$ cat writeup.md…
$ cat writeup.md…
UIUCTF 2026
Task: kCTF Ubuntu 26.04 LTS VM (kernel 7.0.0-29-generic) with hardened boot params, AppArmor userns restriction, locked account — become root and read /root/flag.txt. Solution: CVE-2026-52910 bpf_prog_pack JIT reclaim UAF via SO_REUSEPORT detach race, timerfd epoll IRQ amplification for race window, rdmsr KASLR bypass from JIT kernel context, modprobe_path overwrite for root code execution.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar