A new Linux kernel exploitation technique shows how the zero_pfn mapping can be abused to make dirty pagetable attacks more reliable and turn limited page-table corruption into local privilege escalation. The write-up says zero_pfn can disclose a kernel physical address, helping attackers bypass physical kASLR, and notes that on x86 Linux the Interrupt Descriptor Table (IDT) is mapped immediately after zero_pfn. That layout allows a partially corrupted page-table entry to be redirected into read-write access over the IDT, creating a path from memory corruption to kernel control.
The research further describes Interrupt Oriented Programming (IOP) as a way to gain kernel code execution by chaining fault and interrupt handlers instead of conventional ROP gadgets, including in environments protected by kPTI. It also outlines a SMAP bypass by preserving the AC flag when the usual interrupt prologue that executes clac is skipped. A related dirty pagetable reference provides background on the page-table overlap technique, while the newer research argues similar zero_pfn adjacency issues may also affect ARM systems through overlap attacks against kPTI trampoline mappings even without a physical memory leak.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A 2023 write-up discussed the Dirty Pagetable exploitation technique, which is later referenced as a basis for the zero_pfn-based Linux kernel exploitation approach.
A July 2025 blog post described abusing zero_pfn mappings to simplify dirty pagetable attacks, leak a kernel physical address to bypass physical kASLR, and turn partial page-table corruption into read-write access to the IDT for local privilege escalation. The post also introduced an Interrupt Oriented Programming approach and described a SMAP bypass and ARM-related implications.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.