haitam lazaar / lazaarsec
Security & Vulnerability Researcher

Haitam Lazaar

@lazaarsec·Security Researcher·Systems Architect·Rabat, Morocco

Hi, I'm Haitam! I love security research and I actively do bug bounty. I spend my time auditing software, hunting for vulnerabilities across open-source and enterprise targets, exploring memory corruption and Linux kernel internals, and practicing coordinated disclosure.

Disclosed Research SummaryCNA VERIFIED
High Severity (CVSS 7.0–8.8)5
Medium Severity (CVSS 4.8–6.8)8
Unrated / Business Logic2
GNU Core Credits:2 Disclosed
Primary Focus:Ring-0 / C / Web Logic
Disclosure SLA:Coordinated 60-90d
SECURITY RESEARCH & BUG BOUNTY CONTRIBUTIONS
OpenAI
Stripe
Brave Software
BugBase
GNU
GNUOperating System
AUDITED & ISSUED
15
Published CVEs

100% CNA & Vendor validated

SYSTEMS SOFTWARE
2×
GNU libextractor

Stack Overflow & Root PrivEsc

LOW-LEVEL SYSTEMS
Ring-0
Kernel & Packet Hooks

Netfilter, Port Knocking, C

CREDENTIALS
CRTA
Certified Offensive

CWSE · eJPTv2 · CAPT

01 // Technical Proofs & Code Primitives

haitam@lazaarsec:~/research$
// CVE-2026-91752 — GNU libextractor OLE2 Recursive Allocation PrimitiveCVSS 8.7 High · Fixed in GNU v1.16
/* src/plugins/ole2_extractor.c: Unbounded recursion triggers stack allocation exhaustion */
static int parse_sat (struct EXTRACTOR_Context *ec, const unsigned char *sat, size_t sat_size) {
    unsigned int block = read_uint32(sat);

    /* Flaw: Missing recursion depth bound; dynamic stack buffer allocation exhausts frames */
    char buffer[sat_size]; 
    if (block != ENDOFCHAIN && block < sat_size) {
        return parse_sat(ec, sat + (block * SECTOR_SIZE), sat_size);
    }
    return EXTRACTOR_OK;
}
Exploit Lab & PoC:github.com/Haitam-lazaar/libextractor-ole2-rce ↗Advisory: GNU Release Announcement (v1.16)

02 // Research Disciplines & Specializations

AREAS OF EXPERTISE

Vulnerability Research & Bug Hunting

Source code review, capability verification audits, and business logic analysis. Focus on privilege escalation, authentication bypasses, IDORs, and remote execution primitives with responsible upstream disclosure.

Linux Kernel & Low-Level Systems

Kernel module engineering using Netfilter hooks, packet interception via socket buffers (sk_buff), stateful deep packet inspection, and memory-safe boundary testing.

Offensive AI & Autonomous Reasoning

Multi-agent orchestration architectures executing iterative ReAct reasoning loops across 37+ security tools, with directed attack state graphs and parallel hypothesis racing.

High-Assurance Architecture & Systems Security

Enforcing security controls directly at the database and OS layer—implementing Double-Lock validation routines, trigger-based compliance-as-code, and tamper-evident audit ledgers across distributed heterogeneous planes.

03 // Disclosed Vulnerabilities & CVE Registry

Complete Registry (15) →

04 // Engineering & Security Projects

All Projects (6) →
Offensive AI

AlphaStrike: Multi-Agent Offensive Reasoning Framework

Distributed autonomous reasoning framework executing ReAct loops across 37+ integrated security tools with parallel hypothesis racing and structured state persistence.

PythonMulti-AgentReActCTF SolverOffensive Security
Binary ExploitationGitHub ↗

GNU libextractor OLE2 Exploit Harness

Full exploit lab, standalone PoCs, and adjacent-thread-stack bypass of -fstack-clash-protection for CVE-2026-91752 in GNU libextractor.

CBuffer OverflowGNUExploit LabCVE-2026-91752
Privilege EscalationGitHub ↗

GNU libextractor LPE Harness

Local privilege escalation harness demonstrating root code execution via untrusted search paths (LIBEXTRACTOR_PREFIX) in CVE-2026-100310.

CLinux LPEShared Object InjectionGNUCVE-2026-100310
Linux Kernel & Systems

Stateful Firewall (Linux Kernel Module & PHP Backend)

Linux Kernel module utilizing Netfilter hooks for stateful inspection and dynamic GeoIP filtering, port knocking stealth, and a PHP-based web server backend for real-time rule management.

CNetfilterLinux KernelPHPSystems ProgrammingPort Knocking
Database SecurityGitHub ↗

ORION-7: High-Assurance Database Architecture

A secure-by-design SQL Server reference architecture featuring 'Double-Lock' validation logic, trigger-based compliance-as-code, and distributed multi-plane backups.

SQL ServerRBACCompliance-as-CodeDistributed SystemsAudit Trails
Linux Kernel

IP Packet Payload Manipulation Kernel Driver

Kernel-level packet interception module engineered to dynamically inspect, rewrite, and transform IP payloads pre-transmission across the OSI stack.

CLinux KernelOSI StackRaw SocketsPacket Manipulation

05 // Certifications & Credentials

VERIFIED

Contact & Responsible Disclosure

For collaboration, recruitment inquiries, or encrypted vulnerability reports, reach out directly via email or learn more about my background.