ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 35
AI summary · glm-5.3-flash

The Linux kernel net scheduler packet classifier has a use-after-free (CVSS 7.8) allowing local attackers to escalate privileges from low-privileged code.

ZDI-26-609 describes a use-after-free vulnerability in the Linux kernel's network scheduler packet classifier, with a CVSS score of 7.8. An attacker must first be able to execute low-privileged code on the target system before escalating privileges. The advisory text does not list an assigned CVE identifier.

  • Use-after-free in packet classifier allows local privilege escalation
  • Requires ability to run low-privileged code on the target first
  • CVSS 7.8; no CVE identifier given in the advisory text
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

This source does not provide full text. Read it at zerodayinitiative.com.