ZDI-24-1455: Linux Kernel Net Scheduler ATM Queuing Discipline Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1455?
ZDI-24-1455 has a CVSS rating of 8.8, indicating it is a high-severity vulnerability.
How do I fix ZDI-24-1455?
To fix ZDI-24-1455, update the Linux Kernel to the latest available version that addresses this vulnerability.
What type of vulnerability is ZDI-24-1455?
ZDI-24-1455 is a use-after-free vulnerability that can lead to local privilege escalation.
Who is affected by ZDI-24-1455?
ZDI-24-1455 affects installations of the Linux Kernel that are vulnerable to the identified use-after-free condition.
What must an attacker do to exploit ZDI-24-1455?
An attacker must first have the ability to execute low-privileged code on the target system to exploit ZDI-24-1455.