Researchers documented how a Linux kernel networking flaw fixed by commit 36eec020fab66—a NULL pointer dereference in mq_attach—can be turned from a crash into local root access under the right conditions. The walkthroughs used Debian 12 with vulnerable kernel 6.1.8-1, showed the bug being triggered by creating a bond interface, attaching an mq queuing discipline, and replacing that qdisc, and then demonstrated how the fault path could be steered into a refcount underflow and controlled callback execution. The lab setup deliberately weakened protections by allowing NULL-page mapping and disabling mitigations such as SMEP, SMAP, KASLR, and PTI to study exploitability in a controlled environment.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
When KASLR was enabled, hard-coded gadget and symbol addresses no longer worked, so the exploit was adapted to leak the randomized address of noop_qdisc from a controlled netdev_queue during qdisc replacement. The leaked address was used to compute the KASLR slide, rebuild gadget addresses, and trigger the vulnerability again to regain root.
In the fourth Allele Security post, enabling SMEP broke the earlier ret2usr privilege-escalation method, so the exploit was reworked to use a kernel ROP chain with a stack pivot, prepare_kernel_cred, commit_creds, rtnl_unlock, and a swapgs/sysretq return path. With SMEP enabled and KASLR disabled, the revised exploit successfully regained root privileges.
By aligning a userland stand-in struct Qdisc so refcnt sat at offset 0x64 and setting myqdisc at address 0x28, the researcher drove execution into qdisc_destroy. Kernel logs then showed an NX-protected page execution attempt, and GDB indicated ((struct Qdisc *)0x28)->ops->destroy resolved to 0x28.
After mapping the NULL page and placing crafted data there, the observed kernel behavior changed from a not-present page fault to a refcount underflow/use-after-free warning in mq_attach and qdisc_put. This demonstrated attacker influence over the dereferenced object layout during exploitation.
The researcher then implemented the trigger in C using unshare(CLONE_NEWNET | CLONE_NEWUSER) and libnl NETLINK_ROUTE operations to create the bond interface and manipulate qdiscs programmatically. Running the trigger again caused the process to be killed and produced a kernel call trace through qdisc_graft and tc_modify_qdisc.
The second Allele Security post shows that creating a bond interface, bringing it up, adding an mq qdisc, and replacing that qdisc inside unprivileged user and network namespaces reliably triggers the bug. Kernel logs reported a NULL pointer dereference at address 0x0 after the sequence executed.
The first Allele Security post sets up a Debian 12 lab using Debian kernel package version 6.1.8-1, matching source, debug symbols, and a boot configuration that disables SMEP, SMAP, KASLR, and PTI while setting vm.mmap_min_addr=0. The environment is prepared specifically to study and exploit the mq_attach NULL pointer dereference.
The Allele Security articles identify Linux kernel commit 36eec020fab66, titled "net: sched: fix NULL pointer dereference in mq_attach," as the fix for the targeted networking vulnerability. This establishes the upstream remediation event for the bug later analyzed and exploited in the lab series.
The namespaces manual states that since Linux 3.8, creating a user namespace no longer requires privilege. This capability is relevant to later exploitation techniques that rely on unprivileged user and network namespaces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
man7.org
Open sourceallelesecurity.com
Open sourceallelesecurity.com
Open sourceallelesecurity.com
Open sourceallelesecurity.com
Open sourceoutflux.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.