Google's security-research repository received kernelCTF-related pull requests tied to Linux kernel vulnerabilities including CVE-2024-26582, CVE-2026-23209, and a reference to CVE-2026-23392. The updates were submitted through GitHub pull requests and include repeated revisions to mitigation material, writeups, and proof-of-concept content, with commit history showing iterative changes such as "final," "update writeup," and "update pocs." One pull request associated with CVE-2026-23209 also references files named original.tar.gz and exploit.md, indicating publication of source material and exploit documentation in the repository.
The available records do not provide technical specifics on exploitation, affected distributions, or patch guidance, but they show active disclosure and documentation work around kernelCTF targets in Google's public research repository. For defenders, the appearance of exploit notes and PoC-related updates in a widely watched security-research project is a signal to track the cited CVEs closely, validate kernel exposure, and review vendor advisories and mitigation status for impacted Linux environments.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
A Google security-research pull request titled "Add kernelCTF CVE-2026-43456_lts_cos_mitigation" was published, indicating repository activity for CVE-2026-43456 with multiple verified revisions. The available fragment provides little technical detail beyond code-review and repository update workflow, but it reflects publication of new kernelCTF-related source material.
A Google security-research pull request published kernelCTF exploit materials for CVE-2025-40019 targeting mitigation-v4-6.12, described as a 1-day port of the published essiv ssize-underflow technique. The submission states the exploit captured the flag live as exp521 on 2026-05-13 and includes updated offsets, embedded crypto code to remove an OpenSSL dependency, and schema-compliant metadata changes.
A Google security-research pull request titled "Add kernelCTF CVE-2026-23394_lts_cos" was published, indicating repository publication of materials for CVE-2026-23394_lts_cos. The available fragment mentions commit identifiers and a fix for build warnings, but provides limited technical detail beyond the addition of exploit-related source material.
A Google security-research pull request titled "Add kernelCTF CVE-2026-43074_lts" was published, indicating repository publication of materials for CVE-2026-43074_lts. The available fragment references an LTS submission, a commit identifier, and verification activity, but provides limited technical detail beyond the addition of exploit-related source material.
A Google security-research pull request published kernelCTF materials for CVE-2026-23271_lts, including commits that renamed the original exploit and updated the exploit code and Makefile. The reference indicates repository publication of exploit-related source material rather than a newly disclosed victim or incident.
A Google security-research pull request published materials for CVE-2026-23351_cos, describing an nft_set_pipapo garbage-collection use-after-free affecting Container-Optimized OS build cos-121-18867.381.30. The discussion also documented exploitation details and branch updates, including CI fixes and correction of the nft_immediate_eval offset for the targeted COS build.
A Google security-research pull request titled "Add kernelCTF CVE-2026-23392_cos" was published, indicating repository publication of materials for CVE-2026-23392_cos, including updates to original metadata and an exploit.cpp file. The reference reflects disclosure of exploit-related source material rather than a newly reported victim incident.
A later Google security-research pull request adds files including original.tar.gz and exploit.md for CVE-2026-23209 in the kernelCTF repository. This reflects publication of source material and exploit documentation for the vulnerability.
A Google security-research pull request history shows multiple commits adding and revising a kernelCTF mitigation for CVE-2024-26582, followed by updates labeled final, writeup, and PoCs. The material indicates ongoing security research and documentation work rather than a newly described incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.