"A Guide into Linux Kernel 7.* UAF Exploitation"
(c) Antonius - bluedragonsec.com 2026 - All Rights Reserved
Nicknames : w1sdom, sw0rdm4n, ev1lut10n, d4r3d3v1l, jck.marshall (one time usage), ringlayer, robotsoft, mranton, 黑蝎子, Prof. Robotsoft, Mr. Robot
https://github.com/bluedragonsecurity.
This repository is about Use After Free Exploitation pOc specific to the new slub sheaves architecture in the linux kernel 7.0 on x86_64 architecture.
Everything designed here is specific for linux kernel version 7.0.
For every lab demo (non real life exploit), use vmlinux-7.0.tar.xz !!! For real life exploit, use linux 7.0 !
Please note that some lab exploits here might need more than 1 try,
while some exploits may work in 1 try. I have prepared the vmlinux for testing, you can use the vmlinux.
To test, insmod the lkm then run the exploit (unless the real world exploits). Tested and works good for lubuntu 26 with linux kernel 7.0 (custom build, mitigation level is similar to lubuntu 26 with standard mitigation where kaslr on and kptr_restrict = 2). vmlinux-7.0.tar.xz -> use this one.
For real world exploits, some exploit might need a specific requirements and some of the exploits might need more than 1 try to succeed or might need a long time to succeed.
n.b:
- Some exploits might need to run more than once if failed. - When you have tested some exploits, the next exploit might fails, you need to restart your machine before continue. - For lab source code, you need to compile the lkm with "make" and then "insmod" the .ko before testing the exploit. - To compile the exploit : make
Suggested distro : lubuntu 26 in Qemu.
Linux kernels with default mitigations enabled.
Mitigation level is similar to default ubuntu 26 or lubuntu 26 distro.
kaslr on & kptr_restrict = 2.
HARDENED_USERCOPY enabled
RANDOM_KMALLOC_CACHES enabled
INIT_ON_ALLOC enabled
INIT_ON_FREE off
SMEP, SMAP, KPTI enabled
Linux kernel 7.0 with default mitigations enabled.
Mitigation level is similar to default ubuntu 26 or lubuntu 26 distro.
Standard linux kernel with some UAF(s) patched.
This vmlinux used for every series.
kaslr on, kptr_restrict 2, hardened_usercopy enabled, random_kmalloc_caches enabled, init_on_alloc enabled, init_on_free disabled, smep+smap+kpti enabled
Cross cache UAF exploitation pOc for slub sheaves. Tested on linux kernel 7.0 - lubuntu 26.
Same cache UAF exploitation pOc for slub sheaves. Tested on linux kernel 7.0 - lubuntu 26.
Same cache UAF exploitation p0c using elastic object to build AARW primitives. Tested on linux kernel 7.0 - lubuntu 26.
SheafJack is a novel UAF exploitation technique for slub sheaves. Tested on linux kernel 7.0 & Linux Kernel 7.0-rc1 - lubuntu 26.
Real world exploits - for demonstrating UAF based exploits in linux 7.0. Tested on linux kernel 7.0 - lubuntu 26.
