Research.

Notes from the lab, and the public record of what our engine has broken. All of it verifiable.

Featured Jul 20, 2026 · 8 min read

The Bugs Fuzzers Can't See

Automated kernel bug-finding has converged on one technique: fuzzing. It has a ceiling built in. We do it differently. We read the source and reason about it, to find the bug classes a fuzzer is structurally blind to.

Read note

Notes from the lab

All notes →

The public track record.

Every vulnerability we've disclosed. Each one links to its public record.

43
vulnerabilities disclosed
9
merged into the Linux kernel
11
public CVEs & advisories
16
companies reviewed the fixes

Reviewed by engineers at

Google Meta IBM NVIDIA Intel Red Hat AMD Qualcomm Cisco Arm Broadcom Ericsson NXP SUSE Citrix Alibaba
Arbitrary code execution via crafted expressions
GHSA-8gq3-vp5j-2grp
Cross-tenant agent API-token minting
GHSA-47wq-cj9q-wpmp
Slab use-after-free in AEAD decrypt completion
CVE-2026-63801
Memory corruption in 802.15.4 llsec decrypt
CVE-2026-63831
Use-after-free in MACsec offload RX
Merged upstream
Use-after-free in LE Audio CIG/CIS setup
CVE-2026-63944
Double-completion / double-free on resume
Merged upstream
Certificate-chain validation bypass
CVE-2026-33896
Denial of service via unbounded recursion
CVE-2026-44289
Use-after-free of metadata_dst in eswitch repr release
In review
RX buffer overflow on zero-length serial frames
In review
Stack buffer overflow in NFC digital
Merged upstream
OOB from unvalidated ioctl buffer sizes
In review
OOB write in command-response copy
In review
Use-after-free on inrange_timer at teardown
In review
Stale pen_input pointer on partial registration
In review
Use-after-free of in-use VP9 frames
In review
Resource-exhaustion denial of service
CVE-2026-52746
Heap out-of-bounds write in ciscodump extcap
CVE-2026-15164
Template injection → arbitrary file read
CVE-2026-33130
Stack overflow via deeply nested collections
CVE-2026-33532
OOB read of unset MAC header on raw TX
In review
Missing CAP_NET_ADMIN check on changelink
In review
NULL-deref DoS paths via AMDXDNA_EXEC_CMD
Merged upstream
OOB read on frames shorter than the auth tag
In review
OOB read from unvalidated control-message length
In review
Out-of-bounds read in LLCP SNL TLV parser
Merged upstream
OOB read on LLCP PDUs shorter than the header
In review
Integer overflow in frame-size calculation
In review
OOB read from unvalidated directory-index counts
Queued upstream
OOB read from assoc length underflow
In review
OOB read from unvalidated AV1 frame indices
In review
OOB in NPU cmdstream tile validation
In review
OOB read in firmware-request handler
In review
OOB read in HT/VHT capability IE parsing
In review
OOB read in pairwise-cipher OUI walk
In review
NULL deref on HT-cap without HT-oper
In review
ECRED deferred-recvmsg race → list corruption
In review
OOB read in LLCP connect_sn TLV walk
In review
OOB read in st21nfca ATR_REQ handling
In review
OOB read in port100 frame length handling
In review
OOB read in fdp device-supplied read size
In review
Reachable WARN DoS in rsa-pkcs1pad empty digest
In review

Updated continuously. Embargoed findings appear once they're fixed.

Work with the lab.

You build critical software, or you break it for a living. Let's talk.