Researchers introduced PrimSynth, a multi-agent framework that discovers, validates, and synthesizes exploit primitives for Linux kernel memory-corruption vulnerabilities. The system models six primitive classes and uses vulnerability-directed execution, runtime validation, static analysis, iterative agent feedback, and rebootable test environments to build multi-stage exploit strategies, including object constraints, sequencing, environmental prerequisites, and code-synthesis rules.
Across 16 real-world Linux kernel CVEs spanning five vulnerability types, PrimSynth achieved a reported 100% primitive-match rate. It synthesized complete exploit strategies in 82.4% of cases when public proof-of-concept guidance was available and 61.3% without primitive hypotheses; however, the evaluation used controlled, permissive conditions and did not validate effectiveness against hardened production systems with protections such as KPTI, control-flow integrity, or pointer authentication.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Pengfei Wang, Anying Chen, Danjun Liu, Xu Zhou, and Wei Xie submitted the PrimSynth paper, describing a multi-agent framework to discover, validate, and synthesize exploit primitives for Linux kernel memory-corruption vulnerabilities. The authors evaluated it on 16 real-world Linux kernel CVEs and reported a 100% primitive-match rate, with strategy synthesis rates of 82.4% with public proof-of-concept guidance and 61.3% without it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.