ended5월 15일· 1 sources

Linux Kernel 0-Day: Critical Race Condition Enables Root File Theft

Linux 커널 0-day 취약점, 권한 없는 사용자도 루트 파일 접근 가능

Why it matters

A critical Linux kernel vulnerability exploited through a race condition in process exit handling allows unprivileged users to steal sensitive root-owned files, including SSH host keys and system password hashes. Reported by Qualys and fixed by Linus Torvalds on May 14, 2026, the flaw went unpatched for six years despite initial disclosure in October 2020. The incident demonstrates how subtle kernel timing flaws can completely bypass Unix privilege separation, one of the fundamental pillars of system security.

1
Sources
+0
24h
Growth
129d
Active
Linux 0-dayprivilege escalationrace conditionSSH keysshadow file

Sources

Related Issues