home / channels / vuln-research

vulnerabilities / research

selinux · systemd confinement · sandbox escapes · pi-hole 2 RCE, 3 LPE (root) · nm-l2tp LPE (root) · fprintd bypass LPE (root) ·soon · bluez LPE (root) ·soon · ceph cluster-wide data leak ·soon · open-iscsi socket LPE (root) ·soon
2026.09.02NetworkManager-l2tp: A Newline to RootAn unprivileged D-Bus call writes a root-parsed VPN config value. One newline, root code execution, confinement escape.2026.08.12Confined Root Is Still RootA compromised root daemon can’t change its own SELinux domain. It doesn’t need to - it recruits something already unconfined.2026.08.05Pi-hole: root with extra stepsNine ways to compromise Pi-hole: five paths from a web session to code-exec, three LPEs to root-exec, one file-disclosure2026.07.20Measuring the Blast Radius of a Root DaemonThe real confinement of a root daemon is the intersection of SELinux policy, systemd sandboxing, Linux capabilities, and DAC.
view all posts →