ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

lowVulnerabilityimportance 20
AI summary · glm-5.3-flash

ZDI disclosed a race condition local privilege escalation flaw in the Linux Kernel XFRM subsystem, CVSS 7.5, with no CVE assigned.

The Zero Day Initiative published ZDI-26-576 describing a race condition in the Linux Kernel XFRM subsystem. Local attackers can escalate privileges, but the advisory states an attacker must first be able to execute high-privileged code on the target. ZDI assigned a CVSS score of 7.5; no CVE identifier is listed in the advisory text.

  • Race condition in XFRM allows local privilege escalation
  • Requires prior high-privileged code execution; CVSS 7.5
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

This source does not provide full text. Read it at zerodayinitiative.com.