EIP-2026-102907

PRE-CVE

Linux Kernel 3.0 < 3.3.5 - 'CLONE_NEWUSER|CLONE_FS' Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102907. PoCs published by Sebastian Krahmer.

AI-analyzed exploit summary This exploit leverages the CLONE_NEWUSER feature in the Linux kernel to perform local privilege escalation by manipulating UID mappings in a new user namespace. It sets up a chroot environment and uses a cloned process to gain root privileges.

Description

Linux Kernel 3.0 < 3.3.5 - 'CLONE_NEWUSER|CLONE_FS' Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sebastian Krahmer · clocallinux
https://www.exploit-db.com/exploits/38390

This exploit leverages the CLONE_NEWUSER feature in the Linux kernel to perform local privilege escalation by manipulating UID mappings in a new user namespace. It sets up a chroot environment and uses a cloned process to gain root privileges.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel (versions affected by CLONE_NEWUSER vulnerability)
No auth needed
Prerequisites: Local access to the system · Kernel version vulnerable to CLONE_NEWUSER exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026