important · Privilege — Linux
Public RustyTux code turns an ESP-in-TCP race into a controlled kernel write and an attempted root shell.
Affects
The Linux kernel ESP-in-TCP and strparser paths used by standard distribution kernels.
The race rearms timer work after teardown cancellation, reclaims the freed context with controlled user-key data, and uses timer expiry for a controlled 64-bit write aimed at modprobe_path.
Detail and 1 source
The exploit needs build-specific offsets and timing; its published material is CentOS-specific, was not independently reproduced here, and does not establish current upstream patch status.
Chain to watch
Race ESP-in-TCP parsing against teardown→↓Reclaim the freed context with controlled data→↓Turn stale timer execution into a kernel write against modprobe_path→↓Portability beyond the supplied CentOS target and current upstream remediation remain unresolved.
Unverified chainReproduce on current distribution kernels, then identify the fixing commit or confirm continued reachability.