ZDI-CAN-26601: ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Affected Linux Kernel installations are exposed when an attacker can execute low-privileged code locally on the system. This is a local privilege-escalation issue, so it does not describe unauthenticated remote exploitation.
What access does an attacker need to exploit it?
The attacker must first be able to run low-privileged code on the target system. Successful exploitation can then allow escalation of privileges.
What identifier should be used to track this vulnerability?
Track this issue as CVE-2026-22999. The associated ZDI advisory identifier is ZDI-26-700.