CVE-2026-68138 PoC:Linux qdisc 速率表竞态本地权限提升
github.com | 工具 | CVE-2026-68138 | #public-poc | #kernel-security | #privilege-escalation | #use-after-free | #linux-kernel | #exploit | #poc | #race-condition | #cve-2026-68138
摘要
CVE-2026-68138 的 PoC:Linux qdisc 速率表代码中的竞态可导致释放后使用或双重释放;已在 QEMU 中验证,可将普通进程提升至 root。
为什么值得关注
公开 PoC 将内核竞态推进到可复现的本地 root 提权链。它要求特定内核配置和隔离实验环境,但暴露主机若启用相关命名空间、流量控制和模块加载能力,仍应尽快核对内核是否包含上游修复或发行版回移补丁。
- 厂商
- Linux
- 产品
- Linux kernel
- 受影响版本
- Linux 5.1 through 7.1.5; 7.2-rc1 through rc4
- CVSS
- 7.8
- 发布时间
- 收录时间
Skip to content