Status
This vulnerability is listed in the catalog of vulnerabilities that have been confirmed by CISA to be actively exploited. It is not a theoretical risk — it is being used in the wild.
Description
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Details
- Vendor: Linux
- Product: Kernel
- Added to catalog: 2026-01-26
CISA-Mandated Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Deadline for federal agencies: 2026-02-16
Linux
Kernel