ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

lowAdvisoryimportance 15
AI summary · glm-5.3-flash

ZDI publishes ZDI-26-572, a CVSS 7.5 race condition local privilege escalation in the Linux kernel's XFRM subsystem.

The Zero Day Initiative disclosed a race condition in the Linux kernel's XFRM (transform) subsystem allowing local attackers to escalate privileges. Exploitation requires the attacker to first run high-privileged code on the affected system. The advisory carries a CVSS rating of 7.5; no CVE id is listed in the disclosure text.

  • Race condition LPE in Linux kernel XFRM subsystem
  • Requires prior high-privileged code execution to exploit
  • CVSS 7.5, published as ZDI-26-572
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

This source does not provide full text. Read it at zerodayinitiative.com.