CVE Tools
Back to feed
Research LD_PRELOAD privilege-escalation BEURK Linux

LD_PRELOAD Reloaded. Закрепляемся в Linux — от перехвата функций до руткита BEURK

Хакер (xakep.ru)·By Моисей Сутулин··5 min read
CVE Tools coverage

A new technical article details the capabilities of the LD_PRELOAD mechanism in Linux, demonstrating how attackers can use it for advanced persistence techniques such as userland rootkits. The post covers practical examples using the BEURK rootkit and explains how LD_PRELOAD allows intercepting standard library functions. A key example is the exploitation of CVE-2025-32463">CVE-2025-32463 in sudo to bypass restrictions normally placed on LD_PRELOAD. The research highlights potential risks and detection methods for administrators concerned about stealthy malicious behavior.