securityonline.info 8/25/2026, 3:02:11 AM · external

CVE-2026-53365 Vsock flaw allows privilege escalation on Linux

CVE-2026-53365 Vsock flaw allows privilege escalation on Linux
CyberSIXT Evidence Panel
Primary Source github.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-53365) has been identified in the Linux kernel that allows unprivileged local privilege escalation via Vsock. This exploit does not require elevated rights, making it a significant concern for shared and multi-tenant environments. The flaw is due to improper handling of message buffers in the io_uring zerocopy send path. It was patched in kernel versions 7.0.11 and above, and urgent updates are recommended. Currently, the exploit is deemed of high risk (CVSS 7.8), with a low probability of exploitation (0.2% EPSS), but proactive measures are advised.

View Primary Source Via securityonline.info

Article by CyberSIXT