logo

PoC Exploit Code Publicly Released: New “PinTheft” Linux Flaw Overwrites Page Cache for Instant Root

ID: 226a754b-1f64-5597-ba68-c8926efabebd

STIX ID: report--226a754b-1f64-5597-ba68-c8926efabebd

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

A technical report on “PinTheft,” a Linux local privilege escalation that abuses a double-free in the RDS zerocopy path together with io_uring fixed buffers to steal FOLL_PIN references, force page-cache reallocation of a SUID binary, overwrite its cached code with a payload, and obtain a root shell; the document provides PoC steps, notes limited default exposure (RDS typically disabled except on some distros), and recommends blocking the rds/rds_tcp modules and rebooting or flushing caches after testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.