cross_cache_cred
Cross-cache technique : volume overflow, exp tech : cred overwrite, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_dirtycred
Cross-cache technique : volume overflow, exp tech : DirtyCred, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_dirtycred2
Cross-cache technique : complete free, exp tech : DirtyCred, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_dirtycred_deterministic
Cross-cache technique : kratnowl 6-pool, exp tech : DirtyCred, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_dirtypagetable
Cross-cache technique : volume overflow, exp tech : DirtyPageTable, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_dirtypagetable_deterministic
Cross-cache technique : kratnowl 6-pool, exp tech : DirtyPageTable, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_hijack1
Cross-cache technique : volume overflow, exp tech : function pointer overwrite, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_hijack2_no_sheaf
Cross-cache technique : classic (without sheaves), exp tech : function pointer overwrite, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_modprobe
Cross-cache technique : volume overflow, exp tech : modprobe, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_modprobe_socket_deterministic
Cross-cache technique : kratnowl 6-pool, exp tech : modprobe, comm : socket interface ,target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_pagejack_deterministic
Cross-cache technique : kratnowl 6-pool, exp tech : pagejack, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_read_leak_xattr
Cross-cache technique : volume overflow, exp tech : UAF read -> info leak, vehicle :simple_xattr, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_socket
Cross-cache technique : volume overflow, exp tech : modprobe, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_socket2
Cross-cache technique : complete free, exp tech : modprobe, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_cred
same cache UAF reclaim, tech : cred overwrite, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_dirtycred
same cache UAF reclaim, tech : DirtyCred, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_hijack
same cache UAF reclaim, tech : function pointer hijack, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_leak2lpe
same cache UAF reclaim, tech : convert UAF write into information leak, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_modprobe
same cache UAF reclaim, tech : modprobe, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_pagejack
same cache UAF reclaim, tech : pagejack, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_read_leak_seq_file
same cache UAF reclaim, tech : UAF read -> info leak, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_socket
same cache UAF reclaim, socket interface, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_write_leak_user_key
same cache UAF reclaim, tech : UAF write -> info leak, vehicle userkey_payload, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_write_leak_vmemmap
same cache UAF reclaim, tech : UAF write -> info leak, leaks vmemmap, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_write_leak_xattr
same cache UAF reclaim, tech : UAF write -> info leak, vehicle simple_xattr, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_elastic_imu
same cache UAF reclaim, build aarw using io_uring, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_elastic_pipe_cred
same cache UAF reclaim, build aarw using pipe_buffer, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
same_cache_elastic_pipe_modprobe
same cache UAF reclaim, build aarw using pipe_buffer, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_elastic_imu_deterministic
cross cache tech : kratnowl 6-pool, build aarw using io_uring, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_elastic_pipe_deterministic
cross cache tech : kratnowl 6-pool, build aarw using pipe_buffer, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_elastic_imu_siphon
cross cache tech : SheavesSiphon, build aarw using io_uring, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu.
cross_cache_elastic_pipe_siphon
cross cache tech : SheavesSiphon, build aarw using pipe_buffer, target : linux 7.0 (vmlinux-7.0.tar.xz) - lubuntu 26 in qemu
Some proof of concepts (pOc) to demonstrate SheafJack to exploit UAF in linux 7.0.
SheafJack Demo to Exploit a UAF in linux 7.0.
Cross Cache technique : SheavesSiphon
LPE Tech : Sheafjack + deep sheaf poisoning. Tested on linux 7.0 - lubuntu 26
SheafJack Demo to Exploit a UAF in linux 7.0.
Same Cache UAF Reclaim
LPE Tech : Sheafjack + deep sheaf poisoning. Tested on linux 7.0 - lubuntu 26
This is just some proof of concepts to validate the exploitation techniques but everything in AARW directory is still implemented using AARW.
Results : LPE.
Just like the name suggests, this is just for sheafjack testing using arbitrary read and write.
SheafJack - direct objects[] overwrite testing - non UAF, just AARW for testing & validating the exploitation technique.
Result : LPE. Tested on linux 7.0 - lubuntu 26
Improvisation : deep sheaf poisoning
SheafJack - direct objects[] overwrite testing - non UAF, just AARW for testing & validating the exploitation technique.
Result : LPE. Tested on linux 7.0 - lubuntu 26
Improvisation : deep sheaf poisoning
CVE-2026-46215-EXPLOIT
CVE-2026-46215 Linux Kernel UAF Exploit in drm driver, adapted for linux 7.0. Cross Cache Tech : SheavesSiphon
entrybleed.c
kaslr leak via entrybleed
CVE-2026-46215-exploit-linux-7.0-uaf-stable
CVE-2026-46215 Linux Kernel UAF Exploit in drm driver, adapted for linux 7.0. Cross Cache Tech : SheavesSiphon
Should be more stable than previous version ;-p
Scripts for lab research
dragon_sheafwatch.py slab_mon.c sheaf.py sheaf_mon.sh sheaf_dump.py pipe_spray.c