LIVE · cybersecurity feed
Live wire

toctou

linux kernelhigh

ZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability has been discovered in the Linux Kernel's Net Scheduler packet classifier API. The flaw stems from improper locking during object operations, allowing a local attacker with high-privileged code execution to escalate their privileges and run code within the kernel context. Linux has released an update to address this issue.