<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Kernel Exploitation on Netacoding | Cybersecurity, Assembly &amp; Network Research</title>
    <link>https://netacoding.com/categories/kernel-exploitation/</link>
    <description>Recent content in Kernel Exploitation on Netacoding | Cybersecurity, Assembly &amp; Network Research</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 29 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://netacoding.com/categories/kernel-exploitation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Boundary Mathematics: Weaponizing PAGE_SHIFT Arithmetic via FUSE — Part 3</title>
      <link>https://netacoding.com/posts/fuse-boundary-mathematics-pgoff-overflow/</link>
      <pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://netacoding.com/posts/fuse-boundary-mathematics-pgoff-overflow/</guid>
      <description>How a FUSE daemon&amp;#39;s poisoned attr.size feeds integer overflows into pgoff_t arithmetic across mm/filemap.c, mm/mmap.c, and the Maple Tree VMA walker — yielding XArray OOB walks, infinite kworker loops, and cross-VMA write primitives.</description>
    </item>
    <item>
      <title>Lying to the Kernel: FUSE Trust Boundary &amp; Size Desync as a VFS Attack Surface — Part 1</title>
      <link>https://netacoding.com/posts/fuse-trust-boundary-and-size-desync/</link>
      <pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://netacoding.com/posts/fuse-trust-boundary-and-size-desync/</guid>
      <description>Deep technical dissection of the FUSE userspace-kernel trust inversion and how a malicious daemon weaponizes attr.size lies into kernel heap overflows via kernel_read_file() and virtio-fs.</description>
    </item>
    <item>
      <title>The Async Abort Race: drop_caches × SIGKILL × fuse_abort_conn = Double Put — Part 4 &amp; Conclusion</title>
      <link>https://netacoding.com/posts/fuse-async-abort-race-double-put/</link>
      <pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://netacoding.com/posts/fuse-async-abort-race-double-put/</guid>
      <description>The crown jewel of FUSE exploitation: a three-actor race between a stalled fuse_req, /proc/sys/vm/drop_caches inode eviction, and delayed fuse_abort_conn teardown — yielding DirtyCred-class double-puts and UAF reads on freed slab memory.</description>
    </item>
  </channel>
</rss>
