ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 22
AI summary · glm-5.3-flash

ZDI disclosed a race condition (CVSS 7.5) in the Linux kernel net scheduler enabling local privilege escalation; no CVE assigned in the advisory text.

ZDI advisory ZDI-26-568 describes a race condition in the Linux kernel's net scheduler that allows local attackers to escalate privileges on affected installations. Exploitation requires the attacker to first execute high-privileged code on the target system. ZDI assigned a CVSS rating of 7.5; no CVE identifier is listed in the advisory text.

  • Race condition in Linux kernel net scheduler allows local privilege escalation.
  • Requires prior high-privileged code execution on the target.
  • CVSS 7.5; published as ZDI-26-568 without a listed CVE id.
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

This source does not provide full text. Read it at zerodayinitiative.com.