A critical vulnerability, tracked as CVE-2026-64560, exists in the Linux kernel related to CPU timers. This use-after-free flaw allows local users to gain root access, with a CVSS score of 7.8, indicating high severity. The issue stems from a race condition between CPU timer deletion and non-leader exec() processes, which can lead to unauthorized memory access. Public exploit code has been released, increasing the urgency for updates.
While the bug has not yet been observed in the wild, affected versions include various Linux kernels before the patches were applied. Immediate updates are recommended to mitigate the risk.