Linux kernels mark themselves as tainted when they enter non-standard states, including when unsigned, externally built, or otherwise unsupported kernel modules are loaded. Kernel documentation and DFIR guidance show that investigators can identify this condition through dmesg, /proc/modules, /proc/sys/kernel/tainted, and the kernel-chktaint helper, which decodes taint bits into human-readable reasons.
The guidance highlights that taint status can be an important forensic signal because it may indicate third-party or custom code ran in kernel space, but it also warns that proving which exact .ko file caused the taint can be difficult after the fact. Analysts are advised to correlate taint evidence with shell history, filesystem searches for module files, journal records, and audit logs to reconstruct how a suspicious module was introduced and loaded.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A DFIR blog post explained how to detect and investigate tainted Linux kernels using artifacts such as dmesg, /proc/modules, /proc/sys/kernel/tainted, kernel-chktaint, journalctl, and shell history. It also noted that reconstructing the original file path of a loaded tainting module may be difficult or impossible after the fact.
In the DFIR example, loading a custom kernel module named "dfir" caused the running Linux kernel to become tainted. Kernel messages indicated the module was out-of-tree and failed signature verification, and the taint value was later observed as 12288.
The Linux kernel documentation describes how a kernel becomes tainted when it enters certain non-standard states, such as loading proprietary, unsupported, or unsigned modules, and explains how taint flags are represented and interpreted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.