home / channels / kernel

kernel / exploitation

dirty frag · arm64 · apparmor profile hops
2026.05.13Two Hops and a Shell on UbuntuUbuntu’s userns AppArmor patch checks a pointer, not a property. Two profile hops chain a confined process to host root.2026.05.11Porting Dirty Frag to arm64On aarch64 the rxrpc path oopses and AppArmor blocks the exploit over SSH. A complain-mode profile transition slips it through.
view all posts →