CVE-2024-0582 is a memory leak vulnerability in the Linux kernel's io_uring subsystem. The flaw occurs in the lifecycle handling of a provided buffer ring when a user registers a buffer ring with IORING_REGISTER_PBUF_RING, maps it with mmap(), and then frees it. Under this sequence, kernel memory associated with the buffer ring is not properly released, resulting in a leak. The issue is local in nature and affects systems exposing the vulnerable io_uring functionality to unprivileged local users. According to the provided information, successful triggering can crash the system and may potentially be leveraged for privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact local Linux kernel exploit for CVE-2024-0582, consisting of a short README and a single C source file, exp.c. The exploit targets a use-after-free in the io_uring subsystem on Linux kernel 6.6.1 and is intended for local privilege escalation rather than remote code execution. Repository structure is minimal: README.md identifies the CVE, target kernel version, and links to three public research references; exp.c contains the full exploit logic. There is no framework, no build system, and no modularization beyond a few helper functions for System V message queue operations. The exploit’s core capability is to obtain root privileges by corrupting kernel heap objects and replacing the current process’s cred and real_cred pointers with init_cred. The code uses io_uring_setup with IORING_SETUP_NO_SQARRAY, then registers a provided buffer ring with IORING_REGISTER_PBUF_RING and maps it with mmap using IORING_OFF_PBUF_RING. After unregistering the ring, it reclaims the freed slab object using System V message queues allocated in kmalloc-cg-512. It tags overlapped msg_msg data via the stale pbuf mapping to identify the affected queue. Next, it allocates a secondary message in kmalloc-cg-1k, reads back overlapped metadata through the stale mapping, and frees that object so pipe_buffer structures can be sprayed into the reclaimed space using many pipe() calls. This is used to leak kernel pointers and build a primitive for further kernel memory manipulation. The truncated code still clearly shows the final privilege-escalation stage: it computes or obtains current_task and init_cred addresses, then writes init_cred into the current task’s real_cred and cred-related fields using manipulated linked-list/message metadata through the stale mappings. Finally, it checks getuid()/geteuid() for root and prints a success message. The exploit is operational rather than a mere proof of concept because it contains a complete privilege-escalation path and a concrete payload effect, but it is not highly weaponized: offsets such as TASK_* are hardcoded, the target kernel version is narrow, and the author comments that spawning a shell is unreliable due to init_cred refcount/page-fault issues. There are no network endpoints, C2 addresses, or remote targets; all observable endpoints are local kernel interfaces, syscalls, and repository reference URLs.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-0582, a page-level use-after-free vulnerability in the Linux kernel's io_uring subsystem. The main exploit logic is implemented in 'exp.c', which leverages io_uring to trigger a use-after-free condition, manipulates kernel memory to locate and overwrite the current process's credentials, and spawns a root shell if successful. The exploit is designed for academic research and is intended to be run in a controlled QEMU virtual machine environment, as facilitated by the provided 'build_release.sh' (for building the kernel with the correct configuration) and 'run.sh' (for launching the VM). The 'lts-6.6.config' file provides a minimal kernel configuration enabling io_uring and other necessary options. The exploit targets Linux kernel version 6.6.2 (or compatible 6.6.x) and requires specific kernel settings for reliable exploitation. The attack vector is local privilege escalation, and the payload is a root shell. No network endpoints are involved; the only fingerprintable endpoints are file paths such as '/bin/sh' and '/proc/slabinfo'. The repository is structured for reproducible research and responsible disclosure, with clear warnings against use on production systems.
This repository provides a comprehensive Proof-of-Concept (PoC) exploit for CVE-2024-0582, a Linux kernel vulnerability in the io_uring subsystem that allows use-after-free of memory pages. The repository contains two main exploit techniques: 1. Dirty Cred (implemented in both C and Rust): This method manipulates kernel memory via io_uring to gain write access to /etc/passwd, injecting a new root user entry ('evil::0:0:root:/root:/bin/bash'). The exploit requires adjusting kernel memory offsets for the target system and is designed for local privilege escalation. 2. Dirty Pagetable (implemented in C): This method corrupts page table entries to redirect kernel memory access, leaks kernel base addresses, and injects custom shellcode into the kernel. The shellcode calls prepare_kernel_cred and commit_creds to escalate privileges and spawns a root shell by invoking the pivot_root syscall. This method also requires precise kernel offsets and is highly dependent on the target environment. The repository is well-structured, with separate directories for each exploit method (dirty_cred and dirty_page_table), each containing source code, build scripts (Makefiles), and detailed documentation (README.md) explaining the attack flow, requirements, and configuration steps. There is also a QEMU launch script (run_qemu.sh) for setting up a test environment. The exploits are not weaponized but provide clear PoC code for researchers and security professionals to study or adapt for testing. The main attack vector is local privilege escalation on a vulnerable Linux system.
This repository contains a proof-of-concept local privilege escalation exploit for CVE-2024-0582, targeting the io_uring subsystem in vulnerable Linux kernels (notably Ubuntu). The exploit is implemented in C (dataonly.c) and is accompanied by a README.md that explains the attack strategy and usage. The exploit works by abusing a use-after-free (UAF) vulnerability in io_uring buffer rings to gain write access to the /etc/passwd file, allowing the attacker to append a new root user entry (backdoor). The code increases the file descriptor limit, sprays file objects by opening /etc/passwd many times, searches for file structures in freed memory, modifies file permissions in memory, and attempts to write the backdoor string to /etc/passwd. If successful, this grants root access via the new user. The exploit is operational and requires local access to the target system. No network endpoints are involved; the main fingerprintable target is the /etc/passwd file.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-0582, a vulnerability in the Linux kernel's io_uring subsystem. The main file, GenIoURingExploit.c, is a C program that demonstrates how to leverage this vulnerability to escalate privileges on a vulnerable Linux system. The exploit works by setting up io_uring buffer rings, leaking KASLR (Kernel Address Space Layout Randomization) information, and manipulating kernel socket structures to overwrite function pointers. This allows the attacker to execute arbitrary shell commands (such as spawning a root shell) in kernel context. The exploit requires root or administrative privileges to run, and is intended for educational and research purposes only. The repository also includes a README.md with detailed usage instructions and a LICENSE file. The only fingerprintable endpoint is the device file /dev/ttyS0, which is referenced in the exploit code. The exploit is not part of a framework and is a standalone PoC.
This repository contains a local privilege escalation (LPE) exploit for CVE-2024-0582, targeting the Linux kernel's io_uring subsystem. The exploit is implemented in C (exploit.c) and is designed to be run on a vulnerable Linux system. The code manipulates io_uring buffer rings and socket options to craft kernel memory structures, ultimately triggering a vulnerability that allows the attacker to execute code as root. The exploit interacts with the /dev/ttyS0 device and uses ioctl calls to trigger the vulnerability. The README provides context and references but no detailed write-up. The repository is structured simply, with a single exploit source file and a README. No network endpoints or remote attack vectors are present; the exploit is purely local and requires execution on the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.