linneman labs
content
···
✓
verified
home
/ channels / kernel
kernel / exploitation
dirty frag · arm64 · apparmor profile hops
2026.05.13
Two Hops and a Shell on Ubuntu
Ubuntu’s userns AppArmor patch checks a pointer, not a property. Two profile hops chain a confined process to host root.
2026.05.11
Porting Dirty Frag to arm64
On aarch64 the rxrpc path oopses and AppArmor blocks the exploit over SSH. A complain-mode profile transition slips it through.
view all posts →