« All posts

A Linux Kernel 0-day Journey: From Limited UAF to Physical Memory R/W

A Linux Kernel 0-day vulnerability was found in Red Hat's network scheduler. Learn about its exploitation strategy and significance.

This article discusses a recently found Linux Kernel 0-day vulnerability exploited for Pwn2own 2026. The bug, located in Red Hat's network scheduler subsystem, remained unpatched for 2.5 years. Its exploitation strategy involved transforming an initially limited slab UAF into a page UAF, ultimately allowing for physical memory read and write operations.