, with a fully functional PoC released on GitHub.

CVE-2026-40369Chrome sandboxNtQuerySystemInformation
0 likes · 10 min read
Windows Kernel LPE (CVE‑2026‑40369) PoC: Privilege Escalation from Chrome Sandbox
Black & White Path
Black & White Path
May 17, 2026 · Information Security

From Normal User to Root: Inside the ssh-keysign-pwn Linux Kernel LPE (CVE‑2026‑46333)

The article details the ssh-keysign-pwn vulnerability (CVE‑2026‑46333), explaining its exit‑mm/exit‑files race condition, how ordinary users can steal SSH host keys and /etc/shadow via pidfd_getfd, the affected Linux distributions, exploit steps, mitigation measures, and the broader context of May 2026 kernel security disclosures.

CVE-2026-46333KernelLinux
0 likes · 16 min read
From Normal User to Root: Inside the ssh-keysign-pwn Linux Kernel LPE (CVE‑2026‑46333)
Black & White Path
Black & White Path
May 9, 2026 · Information Security

Dirty Frag: A New Deterministic Linux Page‑Cache Write Vulnerability for Stable Root Escalation

Dirty Frag is a newly disclosed Linux kernel page‑cache write bug that combines xfrm‑ESP and RxRPC primitives to deterministically corrupt struct sk_buff‑frag, allowing an unprivileged local user to gain root without race conditions, works across major distributions, and can be mitigated by disabling the affected modules.

Dirty FragLinux KernelRxRPC
0 likes · 9 min read
Dirty Frag: A New Deterministic Linux Page‑Cache Write Vulnerability for Stable Root Escalation
Black & White Path
Black & White Path
Apr 17, 2026 · Information Security

RedSun PoC Uses Windows Defender Tag to Overwrite Files and Escalate Privileges

The RedSun proof‑of‑concept demonstrates that when Windows Defender detects a malicious file marked with a cloud‑based detection tag, it may rewrite the file to its original location instead of isolating it, allowing an attacker to replace system files and obtain administrator privileges.

RedSunWindows Defenderlocal privilege escalation
0 likes · 1 min read
RedSun PoC Uses Windows Defender Tag to Overwrite Files and Escalate Privileges