Linux kernel traffic-control subsystem use-after-free race
Use-after-free race in the Linux kernel's tc subsystem lets a local user escalate to root. CVSS 7.8 high. Public exploit for CentOS Stream 9 published by STAR Labs.
- Vendor
- Linux
- Product
- Linux Kernel (traffic-control subsystem)
- CVSS
- 7.8
- EPSS (exploit probability)
- N/A
- Status
- unpatched
- Published
A use-after-free race condition in the Linux kernel’s network traffic-control (tc) subsystem allows an unprivileged local user to corrupt kernel memory and escalate to root. Demonstrated on CentOS Stream 9 by STAR Labs researcher Lee Jia Jie, who noted AI tooling accelerated both bug discovery and exploit development. CVSS 7.8.
Patch status: no vendor patch has been announced as of July 28, 2026. Check your distribution’s security advisories. Red Hat, Debian, Ubuntu, and SUSE typically respond to kernel LPEs of this size within days of public disclosure.
Primary exposure: multi-tenant Linux systems, shared servers, and containerized workloads where untrusted users hold shell access.
