CVE-2026-64560 is a use-after-free vulnerability in the Linux kernel POSIX CPU timers subsystem. A race between POSIX CPU-timer deletion, setting, or rearming and a multithreaded non-leader exec() can cause timer code to act on stale thread-group-leader state. If a TGID-targeted timer is armed and remains queued while exec() transfers thread-group leadership, timer deletion can free the underlying POSIX timer object even though timer processing or timerqueue operations can still access its timerqueue node. The issue also affects the CPU nanosleep path, where the timer object may be stack allocated. The upstream fix introduces release/acquire memory ordering around signal-handler state, retries task lookup when it encounters a transitioning former leader, and applies the helper to the affected timer operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This 28-file repository is a device-specific Android local privilege-escalation adaptation for CVE-2026-64560, described as a Linux POSIX CPU timer use-after-free caused by a non-leader exec race. It targets the OnePlus Ace 6 OP6113L1 and binds execution to two exact Android build fingerprints that share a byte-identical decoded kernel Image hash (ee5ee448…); the expected kernel is Android GKI 6.6.118. The documented exploit chain uses a probabilistic timer race and reclaim strategy (fanout or rotate), obtains KASLR/boot-ID state, builds a misc-list/physical-memory bridge, rewrites credentials to root, and attempts to restore altered metadata and SELinux enforcement afterward. Root is intentionally current-boot-only. The repository contains documentation, a JSON device profile with static kernel addresses and tuning, host-side ADB campaign runners, build/profiling tooling, and src/temp-su.c. The latter is a C abstract-UNIX-socket daemon/client that must be started from the newly obtained root shell; it services root, ADB shell, and app-UID clients and spawns /system/bin/sh. Build automation compiles three static ARM64 binaries, including fanout, rotate, and temp-su. However, src/exploit-fanout-opace6.c and src/exploit-rotate-opace6.c, as well as their stated template sources, are referenced by CI and profiles but are not included in the supplied archive. Consequently, the main kernel-write implementation cannot be independently code-reviewed here, despite extensive documentation claiming successful device validation. The profile also has status "draft", while the README/changelog describe it as verified, an internal consistency issue worth noting.
This is a genuine device-specific Android kernel local privilege-escalation repository for CVE-2026-64560, a posix-cpu-timers use-after-free triggered through a non-leader exec race. Its primary payload is an AArch64 C exploit that uses timer spraying and reclaim strategies to gain controlled kernel access, obtain root credentials, restore critical state, and execute a temporary su helper. The helper exposes a root interactive shell only to the Android shell user or root through an abstract UNIX socket and is intended to last only until reboot. The repository contains a Go single-binary toolchain in gotool/ that ports the Python workflow: kallsyms extraction, symbol lookup, raw ARM64 Image/BTF profile derivation, source rendering, target-specific patching, static payload compilation, ELF validation, and an ADB-driven cold-boot campaign. Python tools in tools/ remain as reference implementations and CI parity baselines. scripts/ contains Bash and PowerShell campaign, measurement, build, probing, and target-scaffolding automation. profiles/ and targets/ hold exact-device fingerprints, kernel releases, hashes, offsets, addresses, runtime gates, and artifact metadata; docs/ records validation and porting evidence. Supported profiles include a documented, verified OnePlus 13 fanout chain; a Xiaomi 15 profile; and a realme RMX5010 Android 16 port. The RMX5010 profile has validated static offsets and preflight gates but is explicitly draft, with no full-chain device validation. The campaign deploys binaries over ADB to /data/local/tmp, enforces a 55 C thermal threshold, retries across reboots, checks boot IDs, and determines success only by requesting a new shell that reports uid=0(root). No exploit code network callback, C2 endpoint, persistence mechanism, or partition modification is evident.
This 27-file repository is a device-specific Android local privilege-escalation adaptation for CVE-2026-64560, described as a POSIX CPU timer use-after-free caused by a non-leader exec race. Its documented target is the OnePlus Ace 6 OP6113L1 on one exact Android 16/kernel 6.6.118 build. The intended exploit uses timer spraying and a race/reclaim strategy to reach a controlled kernel-memory bridge, manipulate credentials, restore sensitive metadata, retain SELinux enforcement, and start a current-boot root-shell helper. Host-side Windows batch, POSIX shell, and PowerShell runners drive ADB deployment, fingerprint/kernel/hash checks, thermal gating, bounded retries across reboots, logging, and fresh-shell uid=0 validation. Python tools derive profiles from raw ARM64 kernel images by extracting kallsyms, BTF layout information, and direct-map cycle facts. The included src/temp-su.c is functional C code for a temporary abstract-UNIX-socket shell broker. It must be started with root, accepts only root or Android shell UID clients, and executes /system/bin/sh for an authorized client. However, the repository is incomplete as delivered: the central sources referenced by CI and the profile generator (src/exploit-fanout.c, src/exploit-rotate.c, and generated *-opace6.c files) are absent, as are release artifacts. The supplied OP Ace 6 profile is status=draft and the normal PowerShell runner rejects unverified profiles. Documentation also contains inherited Xiaomi 15/OnePlus 13 references, reflecting template/porting provenance. Consequently, this is a credible exploit adaptation and support toolkit, but it is not directly buildable or validated from the supplied snapshot.
