Exploiting HackSys Extreme Vulnerable Driver (HEVD) on Windows 7 x86: a kernel stack buffer overflow using token-stealing shellcode, and privilege escalation via a Write-What-Where overwrite of the HalDispatchTable
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs
Mounting a crafted btrfs image twice causes an rwsem_down_write_slowpath use-after-free because rwsem_owner_flags returns an already freed task_struct pointer.
A setxattr operation after mounting a crafted ext4 image causes a slab-out-of-bounds write in ext4_xattr_set_entry because a large old_size value is used in a memset call.
__btrfs_free_extent in fs/btrfs/extent-tree.c calls btrfs_print_leaf in a certain ENOENT case, leaking potentially sensitive register values to local users through dmesg.
ext4_empty_dir in fs/ext4/namei.c allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can return zero after a crafted ext4 image is mounted.
btrfs_root_node in fs/btrfs/ctree.c allows a NULL pointer dereference because rcu_dereference(root->node) can return zero when a crafted btrfs image is mounted.
A crafted btrfs image triggers a NULL pointer dereference in btrfs_verify_dev_extents because fs_devices->devices is mishandled inside find_device (fs/btrfs/volumes.c) in Linux kernels before 5.1.