Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

module

Linux Kernel UDP Fragmentation Offset (UFO) Privilege Escalation

Disclosed
Aug 10, 2017

Description

This module attempts to gain root privileges on Linux systems by abusing
UDP Fragmentation Offload (UFO).

This exploit targets only systems using Ubuntu (Trusty / Xenial) kernels
4.4.0-21 based on Ubuntu, such as Linux Mint.

The target system must have unprivileged user namespaces enabled
and SMAP disabled.

Bypasses for SMEP and KASLR are included. Failed exploitation
may crash the kernel.

This module has been tested successfully on various Ubuntu and Linux
Mint systems, including:

Ubuntu 14.04.5 4.4.0-31-generic x64 Desktop;
Ubuntu 16.04 4.8.0-53-generic;
Linux Mint 17.3 4.4.0-89-generic;
Linux Mint 18 4.8.0-58-generic
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.