linneman
labs
building
breaking
observing
content
···
verified
home
/ privilege-escalation
Privilege-Escalation
2026.08.31
A Newline to Root: CVE-2026-19624
An unprivileged D-Bus call writes a root-parsed VPN config value. One newline, root code execution, confinement escape.
2026.08.12
Confined Root Is Still Root
A compromised root daemon can’t change its own SELinux domain. It doesn’t need to - it recruits something already unconfined.
2026.08.05
Pi-hole: root with extra steps
Five ways to compromise Pi-hole: two web session config-to-code paths and three local privilege escalations
2026.07.20
Measuring the Blast Radius of a Root Daemon
The real confinement of a root daemon is the intersection of SELinux policy, systemd sandboxing, Linux capabilities, and DAC.