A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation exploit for CVE-2023-2598, targeting the Linux kernel's io_uring subsystem. The main exploit code is in 'exp.c', which leverages a strong out-of-bounds write primitive to overwrite memory and ultimately modify the '/etc/passwd' file. The exploit attempts to add a new root user ('hacker') by writing a new line to '/etc/passwd', granting root access. The code uses advanced Linux features such as io_uring, memory mapping, and file descriptor manipulation. The exploit is operational and demonstrates a practical attack, but is not weaponized for mass exploitation. The only fingerprintable endpoint is the '/etc/passwd' file, which is the target for privilege escalation. The repository is structured simply, with a single C exploit file, a README describing the exploit's purpose, and a license file.
This repository contains a working local privilege escalation exploit for CVE-2023-2598, a vulnerability in the Linux kernel's io_uring subsystem. The main exploit code is in 'my_exploit.c', which is a C program that manipulates kernel memory to overwrite the credentials structure of a process, setting its UID and GID to 0 (root). The exploit works by exhausting the kernel's credential cache and memory allocator (buddy system), then spraying cloned processes to increase the chances of finding and modifying the correct credentials in memory. Once successful, it spawns a root shell (/bin/sh). The repository also includes a 'rootfs' directory with a minimal root filesystem, likely for use in a container or VM for testing. The exploit is operational and demonstrates a full privilege escalation chain, but is not part of a framework and requires local code execution on a vulnerable Linux system.
This repository contains a working local privilege escalation exploit for CVE-2023-2598, a vulnerability in the Linux kernel's io_uring subsystem. The main file, CVE-2023-2598.c, is a C program that leverages advanced kernel memory manipulation techniques, including the use of memfd, io_uring, and direct interaction with the /dev/ttyS0 device via ioctl. The exploit is designed to leak kernel addresses, craft fake kernel structures, and ultimately execute a shell as root by hijacking kernel control flow. The README.md provides build instructions, references, and a demonstration of successful exploitation on a Linux 6.3.1 system. The exploit is operational and provides a root shell if successful. The only fingerprintable endpoint is the use of /dev/ttyS0, which is targeted for the ioctl call that triggers the vulnerability. The repository is structured simply, with one exploit source file and a README.
This repository contains a local privilege escalation (LPE) exploit for CVE-2023-2598, a vulnerability in the Linux kernel's io_uring subsystem. The main exploit code is in 'exploit.c', which is a C program leveraging advanced memory manipulation and io_uring buffer registration to achieve arbitrary kernel memory access. The exploit constructs fake kernel structures and triggers a call to call_usermodehelper_exec, resulting in a root shell. The exploit targets the Linux kernel on systems where io_uring is enabled and accessible. The repository also includes a detailed write-up ('writeup.md') explaining the vulnerability and exploitation process, and a brief README with compilation instructions. The exploit does not target network endpoints but interacts with local kernel interfaces and file descriptors. The main fingerprintable endpoints are file paths used for memory file descriptors and the TTY device for shell access. The exploit is operational and provides a working local root shell if successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.