Vibeleaderboard
Index / tool
Visit github.com
Category
Cybersecurity
Rank
No. 2364Tools index
Type
TOOL
GitHub
12 stars
Date

About

RustyTux is a Linux kernel local-privilege-escalation exploit for a publicly disclosed strparser race condition, in which an active TCP receive parser overlaps with socket teardown and rearms strparser's timer work after it was supposedly canceled, producing an ESP-in-TCP use-after-free. The exploit derives the randomized kernel base via an x86 prefetch timing side channel, wins the teardown race, and reclaims the freed espintcp context with attacker-controlled user-key payloads; as of September 2026 it targets standard kernels in CentOS Stream 9 and Ubuntu 26.04 LTS and is reachable by an unprivileged local user, though timing must be tuned per environment.

Tags

linux-kernelexploitprivilege-escalationrace-condition

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.