Security researchers and hardening vendors published a connected body of work showing how Linux kernel heap vulnerabilities can be turned into reliable exploitation primitives and how newer allocator-focused defenses aim to break those chains. Public research revisited CVE-2021-26708, including Alexander Popov's write-up on exploiting the bug and a later proof of concept demonstrating compromise through sshd, while additional analysis examined the msg_msg technique for kernel heap reconnaissance and the broader exploitation value of slab allocator behavior.
Follow-on defensive work focused on disrupting those memory-unsafety paths at the allocator level. grsecurity described AUTOSLAB as a change to the kernel heap security model, HardenedVault assessed SLUBStick risk for embedded systems, and later discussed VED and post-CFI data-oriented protections intended to reduce exploit reliability even when control-flow defenses are present. Together, the reports show a shift from documenting practical Linux kernel heap exploitation to deploying mitigations that target heap grooming, object reuse, and data-only attack techniques.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers from Graz University of Technology presented Fence2Pwn, a Linux kernel exploitation technique that abuses KFENCE’s alternate allocation path to enable cross-cache reclamation of freed kernel memory. The work demonstrated controlled object overlap using synthetic tests and CVE-2023-52926 in io_uring, and noted that Linux kernel and Android mitigations were introduced after disclosure.
grsecurity published an article explaining how AUTOSLAB changes the memory unsafety landscape, adding a new technical development to the broader story.
A hardenedvault article titled "VED 2026: after CFI - data only" was published, documenting a further development in the VED security work.
Phrack issue 71 was published, providing a reference point for related technical research included in that issue.
A hardenedvault post published a proof of concept for exploiting CVE-2021-26708 against sshd, adding further technical detail to the vulnerability's exploitation story.
Alexander Popov published technical details on exploiting CVE-2021-26708 in the Linux kernel in a post titled "Four Bytes of Power: Exploiting CVE-2021-26708 in the Linux kernel."
A hardenedvault post assessed SLUBStick risk for embedded systems, contributing analysis of exploitation risk in that environment.
A hardenedvault article described the "msg_msg" exploit reconnaissance technique and its mitigation in VED, documenting a defensive development related to kernel exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcegrsecurity.net
Open sourcehardenedvault.net
Open sourcehardenedvault.net
Open sourcephrack.org
Open sourcehardenedvault.net
Open sourcehardenedvault.net
Open sourcea13xp0p0v.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.