Welcome

Welcome to my personal website. I’m Ernesto Martínez García, a 26 years old computer enthusiast from Spain, currently living in Austria. My dedication is Computer Security in its low level aspect, although I also enjoy managing headless Linux systems, hardening, programming and automation.

Currently doing a PhD in Information Security at the Institute of Information Security (ISEC, former IAIK) in the Secure Systems group and under the supervision of Stefan Mangard and Lukas Maar. I am also a member of the Capture The Flag team LosFuzzys, where I currently take the role of team captain. I also play with the merger team KuK Hofhackerei.

Here you’ll find my novice technical writings about security, software and linux systems. You can also visit my Bookmarks to see if you find something interesting through a chaotic collection of links I’ve been arranging for years.

Also please don’t hesitate to contact me if you want to, I’d be more than happy to respond. You can do so via old fashioned plaintext emails to my email address. Usually I check for new email often, although my response would depend on the workload.

Education

PhD Student in Information Security

Graz University of Technology
Ongoing

Masters in Computer Science

Graz University of Technology
2022–2025 · 120 ECTS
Graduated with Distinction

Bachelor in Computer Engineering

University of Alicante
2018–2022 · 240 ECTS
Graduated with Distinction · High Academic Performance Programme

Publications

LeakyTree: Cross-VM Bit-by-Bit Deduplicated Page Leakage via Linux Kernel Samepage Merging Internals

Ernesto Martínez García, Lukas Maar, Martin Unterguggenberger, Mathias Oberhuber, Stefan Mangard
Upcoming · ACM Conference on Computer and Communications Security (CCS) 2026

Presentations

Security Implications of Kernel Electric Fence

Linux Security Summit Europe · Linux Foundation
Upcoming · Prague, Czechia · 8 October 2026

Introduction to Linux Kernel Exploitation

Graz University of Technology · Summer Semester 2026

Secure Boot Overview

Graz University of Technology · 23 June 2023

Pseudo Random Number Generator Presentation

Graz University of Technology · 22 June 2023

Teaching

Secure Software Development

Lecturer
Graz University of Technology · 2025–present

Writings

GlacierCTF2025 - Flip Flip Hooray!

A kernel pwn challenge I authored for GlacierCTF 2025, where you have one single bitflip to pwn the arm64 KASLR-enabled kernel. The solution makes use of the fact that the physmap on arm64 is not randomized to flip physical memory, achieving arbitrary flips to escalate to an unlimited AAW.

GlacierCTF2025 - Typst Lotto

Typst Lotto is a CTF challenge I authored for GlacierCTF 2025. An attacker must side-channel the Typst memoization engine to leak digits that were previously written in the document, but deleted afterwards.

GlacierCTF2024 - ksmaze

A GlacierCTF 2024 challenge I authored for GlacierCTF 2024. Players must reverse-engineer and diff the provided Linux kernel image to find a subtle change in the copy-on-write KSM mechanism to solve an impossible puzzle.

GlacierCTF2024 - Schrödinger Compiler

Authored CTF challenge from GlacierCTF 2024. Players submit a C++ file, gets compiled on our machines with no kind of output, and does not run the binary. This allows for leaking files from the filesystem via a timing side-channel attack on C++ static evaluations.

Others