Google Project Zero released MAccConc, a prototype toolkit for systematically testing Linux kernel race conditions by tracing memory accesses and injecting execution delays to force selected thread orderings. Using KASAN/ASAN outline instrumentation with KCOV, it identifies conflicting cross-thread accesses to the same memory region as communication points, then uses count-augmented stack traces and ordering constraints to reproduce target interleavings without modifying kernel source code. The tooling includes automated A-B-A interleaving tests plus terminal and graphical interfaces; a dup()/close() demonstration forced reuse of a file descriptor closed by a concurrent thread.
The approach can validate known flaws and aid discovery of new kernel concurrency bugs, including the n_hdlc race tracked as CVE-2017-2636, where concurrent flush_tx_queue() and n_hdlc_send_frames() operations can cause a double free and local privilege escalation to root. MAccConc currently has coverage and scalability constraints: ASAN outline instrumentation misses many direct stack-object accesses, and exhaustive interleaving searches become impractical for large syzkaller reproducers. Required LLVM support shipped in LLVM 23.1.0, while the associated Linux kernel patches had not yet been upstreamed at publication.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Project Zero published MAccConc (Memory Access Concurrency), a prototype toolset that traces kernel memory accesses, identifies conflicting cross-thread communication points, and injects delays to test selected execution orderings.
syzkaller detected a suspicious crash associated with the n_hdlc driver race. The flaw can cause a double free through concurrent flush_tx_queue() and n_hdlc_send_frames() activity.
Linux commit be10eb75893 introduced a race condition in the n_hdlc driver, later tracked as CVE-2017-2636.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcelinuxsecurity.com
Open sourceprojectzero.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.