Impact
A kernel flaw allows an unprivileged local user to execute arbitrary code in the kernel, resulting in local privilege escalation. The attacker can gain root privileges and full control over the affected system. This weakness is categorized as CWE‑825, indicating that operations are not properly restricted within the bounds of a resource.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6, 7, 8, 9, and 10. No specific kernel minor versions are listed, so all kernel variants within these distributions are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 reflects moderate to high impact. The EPSS score of <1% indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. The attack requires local, unprivileged user access and does not rely on network-based exploitation. Once exploited, the user can elevate to root and run arbitrary code. Given its local nature, the risk is primarily for systems with easy local access or compromised user accounts.
OpenCVE Enrichment