Skip to finding
important · Privilege — Linux

Public RustyTux code turns an ESP-in-TCP race into a controlled kernel write and an attempted root shell.

Affects

The Linux kernel ESP-in-TCP and strparser paths used by standard distribution kernels.

The race rearms timer work after teardown cancellation, reclaims the freed context with controlled user-key data, and uses timer expiry for a controlled 64-bit write aimed at modprobe_path.

Detail and 1 source

The exploit needs build-specific offsets and timing; its published material is CentOS-specific, was not independently reproduced here, and does not establish current upstream patch status.

Chain to watch
Race ESP-in-TCP parsing against teardown→↓Reclaim the freed context with controlled data→↓Turn stale timer execution into a kernel write against modprobe_path→↓Portability beyond the supplied CentOS target and current upstream remediation remain unresolved.
Unverified chainReproduce on current distribution kernels, then identify the fixing commit or confirm continued reachability.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026