Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-68138 PoC: Linux qdisc rate-table race local privilege escalation

Summary

A PoC for CVE-2026-68138, a race in Linux qdisc rate-table code causing use-after-free or double-free; validated in QEMU, it escalates an ordinary process to root on vulnerable kernels.

Why it matters

The public PoC turns the kernel race into a reproducible local root-escalation chain. It requires specific kernel configuration and an isolated lab, but hosts exposing the relevant namespace, traffic-control, and module-loading capabilities should verify that the upstream fix or an equivalent backport is present.
Vendor
Linux
Product
Linux kernel
Affected versions
Linux 5.1 through 7.1.5; 7.2-rc1 through rc4
CVSS
7.8
Published
Collected

original ↗

Related coverage

back