Research.

What we've broken, and how.

Notes from the lab

The public track record.

Every vulnerability we've disclosed. Each one links to its public record.

Reviewed by engineers at

Google Meta IBM NVIDIA Intel Red Hat AMD Qualcomm Cisco Arm Broadcom Ericsson NXP SUSE Citrix Alibaba
Arbitrary code execution via crafted expressions
GHSA-8gq3-vp5j-2grp
Cross-tenant agent API-token minting
GHSA-47wq-cj9q-wpmp
Slab use-after-free in AEAD decrypt completion
CVE-2026-63801
Memory corruption in 802.15.4 llsec decrypt
CVE-2026-63831
Use-after-free in MACsec offload RX
Merged upstream
Use-after-free of metadata_dst in eswitch repr release
Queued upstream
Resource-exhaustion denial of service
CVE-2026-52746
Use-after-free in LE Audio CIG/CIS setup
CVE-2026-63944
RX buffer overflow on zero-length serial frames
Merged upstream, stable-backported
Double-completion / double-free on resume
Merged upstream
Certificate-chain validation bypass
CVE-2026-33896
Denial of service via unbounded recursion
CVE-2026-44289
Stack buffer overflow in NFC digital
Queued upstream
OOB from unvalidated ioctl buffer sizes
In review
Use-after-free on inrange_timer at teardown
In review
Stale pen_input pointer on partial registration
In review
Use-after-free of in-use VP9 frames
In review
Missing CAP_NET_ADMIN check on changelink
Merged upstream, stable-backported
OOB read on frames shorter than the auth tag
Merged upstream, stable-backported
Heap out-of-bounds write in ciscodump extcap
CVE-2026-15164
Template injection → arbitrary file read
CVE-2026-33130
Stack overflow via deeply nested collections
CVE-2026-33532
OOB read of unset MAC header on raw TX
In review
NULL-deref DoS paths via AMDXDNA_EXEC_CMD
Merged upstream
OOB read from assoc length underflow
Queued upstream
NULL deref on HT-cap without HT-oper in TDLS
Merged upstream
Out-of-bounds read in LLCP SNL TLV parser
Queued upstream
OOB read on LLCP PDUs shorter than the header
In review
Integer overflow in frame-size calculation
In review
OOB read from unvalidated directory-index counts
Queued upstream
OOB read from unvalidated AV1 frame indices
In review
OOB in NPU cmdstream tile validation
In review
OOB read in firmware-request handler
In review
OOB read in HT/VHT capability IE parsing
In review
OOB read in pairwise-cipher OUI walk
In review
ECRED deferred-recvmsg race → list corruption
In review
OOB read in LLCP connect_sn TLV walk
In review
OOB read in st21nfca ATR_REQ handling
In review
OOB read in port100 frame length handling
In review
Reachable WARN DoS in rsa-pkcs1pad empty digest
Queued upstream

Updated continuously. Embargoed findings appear once they're fixed.

Work with the lab.

You build critical software, or you break it for a living. Let's talk.