New CentOS 9 Vulnerability Lets Attackers Escalate to Root Privileges – PoC Released
ID: 75307bc5-700b-594e-8f4f-e6e8b949180f
STIX ID: report--75307bc5-700b-594e-8f4f-e6e8b949180f
Feed Name: cybersecurityNews.com
Threat Score
**CentOS 9 CAKE Qdisc use-after-free LPE:** A critical use-after-free flaw in the Linux kernel's CAKE traffic-control qdisc can be abused by a local attacker on CentOS 9 to gain root; the report includes root-cause code excerpts, a PoC exploit chain (KASLR bypass, fake qdisc spraying, ROP to overwrite modprobe_path), vendor notification status, and mitigations such as removing CAKE qdisc, monitoring netlink/tc activity, and updating kernels when patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
