ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

lowVulnerabilityimportance 25
AI summary · glm-5.3-flash

The Linux kernel KVM IOAPIC has a use-after-free (CVSS 8.2) allowing local privilege escalation, but exploitation requires high-privileged code execution first.

ZDI-26-608 describes a use-after-free vulnerability in the Linux kernel's KVM IOAPIC component, with a CVSS score of 8.2. An attacker must first obtain the ability to execute high-privileged code on the target system, which limits the practical impact of the privilege escalation. The advisory text does not list an assigned CVE identifier.

  • Use-after-free in KVM IOAPIC allows local privilege escalation
  • Requires high-privileged code execution on the target first
  • CVSS 8.2; no CVE identifier given in the advisory text
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.

This source does not provide full text. Read it at zerodayinitiative.com.