Linux Kernel Exploitation: Know the Attack Surface
CVE-2022-0847 (Dirty Pipe) let any unprivileged user overwrite read-only files and own root — and it bypassed every modern kernel mitigation. This post walks through mapping the Linux kernel attack surface with real commands, from version enumeration to eBPF exposure, so you know exactly what an attacker sees on your box.
