I just wrote my first exploit for a real-world kernel vulnerability. It is about CVE-2022-24122. I did some cross-cache UAF attack to corrupt modprobe_path. You need to know the kernel base to prevent an oops during the exploit process. Reliability isn't great ๐ maybe like 5%
I recently played GreyCTF Finals with @ARESxCTF. Me and @bitfriends_ managed to blood a kpwn challenge by finding some new triggers for modprobe_path.
You can find the blogpost + writeup here:
https://t.co/kQM0IVcly3
Thanks @NUSGreyhats for hosting a great no-LLM CTF!
With a slight delay, our team is proud to share that ARESx has won first place on m0leCon 2026 finals ๐๐ฎ๐น
thanks to @pwnthem0le for the great event and hope to see everyone next year! ๐ฅณ
With a slight delay we are proud to announce ARESx won Securinets finals 2025 in Tunisia ๐๏ธ๐๏ธ
Thank you @SecuriNets for hosting the ctf, here are some pics from the trip!!
For the weekend ARESx had the honor of attending mimic ctf 2025
Big thank you to @XCTF_League for organizing the event ๐๐
Hope to see you all next year!
We are proud to announce, ARESx placed 3rd on m0leCon CTF!!! ๐๐ฎ๐น
Thank you for hosting! @pwnthem0le
Looking forward to see everyone in Turin!!
#pwnthem0le
We are happy to announce that ARESx as part of @malta_ctf placed 8th in the #DEFCON CTF finals!
It was very nice meeting everyone and competing against some of the best teams in the world!
Huge thanks to @plainshift for the support given to the team!
Photo dump:
We got 8th place in defcon!
Working together onsite was great as always, also really enjoyed meeting our friends in the other teams ๐.
Thanks @Nautilus_CTF for hosting <3
ZDI-CAN-27262 is a Linux kernel 0-day I reported recently that allows unprivileged users to escalate privileges to root.
The vulnerability is a race condition leading to a UAF in the kmalloc-196 cache. It was introduced in v4.2-rc1 and has been present in the kernel for 10 years.
Happy new year! Our 2024 Recap is here:
- 6 CTFs won, including 2 DEFCON Prequalifiers
- 1st meetup of ~80 members @ DEFCON
- 19.5k mvms sent on Discord
- Rank #2 global on CTFtime
We're incredibly proud of all of our members and look forward to seeing everyone again next year!
1st place at HITCON CTF 2024 Finals!
Many thanks to HIT for hosting an amazing event, and weโre all very excited to see everyone again at DEF CON CTF next year!
I just wrote my first exploit for a real-world kernel vulnerability. It is about CVE-2022-24122. I did some cross-cache UAF attack to corrupt modprobe_path. You need to know the kernel base to prevent an oops during the exploit process. Reliability isn't great ๐ maybe like 5%