Conducted 𝗼𝗳𝗳𝗲𝗻𝘀𝗶𝘃𝗲 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵 on the Linux kernel's 𝗲𝗕𝗣𝗙 (extended Berkeley Packet Filter) verifier, the security gatekeeper (~20,000 lines of code) that statically analyses every 𝗲𝗕𝗣𝗙 𝗽𝗿𝗼𝗴𝗿𝗮𝗺 before allowing execution in ring 0. The project built on a prior team's theoretical vulnerability assessment (𝗜𝗦𝗢-𝗜𝗘𝗖 𝗧𝗦 𝟭𝟳𝟵𝟲𝟭-𝟮𝟬𝟭𝟯 𝗖 𝗦𝗲𝗰𝘂𝗿𝗲 𝗖𝗼𝗱𝗶𝗻𝗴 𝗦𝘁𝗮𝗻𝗱𝗮𝗿𝗱), which had identified ~60 vulnerability candidates in the 𝗫𝗗𝗣 𝗦𝘆𝗻𝗣𝗿𝗼𝘅𝘆 kernel implementation and classified 9 as exploitable and 12 as having limited exploitability after passing the verifier unchecked. 𝗠𝘆 𝗰𝗼𝗻𝘁𝗿𝗶𝗯𝘂𝘁𝗶𝗼𝗻: bridging the gap from theory to working exploits. Analysed verifier logic bugs across three exploitation primitive classes, 𝗢𝘂𝘁-𝗼𝗳-𝗕𝗼𝘂𝗻𝗱𝘀 𝗥𝗲𝗮𝗱 (OOB-R), 𝗢𝘂𝘁-𝗼𝗳-𝗕𝗼𝘂𝗻𝗱𝘀 𝗪𝗿𝗶𝘁𝗲 (OOB-W), and 𝗧𝘆𝗽𝗲 𝗖𝗼𝗻𝗳𝘂𝘀𝗶𝗼𝗻, with demonstrated paths to arbitrary kernel memory access and Local Privilege Escalation (LPE) to root. 𝗠𝗲𝘁𝗵𝗼𝗱𝗼𝗹𝗼𝗴𝘆: Multi-stage analysis pipeline: 𝗖 𝘀𝗼𝘂𝗿𝗰𝗲 →𝗲𝗕𝗣𝗙 𝗯𝘆𝘁𝗲𝗰𝗼𝗱𝗲 (llvm-objdump -d) → 𝘁𝗿𝗮𝗻𝘀𝗹𝗮𝘁𝗲𝗱 𝗶𝗻𝘀𝘁𝗿𝘂𝗰𝘁𝗶𝗼𝗻𝘀 (bpftool prog dump xlated) → 𝗿𝘂𝗻𝘁𝗶𝗺𝗲 𝘁𝗿𝗮𝗰𝗲𝘀 (GDB over QEMU). Kernel emulation on Linux LTS 6.8 using 𝗤𝗘𝗠𝗨/𝗞𝗩𝗠 with custom cloud-init provisioned 𝗨𝗯𝘂𝗻𝘁𝘂 𝟮𝟰.𝟬𝟰 𝗩𝗠𝘀 Vulnerability injection via 𝗴𝗶𝘁 𝗮𝗽𝗽𝗹𝘆 𝗽𝗮𝘁𝗰𝗵𝗲𝘀s into xdp_synproxy_kern.c (real Linux kernel selftests code) Full client-server test topology simulating 𝗿𝗲𝗮𝗹 𝗻𝗲𝘁𝘄𝗼𝗿𝗸-𝗹𝗲𝘃𝗲𝗹 𝗮𝘁𝘁𝗮𝗰𝗸 𝘃𝗲𝗰𝘁𝗼𝗿𝘀 𝘃𝗶𝗮 𝗫𝗗𝗣. 𝗥𝗲𝘀𝘂𝗹𝘁𝘀: 5 confirmed exploitable vulnerabilities, with functional 𝗽𝗿𝗼𝗼𝗳-𝗼𝗳-𝗰𝗼𝗻𝗰𝗲𝗽𝘁 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝘀 demonstrating verifier logic bypass and kernel privilege escalation paths.