Skip to content

0x9000 · Area

Kernel Exploitation

A memory-corruption bug in the kernel is not about a shell — it is about privilege. The attacker already runs code as an unprivileged user; the goal is to turn a kernel bug into root, or to escape a sandbox. This area covers how the kernel represents privilege, the classic privilege-escalation payload, why the kernel's shared address space made ret2usr so easy, and the mitigations — SMEP, SMAP, KASLR, KPTI — that closed each door. Examples target a deliberately vulnerable kernel module in a throwaway VM.

Guides in this area

  1. A kernel memory-corruption bug is about privilege, not a shell. The credential model, the commit_creds(prepare_kernel_cred(0)) payload, and returning cleanly to userspace — in a lab VM.

  2. The kernel once trusted userspace memory, so exploits just pointed kernel execution at a user payload. SMEP and SMAP ended that — and how kernel ROP works around them.

  3. Kernel address randomization, page-table isolation, and the config options that harden a Linux kernel against memory-corruption exploits — what each one stops and how to enable it.

Other areas