Security research, advisories, and proof-of-concept code from LinnemanLabs.
Links to write-ups, disclosures, and reproducible PoCs.
| Project | Findings / Techniques | CVEs | Result | Write-up | PoC |
|---|---|---|---|---|---|
| bluez | ? | ? | LPE to root | Coordinating Post-Embargo | Withheld |
| nm-l2tp | 1 | 1 | LPE to root | soon | soon |
| open-iscsi | ? | ? | Authorization bypass on control socket | soon | soon |
| open-isns | ? | ? | ? | Embargo | Withheld |
| pi-hole | 5 | Pending | 2 authenticated-RCE, 2 root LPE, 1 file disclosure | Pi-hole: root with extra steps | Available |
| ceph | 6 | Pending | Cross-tenant and cross-pool file disclosure | Embargo | Withheld |
| fprintd | 17 | 1 | Fingerprint bypass, LPE to root | soon | soon |
| KWin / Mutter | 2 | - | Unprivileged keylogging via compositor accessibility D-Bus | Hello, my name is Orca | Available |
| SELinux / systemd | 12 techniques | - | Confined root -> unconfined root | Confined Root Is Still Root | Available |
These tools are intended for authorized security testing and research only.
Unauthorized use against systems you do not own or have explicit permission to test is illegal.
MIT. Copy it, steal it, modify it, learn from it, share your improvements with me. Or don't. It's code, do what you want with it.