A Linux kernel eventpoll vulnerability, designated CVE-2026-43074, allows local users to escalate privileges to root level. The flaw was confirmed on a Pixel 10 Pro and has a CVSS score of 7.8, indicating high severity. It involves a use-after-free condition in the eventpoll loop-depth check, potentially enabling kernel control. Although exploit code is publicly available, no exploitation in the wild has been confirmed. The vulnerability affects various Linux versions and has been patched in several updates. Users are advised to apply the latest kernel and Android security updates immediately.
Kernel Eventpoll Bug CVE-2026-43074 Grants Local Root Access
CyberSIXT Evidence Panel
Article by CyberSIXT