I just released our kernelCTF VSock 0-day write-up with @_qwerty_po . (exp196/exp197, CVE-2024-50264)
github.com/google/securitβ¦
We made history by being the first to exploit VSock in kernelCTF, expanding its known attack vectors. π₯³
Itβs a pretty *simple* race condition, right?
V4bel
59 posts
Independent Vuln. Researcher / Pwn2Own Berlin 2025, 2026 / Google kernelCTF 0-day / Pwnie Awards 2025
Joined November 2019
- Google kernelCTF LTS/COS 0-day WIN! Successfully exploited an extremely complex race condition 0-day vuln on two instances without using namespaces π work with @_qwerty_po
- @_qwerty_po and I exploited a VSock 1-day in Google kernelCTF back in *February*, securing $71,337 π₯³ (CVE-2025-21756, exp237/exp249) And Iβve just published the write-up: github.com/google/securitβ¦ A kernel developer reviewing a patch for a separate VSock bug I submitted
00:00 - Found a 0-day in the Linux Kernel TCP a while back and finally sharing the details!π¨ New Linux Kernel vulnerability (CVE-2024-27394) discovered & patched by Theori! π blog.theori.io/deep-dive-intoβ¦ Our researcher @v4bel at #Theori identified a critical #UAF vulnerability in TCP-AO caused by a race condition in the #RCU API. Using techniques from the ExpRace paper,
- Our CVE-2024-50264 with @_qwerty_po has won the Best Privilege Escalation category at the 2025 Pwnie Awards. Thank you, @PwnieAwards!!
- CVE-2025-38087: Linux Kernel Traffic Control TAPRIO Use-After-Free This is a 64byte UAF write vuln I discovered for Pwn2Own. However, I couldnβt reliably exploit it due to the extremely narrow race window, so I had no choice but to patch it π₯ git.kernel.org/pub/scm/linux/β¦
- Our CVEβ2024β50264 has been nominated for the Best PE at the Pwnie Awards π«’We are very happy to announce the nominees for the 2025 Pwnie Awards! As a reminder, we will be presenting the winners at DEF CON this year. Saturday the 9th, 10:00AM Main Stage. Hope to see you there! docs.google.com/document/d/1fyβ¦
- Did you know that in Upstream, the conventional βoverwriting modprobe_pathβ technique doesnβt work anymore? So, I developed a new technique that generally triggers modprobe_path. It's a simple ideaβnothing fancy, but pretty useful ππ NEW RESEARCH: We've revived the modprobe_path privilege escalation technique in #Linux kernels. How? Read out blog to find out: blog.theori.io/reviving-the-mβ¦ Remember, we will always find a new way!
- If I ever get a chance, I would like to share my insights on race conditions π€
- Replying to @v4belBTW, This is a variant of CVE-2021-26708: a13xp0p0v.github.io/2021/02/09/CVEβ¦ It was the first vuln analyzed after joining the company two years ago. Back then, I knew vvs still ended up as a dangling ptr even after the vuln was patched, but only recently succeeded in triggering the UAF. π₯²
- Happy New Year! I hope I can grow even more this year π











