Skip to main content
Mallory
Back to stories
proof-of-concept-releaseendpoint-software-vulnerabilityopen-source-dependency-vulnerability

Google security-research repo adds kernelCTF exploit material for Linux kernel CVEs

Updated 3d agoFirst seen Apr 11, 202610 sources

Google's security-research repository received kernelCTF-related pull requests tied to Linux kernel vulnerabilities including CVE-2024-26582, CVE-2026-23209, and a reference to CVE-2026-23392. The updates were submitted through GitHub pull requests and include repeated revisions to mitigation material, writeups, and proof-of-concept content, with commit history showing iterative changes such as "final," "update writeup," and "update pocs." One pull request associated with CVE-2026-23209 also references files named original.tar.gz and exploit.md, indicating publication of source material and exploit documentation in the repository.

The available records do not provide technical specifics on exploitation, affected distributions, or patch guidance, but they show active disclosure and documentation work around kernelCTF targets in Google's public research repository. For defenders, the appearance of exploit notes and PoC-related updates in a widely watched security-research project is a signal to track the cited CVEs closely, validate kernel exposure, and review vendor advisories and mitigation status for impacted Linux environments.

Share:
Google security-research repo adds kernelCTF exploit material for Linux kernel CVEs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the earliest known activity through the most recent confirmed update.

9 EVENTS
Apr 11, 20261mo ago

KernelCTF mitigation work for CVE-2024-26582 is added and updated

A Google security-research pull request history shows multiple commits adding and revising a kernelCTF mitigation for CVE-2024-26582, followed by updates labeled final, writeup, and PoCs. The material indicates ongoing security research and documentation work rather than a newly described incident.

Apr 22, 202626d ago

kernelCTF repository adds CVE-2026-23209 source material and exploit documentation

A later Google security-research pull request adds files including original.tar.gz and exploit.md for CVE-2026-23209 in the kernelCTF repository. This reflects publication of source material and exploit documentation for the vulnerability.

kernelCTF repository adds CVE-2026-23392_cos exploit materials

A Google security-research pull request titled "Add kernelCTF CVE-2026-23392_cos" was published, indicating repository publication of materials for CVE-2026-23392_cos, including updates to original metadata and an exploit.cpp file. The reference reflects disclosure of exploit-related source material rather than a newly reported victim incident.

Add kernelCTF CVE-2026-23392_cos by NLQuy · Pull Request #369 · google/security-research · GitHub
Apr 27, 202621d ago

kernelCTF repository adds CVE-2026-23351_cos exploit materials

A Google security-research pull request published materials for CVE-2026-23351_cos, describing an nft_set_pipapo garbage-collection use-after-free affecting Container-Optimized OS build cos-121-18867.381.30. The discussion also documented exploitation details and branch updates, including CI fixes and correction of the nft_immediate_eval offset for the targeted COS build.

kernelctf: CVE-2026-23351_cos by 11X0r · Pull Request #371 · google/security-research · GitHub
May 6, 202612d ago

kernelCTF repository adds CVE-2026-23271_lts exploit materials

A Google security-research pull request published kernelCTF materials for CVE-2026-23271_lts, including commits that renamed the original exploit and updated the exploit code and Makefile. The reference indicates repository publication of exploit-related source material rather than a newly disclosed victim or incident.

Add kernelCTF CVE-2026-23271_lts by simond67 · Pull Request #379 · google/security-research · GitHub
May 11, 20267d ago

kernelCTF repository adds CVE-2026-43074_lts exploit materials

A Google security-research pull request titled "Add kernelCTF CVE-2026-43074_lts" was published, indicating repository publication of materials for CVE-2026-43074_lts. The available fragment references an LTS submission, a commit identifier, and verification activity, but provides limited technical detail beyond the addition of exploit-related source material.

Add kernelCTF CVE-2026-43074_lts by 2045castor · Pull Request #380 · google/security-research · GitHub
May 13, 20265d ago

kernelCTF repository adds CVE-2026-23394_lts_cos exploit materials

A Google security-research pull request titled "Add kernelCTF CVE-2026-23394_lts_cos" was published, indicating repository publication of materials for CVE-2026-23394_lts_cos. The available fragment mentions commit identifiers and a fix for build warnings, but provides limited technical detail beyond the addition of exploit-related source material.

Add kernelCTF CVE-2026-23394_lts_cos by sysroot314 · Pull Request #381 · google/security-research · GitHub

kernelCTF repository adds CVE-2025-40019 mitigation-v4-6.12 exploit materials

A Google security-research pull request published kernelCTF exploit materials for CVE-2025-40019 targeting mitigation-v4-6.12, described as a 1-day port of the published essiv ssize-underflow technique. The submission states the exploit captured the flag live as exp521 on 2026-05-13 and includes updated offsets, embedded crypto code to remove an OpenSSL dependency, and schema-compliant metadata changes.

kernelCTF exp521: CVE-2025-40019 essiv on mitigation-v4-6.12 by AshmitSh4rma · Pull Request #382 · google/security-research · GitHub
May 15, 20263d ago

kernelCTF repository adds CVE-2026-43456_lts_cos_mitigation materials

A Google security-research pull request titled "Add kernelCTF CVE-2026-43456_lts_cos_mitigation" was published, indicating repository activity for CVE-2026-43456 with multiple verified revisions. The available fragment provides little technical detail beyond code-review and repository update workflow, but it reflects publication of new kernelCTF-related source material.

Add kernelCTF CVE-2026-43456_lts_cos_mitigation by rqdaA · Pull Request #383 · google/security-research · GitHub
SOURCE COVERAGE

Sources

10 references tracked. Mallory keeps watching after this page renders.

10 SOURCESView all
Google Security Research Pull RequestsAdvisories
May 15, 2026

Add kernelCTF CVE-2026-43456_lts_cos_mitigation by rqdaA · Pull Request #383 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
May 13, 2026

Add kernelCTF CVE-2026-23394_lts_cos by sysroot314 · Pull Request #381 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
May 13, 2026

kernelCTF exp521: CVE-2025-40019 essiv on mitigation-v4-6.12 by AshmitSh4rma · Pull Request #382 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
May 11, 2026

Add kernelCTF CVE-2026-43074_lts by 2045castor · Pull Request #380 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
May 6, 2026

Add kernelCTF CVE-2026-23271_lts by simond67 · Pull Request #379 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
Apr 27, 2026

kernelctf: CVE-2026-23351_cos by 11X0r · Pull Request #371 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
Apr 23, 2026

Add kernelCTF CVE-2026-23392_cos by NLQuy · Pull Request #370 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
Apr 22, 2026

Add kernelCTF CVE-2026-23392_cos by NLQuy · Pull Request #369 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
Apr 22, 2026

kernelCTF: add CVE-2026-23209_cos by 4ab48b3f1ded2472 · Pull Request #368 · google/security-research · GitHub

github.com

Open source
Google Security Research Pull RequestsAdvisories
Apr 11, 2026

CVE 2026 23392 cos by NLQuy · Pull Request #363 · google/security-research · GitHub

github.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.