securityonline.info 8/12/2026, 2:31:23 AM · external

Linux Kernel CPU Timer Flaw Lets Local Users Gain Root Access

Linux Kernel CPU Timer Flaw Lets Local Users Gain Root Access
Developing story vulnerability 5 articles tracked
Zoom and Linux kernel patches address multiple zero‑click and privilege escalation flaws
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability, tracked as CVE-2026-64560, exists in the Linux kernel related to CPU timers. This use-after-free flaw allows local users to gain root access, with a CVSS score of 7.8, indicating high severity. The issue stems from a race condition between CPU timer deletion and non-leader exec() processes, which can lead to unauthorized memory access. Public exploit code has been released, increasing the urgency for updates.

While the bug has not yet been observed in the wild, affected versions include various Linux kernels before the patches were applied. Immediate updates are recommended to mitigate the risk.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline