ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability
Published Aug 24, 2026
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
1 affected component
Linux Linux kernel
Event History
Aug 24, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must already be able to execute low-privileged code locally on an affected Linux kernel installation. The issue is therefore relevant to systems where untrusted users, local accounts, workloads, or code execution footholds are present.
2
What is the potential impact after exploitation?
A successful exploit allows a local attacker to escalate privileges on the affected system.
3
What severity information is available?
ZDI assigned this vulnerability a CVSS rating of 7.8. The provided risk value is 52.