Open note Linux Kernel OOB Read/Write Exploitation: Overwriting a Syscall to Root with commit_creds
First successful Linux kernel exploit: OOB read/write in a lab kernel module, syscall overwrite (sys_vmsplice) and commit_creds(prepare_kernel_cred(0)) to uid 0 — full authentic footage.