This 42-file repository is a device-specific local Android kernel privilege-escalation adaptation for CVE-2026-64560, a posix_cpu_timers non-leader-exec race/use-after-free fixed upstream by Linux commit 920f893f735e. It contains PowerShell and POSIX ADB campaign runners, C source for a temporary root helper, target profiles for Xiaomi 15 (dada) and OnePlus 13 (OP5D0DL1/PJZ110), target-derived kernel offsets, run evidence, and Python tooling to derive BTF layouts, kallsyms, and profile facts from an exact raw ARM64 kernel Image. The runners enforce target fingerprint/kernel/hash gates, verify payload hashes, wait for thermal conditions, retry across cold boots, and verify success only from a fresh ADB shell. The documented chain races CPU timers, derives KASLR, performs controlled kernel-object reclaim and bridge operations, gains physical-memory/pipe-metadata access, swaps credentials, restores affected state and SELinux enforcement, and starts the temporary-su daemon. src/temp-su.c exposes only a local abstract UNIX socket and requires peer UID 0 or Android shell UID 2000 before spawning /system/bin/sh; access ends at reboot. The repository contains logs/evidence of OP13 root-shell results and declares verified profiles, but the core exploit C sources and referenced release binaries (for example src/exploit-fanout*.c and bin/cve-2026-64560-*) are referenced by manifests and documentation yet are absent from the supplied file inventory. Consequently, the included orchestration and helper are not independently buildable/runnable as a complete exploit from this archive alone.
This is a device-specific Android local privilege-escalation adaptation for CVE-2026-64560, described as the Linux posix-cpu-timers non-leader-exec race/UAF. It targets only the Redmi K80 Pro (miro) OS3.0.304.0.WOMCNXM build and uses hardcoded kernel layout, direct-map, physical-memory, credential, and SELinux offsets. Documentation describes two race strategies: fanout and rotate. The chain races timer destruction and non-leader exec, uses a forged timer/sysctl structure to alter/read boot_id and calculate KASLR, creates a UHID/misc-device bridge for kernel arbitrary read/write, obtains physical memory access through pipe-buffer manipulation, rewrites credentials to root, and changes SELinux to permissive. A conservative safety design reportedly restores intermediate state or spins indefinitely when restoration cannot be proven; failures can hang or reboot the target. The repository has 29 files: extensive Chinese-language build/use/technical documentation; C reference/profile files; a fully present C temporary-su daemon; and Python/shell tooling for extracting Android kernels, BTF offsets, device-tree memory maps, profile generation, diagnostics, and reproducible NDK builds. The primary exploit C files and prebuilt binaries referred to throughout the README (src/exploit-fanout-miro.c, src/exploit-rotate-miro.c, upstream source inputs, and release_build binaries) are not included in the supplied file listing/content. Consequently, the core exploit implementation cannot be independently code-verified from this archive snapshot; the assessed exploitation behavior is based on the detailed repository documentation and supporting profile/tooling. The included temp-su.c is functional: it requires root to start, exposes abstract socket dada_temp_su_v1, restricts clients to UID 0 or 2000, and serves root interactive /system/bin/sh sessions until reboot.
This 20-file repository is a device-specific adaptation for CVE-2026-64560, described as a POSIX CPU-timer non-leader exec() race leading to Android kernel local privilege escalation. PowerShell scripts provide reproducible Android NDK builds, artifact checksum enforcement, ADB device profiling, draft-profile generation, thermal gating, payload staging, bounded retry/reboot recovery, and fresh-shell root validation. A verified JSON profile binds execution to one Xiaomi 15/dada firmware and kernel build, with pinned boot/Image and artifact hashes. src/temp-su.c is present and supplies a root-owned abstract UNIX-socket service restricted to UID 0 and Android shell UID 2000. tools/derive_profile.py scans an uncompressed arm64 Image for linked-list cycles and derives address-related profile facts. Although the profile and documentation reference fanout and rotate native exploit sources/binaries, src/exploit-fanout.c, src/exploit-rotate.c, and the bin/ release artifacts are absent from the provided file set; consequently the archived repository cannot build or execute the full exploit as supplied. No external HTTP, DNS, IP, or TCP/UDP command-and-control endpoint is present.
This repository is a local Android kernel privilege-escalation exploit for CVE-2026-64560, a use-after-free in Linux posix CPU timers caused by a race between posix_cpu_timer_del() and de_thread() during non-leader exec(). The repo contains a Makefile, a README, and four C sources: src/exploit.c as the main exploit, src/cve_2026_64560.c as a simpler PoC/UAF trigger and detector, src/rbtree_trigger.c implementing the reclaimed fake k_itimer/rbtree rotation write primitive, and src/uhid_bridge.c implementing a UHID-based kernel address leak and planned kernel R/W bridge. The main exploit structure is phased. Phase 1 creates CLOCK_PROCESS_CPUTIME_ID timers and races timer deletion against a non-leader execve("/system/bin/sh", ["sh","-c","true"]) to leave a freed k_itimer still linked in signal->cpu_timers. Phase 2 attempts heap reclaim of the freed slab and uses crafted rbtree metadata so a subsequent timer insertion triggers rb_set_parent() and performs a controlled 8-byte kernel write. The intended first target is a UHID file object's f_op pointer. Phase 3 uses /dev/uhid plus perf_event_open sampling to leak the kernel address of the UHID file structure, then tries to verify fops redirection and establish a pipe-based physical/kernel read-write bridge. Later phases are intended to bypass KASLR, disable SELinux by writing selinux_state.enforcing = 0, and patch task credentials to init_cred for root. The code is not just a detector: it contains exploit logic, device-specific offsets, reclaim/rotation helpers, and privilege-escalation goals. However, it is not fully complete end-to-end in the provided snapshot. The main exploit reports placeholders for KASLR, SELinux disable, and cred patching until the pipe R/W bridge is working. That makes it more than a PoC trigger but still partially unfinished, best classified as OPERATIONAL rather than fully weaponized.
This repository is a small, focused proof-of-concept for CVE-2026-64560, a Linux kernel use-after-free race in posix CPU timers caused by non-leader exec() interacting with timer deletion/set/rearm paths. The repo contains 5 files: a detailed README, the upstream kernel fix patch, and a poc/ directory with one C source file plus Linux/Android build files. The main executable logic is in poc/cve_2026_64560_poc.c. The PoC is a local race trigger, not a full privilege-escalation exploit. Its core capability is to stress the vulnerable kernel path by running two concurrent activities: (1) timer threads repeatedly create, arm, briefly exercise, and delete CLOCK_PROCESS_CPUTIME_ID timers; and (2) exec threads repeatedly fork child processes where a non-leader pthread calls execve() on /bin/true (Linux) or /system/bin/true (Android). This is specifically designed to hit the window where pid_task() resolves the old thread-group leader while its sighand has just been cleared during de_thread()/__exit_signal(), causing the timer object to be freed while still queued in the process CPU timer rbtree. If the race lands on an unpatched kernel, subsequent timerqueue operations or run_posix_cpu_timers() may dereference the freed k_itimer, producing KASAN use-after-free reports, warnings, panic, or instability. The code includes a --check mode that verifies basic prerequisites by creating a CLOCK_PROCESS_CPUTIME_ID timer, checking the exec target path, and reading /proc/version. There is no network communication, no command-and-control behavior, and no payload for code execution or persistence. The included patch file documents the upstream fix strategy, including timer_lock_sighand() and memory-ordering changes in __exit_signal()/lock_task_sighand().
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability covered by the Miracle Linux kernel package update. Individual technical details and exploit availability are not specified.
A race condition in Linux kernel POSIX CPU timer handling during a non-leader thread's exec() can leave a freed timer object queued, causing use-after-free when subsequent timer operations access it. Related synchronization problems affect timer setting and rearming. The reference assigns a CVSS v3 base score of 7.8, describing local exploitation requiring low privileges with potentially high confidentiality, integrity, and availability impacts. Exploits are reported available.
A vulnerability addressed by the Red Hat Enterprise Linux 9.6 kernel update referenced in RHSA-2026:65708. The content provides no vulnerability-specific technical description.
A use-after-free vulnerability in Linux kernel POSIX CPU timers caused by a race involving non-leader exec().
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.