CVE-2026-52910 is a use-after-free vulnerability in the Linux kernel's handling of classic BPF programs attached to reuseport socket groups. When a program is replaced or detached through reuseport_attach_prog() or reuseport_detach_prog(), sk_reuseport_prog_free() immediately releases the cBPF program through bpf_release_orig_filter() and bpf_prog_free() without waiting for concurrent RCU readers to finish. UDP packet processing can consequently access freed program memory in reuseport_select_sock(). A reproducer triggered a KASAN-detected four-byte out-of-bounds read. The existing eBPF destruction path is not affected under the described fast-path behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains two standalone, statically linked C proof-of-concept kernel exploits, plus Bash/QEMU tooling that constructs disposable Ubuntu guests and executes each binary from a fresh Docker container with networking disabled. It is not a Metasploit, Nuclei, or similar framework module. The top-level Makefile builds the two PoC directories; each directory has target-specific build instructions and technical documentation. The VM builder downloads checksum-verified Ubuntu cloud images, provisions Docker, validates the expected kernel release, and creates a read-only golden qcow2 image. The runner boots a temporary qcow2 overlay, transfers a selected binary through guest SSH, bind-mounts it as /payload in a new container, and destroys the overlay after execution. CVE-2026-52910 is a hard-coded Ubuntu 6.8.0-139-generic reuseport classic-BPF race exploit. Its poc.c coordinates socket, timerfd, epoll, packet-ring, pipe, and JIT-filter sprays to reclaim a stale program. filter-gen.c produces the included target-specific filter data, using fixed return and core_pattern-related kernel addresses. The intended post-exploitation action is an interactive host-namespace root shell via a core-pattern overwrite and core-dump trigger. CVE-2026-80521 targets the AF_UNIX garbage collector lifetime flaw in Ubuntu kernel 7.0.0-31-generic. Its accompanying documentation describes arranging a partial collection of a strongly connected component using AF_UNIX sockets and SCM_RIGHTS, then reclaiming the resulting stale SCC-linked unix_vertex. xdk_kaslr.c supplies prefetch-timing helpers to infer the kernel KASLR and direct-map bases without direct kernel reads. The documented exploit chain uses AF_PACKET ring allocations and heap grooming, then escapes the container and exposes a root shell in guest host namespaces. Both exploits are destructive, kernel-version-specific local/container attacks rather than remote network exploits.
This 16-file C/Bash repository contains two destructive, target-specific Linux kernel container-escape PoCs plus tooling to build and run them only within disposable QEMU Ubuntu guests. The root Makefile builds static x86-64 binaries in pocs/CVE-2026-52910 and pocs/CVE-2026-80521. CVE-2026-52910 includes poc.c, a cBPF-JIT filter generator, and generated filter data; it races reuseport classic-BPF program replacement and uses kernel-address-specific JIT spraying to redirect execution via core_pattern. CVE-2026-80521 includes a KASLR/direct-map prefetch side-channel helper and documentation describing an AF_UNIX SCC garbage-collection use-after-free induced through SCM_RIGHTS descriptor-graph races, heap grooming, and object reclamation. The latter directory's Makefile references poc.c, although that source file is not present in the supplied file listing. vm/build_image.sh downloads and checksum-verifies Ubuntu cloud images, provisions Docker in a golden guest image, and vm/run_container.sh boots a temporary QCOW2 overlay, transfers the selected binary over loopback SSH, and runs it in a network-disabled Docker container. The repository is standalone and not a Metasploit, Nuclei, or other exploit-framework module.
