STAR Labs publicly disclosed CVE-2026-53264, a Linux kernel local privilege escalation flaw in the net/sched traffic-control subsystem, and released exploit details showing how an unprivileged local user can obtain root access under specific conditions. The bug stems from a use-after-free race in tcf_idr_check_alloc(), where action objects can be freed during lookup because of a lock and RCU mismatch. The researcher demonstrated reliable exploitation on CentOS Stream 9 by racing RTM_NEWTFILTER and RTM_DELTFILTER, reclaiming freed tc_action objects, and ultimately overwriting core_pattern to execute code as root.
The write-up said exploitation depends on factors including enabled unprivileged user namespaces and relevant net/sched components such as clsact and flower, with additional techniques used to improve reliability, including an EntryBleed kASLR leak and race optimization with timerfd and epoll. Researcher Lee Jia Jie said AI helped identify the bug, generate a KASAN proof of concept, and refine exploit reliability, although human validation remained essential. The upstream patch landed on June 1 and was backported to several stable branches, but distribution-level patch coverage was still uneven, and no confirmed in-the-wild exploitation had been reported.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs publicly disclosed CVE-2026-53264, a use-after-free race in the Linux traffic-control subsystem, along with exploit code and technical details showing reliable local root exploitation under specific conditions. The writeup says the bug was assigned CVE-2026-53264 and patched, and describes exploitation against CentOS Stream 9 for TyphoonPwn 2026.
The upstream patch for the Linux kernel local privilege escalation flaw CVE-2026-53264 landed on June 1, 2026. The fix was also backported to multiple stable branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.