Skip to content
Auto-CTI
Back to today
NEW MEDIUM B2

ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability

B ZDI: Published Advisories · · CVE-2026-64530

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
9.8
EPSS
1%

Key insight

The flaw allows local attackers to escalate privileges in the Linux kernel and affects unpatched Ubuntu systems.

Description

CVE-2026-64530 is a use-after-free vulnerability in the Linux kernel's Net Scheduler Packet Classifier API. A local attacker must first be able to execute low-privileged code to exploit the flaw and escalate privileges. The ZDI has assigned a CVSS score of 8.8. Linux kernel installations are affected; active exploitation is not currently known.

Risk score

62
cvss base
98.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
113.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
30.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

1 TTP
Recon
Resource Dev
Initial Access
Execution
Persistence
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1068
Exploitation for Privilege Escalation
Privilege Escalation The attacker exploits a use-after-free vulnerability in the Linux kernel's net scheduler packet classifier API (CVE-2026-64530) after obtaining low-privileged code execution, triggering the bug to execute arbitrary code with elevated privileges. high llm
ESC