This is a standalone Linux-kernel race reproducer/stress toolkit for CVE-2026-52910, not a Metasploit, Nuclei, or similar framework module. Its primary executable, reuseport_race_hammer.c, creates multiple UDP SO_REUSEPORT socket groups, attaches classic-BPF reuseport selector programs, concurrently floods each group with UDP traffic, and repeatedly replaces or detaches the selectors. This targets an unsafe immediate free of an old cBPF program while an RCU-protected RX softirq path may still execute its instructions. The result is intended to expose a KASAN vmalloc out-of-bounds/UAF condition, a kernel crash, or incorrect deterministic packet selection. The C hammer uses a final settle-and-measure phase in which each selector must route all traffic to a final socket; packets arriving at other sockets generate an integrity warning. run_hammer.sh is a privileged test wrapper that optionally raises net.core.optmem_max, captures pre/post bpf_prog vmalloc counts, scans only new dmesg output for kernel failure indicators, and optionally invokes kmemleak. livepatch_cycle.sh runs the hammer while applying and reverting a configurable kpatch/livepatch module, including an immediate-revert RCU-hazard mode intended to identify pending callback/module-unload lifecycle failures. The repository also contains a Makefile, GitHub Actions build/ShellCheck workflow, GPL-2.0 license, and documentation. It is a disruptive local proof of concept intended for authorized disposable systems, rather than an exploitation chain providing privilege escalation or remote code execution.
This repository is a small standalone proof-of-concept exploit repository for CVE-2026-52910. It contains 5 files: a README, Makefile, license, gitignore, and one C source file named crash.c. The Makefile targets Android/aarch64 using the Android NDK clang toolchain, indicating the PoC is intended for Android or Android-derived kernels, though the bug class also applies to Linux kernel behavior. The exploit is a local kernel denial-of-service PoC, not a remote exploit. Its core capability is to trigger a kernel panic by racing setsockopt(SO_ATTACH_REUSEPORT_CBPF) on a UDP loopback socket while the old classic BPF reuseport program is still being used in the receive path. To widen the race window, the code creates a timerfd and duplicates it across many epoll instances in forked child processes, producing an epoll/timerfd callback storm that slows kernel processing. A secondary thread repeatedly replaces the attached cBPF program and immediately performs a pipe spray with zero-filled pages, attempting to reclaim freed kernel memory. The README explicitly states the intended outcome: the reclaimed bpf_prog page has bpf_func set to 0x0, causing a NULL jump and kernel panic. Main exploit flow in crash.c: main() raises RLIMIT_NOFILE, creates a timerfd, sets up the epoll storm via setup_epoll_storm(), creates a UDP socket bound to 127.0.0.1:12345 with SO_REUSEPORT, attaches an initial cBPF filter, initializes many pipes for spraying, starts a replacer thread, then continuously sends UDP datagrams to the loopback socket while arming the timerfd with varying nanosecond values. The replacer thread alternates between two small sock_fprog filters (fprog_a and fprog_b), calling setsockopt(SO_ATTACH_REUSEPORT_CBPF) in a tight loop and spraying pipe buffers after each replacement. Synchronization is handled with a pthread barrier so packet sending, timer arming, and filter replacement occur in a coordinated race. There is no post-exploitation payload, persistence, credential theft, or command execution. The only intended result is kernel crash/panic. No external C2 or internet endpoints are present; the only network target is the local loopback UDP endpoint 127.0.0.1:12345 used to exercise the vulnerable kernel path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel race condition causes a classic BPF (cBPF) reuseport program to be freed before concurrent RCU readers finish accessing it, resulting in invalid memory access. The fix defers freeing the program until after an RCU grace period. The advisory assigns CVSS v3 severity 6.4, describing local exploitation requiring high privileges and high attack complexity, with potentially high confidentiality, integrity, and availability impacts.
A Linux kernel race condition involving classic BPF programs attached to reuseport socket groups. Concurrent program replacement or detachment and UDP packet processing can cause a program to be freed while RCU readers still access it, resulting in invalid memory accesses. The reported reproducer triggers a KASAN vmalloc-out-of-bounds read. The fix defers freeing the cBPF program until after an RCU grace period. The listed CVSS v3 base score is 6.4, with local access, high attack complexity, high privileges required, and high confidentiality, integrity, and availability impacts. The advisory recommends updating the affected Google COS kernel packages to version 18867.381.201 or later.
A separate reuseport cBPF program-replacement race enabling a container escape on the specific Ubuntu 24.04 kernel 6.8.0-139-generic x86-64 build. It is mentioned as an additional proof of concept rather than the article's primary focus.
Linux kernel BPF lifetime-management vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.