Výsledky hledání

výrobce: Linux× v celém archivu zrušit filtry

58 karet z 61 položek CZ · EN/orig

2

Linux Kernel — Four Public Local-Root Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 8.8, CVEs: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, CVE-2026-74469, Summary: A coordinated disclosure has made public four Linux kernel vulnerabilities capable of local privilege escalation to root: DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) and DiagSpill (CVE-2026-74469). Public proof-of-concept exploits are available. The first three generally require…

EPSS 0.00 CVSS 8.8 CVE-2026-68121 CVE-2026-74469 CVE-2026-80844 CVE-2026-81000 Linux FI

tg: zranitelnost

· NCSC-FI · Linux Kernel — Four Public Local-Root Vulnerabilities

Linux Kernel — Multiple Security Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-93203, CVE-2026-93201, CVE-2026-93196, CVE-2026-93192, CVE-2026-93190, CVE-2026-93189, CVE-2026-93178, CVE-2026-93177, CVE-2026-93176, CVE-2026-93175, CVE-2026-93170, CVE-2026-93165, CVE-2026-93154, CVE-2026-93151, CVE-2026-93148, CVE-2026-93147, CVE-2026-93144, CVE-2026-93138, CVE-2026-93137, CVE-2026-93127 (+146 other associated CVEs), Summary: The Linux kernel project has disclosed a…

CVSS 9.8 Linux FI

tg: zranitelnost

· NCSC-FI · Linux Kernel — Multiple Security Vulnerabilities

6

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management…

KEV ✓ EPSS 0.01 CVE-2025-39682 Linux veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-39682)

1

SPOJENO PŘES CVE ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…

KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU

tg: zneužíváno tg: zranitelnost tg: rozbor tp: průmyslové systémy

· CISA Advisories · ABB Ability Edgenius · Fortinet PSIRT · Linux Kernel Vulnerability copy.fail - CVE-2026-31431 · Elastic Security · Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild · CERT-EU · 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") · CERT.at · Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte · NKI Maďarsko · Riasztás a Linux rendszereket érintő Copy Fail sérülékenységről

23

ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-31719.

EPSS 0.00 CVSS 8.8 CVE-2026-31719 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-64265.

EPSS 0.00 CVSS 7.8 CVE-2026-64265 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability

ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.

EPSS 0.00 CVSS 6.0 CVE-2026-43040 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-72463.

EPSS 0.00 CVSS 7.5 CVE-2026-72463 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.

EPSS 0.00 CVSS 9.0 CVE-2026-64397 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-38416.

EPSS 0.00 CVSS 8.8 CVE-2025-38416 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability

ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74565.

EPSS 0.00 CVSS 7.8 CVE-2026-74565 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability

ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.

EPSS 0.00 CVSS 6.4 CVE-2026-80994 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability

ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74465.

EPSS 0.00 CVSS 7.8 CVE-2026-74465 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability

ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-46227.

EPSS 0.00 CVSS 6.4 CVE-2026-46227 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability

ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-45930.

EPSS 0.00 CVSS 6.0 CVE-2026-45930 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-53182.

EPSS 0.00 CVSS 8.2 CVE-2026-53182 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability

ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability

This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-31583.

EPSS 0.00 CVSS 7.1 CVE-2026-31583 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability

ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

CVSS 8.5 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability

ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.

EPSS 0.00 CVSS 8.2 CVE-2026-23413 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.

EPSS 0.01 CVSS 8.5 CVE-2026-89688 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.

EPSS 0.00 CVSS 8.8 CVE-2026-72196 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.

CVSS 7.3 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

CVSS 5.2 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

CVSS 5.2 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.

EPSS 0.00 CVSS 7.8 CVE-2026-22999 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.

EPSS 0.01 CVSS 6.7 CVE-2026-64046 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.

EPSS 0.00 CVSS 7.1 CVE-2025-22050 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

5

Linux Detection Engineering - Local Privilege Escalation

Local privilege escalation (LPE) is the step that turns a foothold into full control of a host. An attacker who lands as an unprivileged user rarely stops there. They want root, and Linux keeps offering new ways to get it.In this edition of our "Linux Detection Engineering" series, we’ll cover:The default flow that a Linux LPE produces on the host and the general rules that detect it.The recurring LPE patterns behind the most recent LPEs and how each works, along with how each looks through the…

Linux Elastic US

tg: rozbor tg: návod tp: AI

· Elastic Security · Linux Detection Engineering - Local Privilege Escalation

1

ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

CVSS 8.8 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

5

SPOJENO PŘES CVE Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root

Dirty Frag turns low-privileged Linux access into root, and can escape containers. The affected CVEs, how to check if you're exposed, and how to fix it. Category: Vulnerabilities & Threats

EPSS 0.93 CVE-2026-43284 Linux BE HU

tg: zranitelnost tg: návod

· Aikido Security · Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root · NKI Maďarsko · Riasztás a Linux rendszereket érintő Dirty Frag sérülékenységről

Multiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

EPSS 0.01 CVE-2025-40074 CVE-2026-64216 CVE-2026-64581 CVE-2026-74626 CVE-2026-74653 CVE-2026-74662 CVE-2026-80536 CVE-2026-80557 CVE-2026-80562 CVE-2026-80572 CVE-2026-80583 CVE-2026-80590 CVE-2026-80725 Debian Linux FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)

1

1

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

2

ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.

CVSS 8.2 Linux US

· Zero Day Initiative · ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 Linux US

· Zero Day Initiative · ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability

1

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …

KEV ✓ · ransomware EPSS 0.97 CVE-2025-49132 CVE-2026-15409 CVE-2026-27760 CVE-2026-29053 CVE-2026-3891 CVE-2026-46300 CVE-2026-48907 CVE-2026-60137 CVE-2026-63030 WordPress Ghost CMS SonicWall Linux US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: Lot of summer shells and fit http profiles

6

ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVSS 7.5 Linux US

· Zero Day Initiative · ZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability

ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVSS 7.5 Linux US

· Zero Day Initiative · ZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability

ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVSS 7.5 Linux US

· Zero Day Initiative · ZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability

ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-46319.

EPSS 0.00 CVSS 7.5 CVE-2026-46319 Linux US

· Zero Day Initiative · ZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability

ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVSS 7.5 Linux US

· Zero Day Initiative · ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

CVSS 7.5 Linux US

· Zero Day Initiative · ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

2

ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 Linux US

· Zero Day Initiative · ZDI-26-442: Linux Kernel CAN ISO-TP Protocol Race Condition Local Privilege Escalation Vulnerability

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

CVSS 8.8 Linux US

· Zero Day Initiative · ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Local Privilege Escalation Vulnerability

1

Hooked on Linux: Rootkit Detection Engineering

Introduction In part one, we examined how Linux rootkits work: their evolution, taxonomy, and techniques for manipulating user space and kernel space. In this second part, we turn to detection engineering. We begin by showing why static detection is often unreliable against Linux rootkits, even when binaries are only trivially modified, and then move on to behavioral and runtime signals that defenders can use instead. From shared object abuse and LKM loading to eBPF, io_uring, persistence, and…

Linux US

tg: rozbor tg: návod tp: malware

· Elastic Security · Hooked on Linux: Rootkit Detection Engineering

1