The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2016-6187, a heap off-by-one vulnerability in the Linux kernel. The main file, 'matreshka.c', is a C program that demonstrates the vulnerability by manipulating kernel heap structures and using userfaultfd to control page faults. The exploit writes crafted data to '/proc/self/attr/current' and uses System V message queues and memory mapping to trigger the bug. The result is that the kernel's instruction pointer is redirected to 0xdeadbeef, demonstrating control over execution flow, but no practical payload (such as privilege escalation or shell access) is provided. The exploit must be run locally on a vulnerable Linux system. The repository structure is simple, consisting of a README and the exploit source code.
This repository contains a local privilege escalation exploit for CVE-2016-6187, targeting Linux kernel versions prior to 4.6.5. The vulnerability is a heap-based single null byte overflow in AppArmor's setprocattr LSM hook, which can be exploited to corrupt heap metadata and achieve arbitrary kernel memory manipulation. The exploit is implemented in C (exploit.c) and is compiled statically via the provided Makefile. The exploit works by manipulating message queues and IPv6 multicast socket options to create overlapping heap allocations, leaking kernel pointers, and ultimately overwriting the ptmx_fops.unlocked_ioctl function pointer. By triggering an ioctl on /dev/ptmx, the exploit pivots the kernel stack to a user-controlled ROP chain, which escalates privileges by calling commit_creds(prepare_kernel_cred(NULL)) and spawns a root shell. The repository also includes a boot script (boot.sh) for launching a QEMU virtual machine with a vulnerable kernel and a sample kernel configuration file. The exploit requires /dev/rfkill to be accessible by unprivileged users and is intended for local execution on a vulnerable system. The README provides detailed technical background, exploitation steps, and requirements.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.