logo

CVE-2026-53365: VsockDrop PoC Enables Unprivileged Local Privilege Escalation

ID: 87fb9275-ab75-5ba9-9d15-a5a82b772d40

STIX ID: report--87fb9275-ab75-5ba9-9d15-a5a82b772d40

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Do Son

...
...

A public proof-of-concept named VsockDrop exploits CVE-2026-53365 in the Linux kernel vsock zerocopy send path to achieve unprivileged local privilege escalation to root by deterministically decrementing page pins and reclaiming a freed page to modify /usr/bin/su; the bug affects kernels from 6.7 through 7.0.10, has upstream patches (e.g., 7.0.11, 6.18.34), and administrators are advised to update kernels or restrict AF_VSOCK/ local access until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.