• Sources: primary, discussion
  • Summary: A public repository named RustyTux publishes what it describes as a Linux kernel n-day local privilege escalation, working through a race in the kernel strparser code. It claims unprivileged local root against stock CentOS Stream 9 and Ubuntu 26.04 kernels. The claim and the affected version list are the repository's own, and this entry cites no distribution advisory confirming either.
  • Why it matters: An exploit that needs only an unprivileged local account turns a limited foothold, a web shell or a CI runner, into control of the whole host.
  • Follow-up: Whether distributions publish advisories naming the affected kernel builds and a fixed version.

send feedback on this story