ZDI discloses Linux kernel clsact qdisc UAF local privilege escalation bug, CVE-2026-23413
sh4dy_0011 · x · 2026-09-15
- Zero Day Initiative (ZDI-26-694 / CVE-2026-23413) published a use-after-free local privilege escalation vulnerability in the Linux kernel's clsact qdisc net scheduler, CVSS 8.2.
- The flaw lies in handling of tcxentry objects: operations are performed without validating object existence, letting local attackers who already run high-privileged code execute arbitrary code in kernel context.
- Discovered by p0ch1ta and sh4dy, reported 2026-02-12 and coordinated-released 2026-09-14; Linux has shipped a fix (commit 5258572aa5fd). The poster notes the fix's commit message is wrong.
More from Safety
- Why an AI kill switch will never save us: inside the AI Kill Switch Act debate — shaunralston · 2026-09-15
- Neil Chilson: Congress should target AI catastrophic risk outcomes, not compliance checklists — neil_chilson · 2026-09-15
- FOIA lawsuit reveals 132 pages on secret US AI eval framework — nearly all redacted — GaryMarcus · 2026-09-15
- Amodei Calls Chinese AI Lead a 'Grave Danger,' Urges Keeping Chip Export Curbs — pstAsiatech · 2026-09-15
- China leads US in consumer AI adoption; Amodei urges keeping chip export curbs — pstAsiatech · 2026-09-15
- Third sandbox escape: OpenAI's Codex breached via CLI and Rust heap attack — EdenEmarco177 · 2026-09-15