EIP-2026-102907
PRE-CVELinux Kernel 3.0 < 3.3.5 - 'CLONE_NEWUSER|CLONE_FS' Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102907. PoCs published by Sebastian Krahmer.
AI-analyzed exploit summary This exploit leverages the CLONE_NEWUSER feature in the Linux kernel to perform local privilege escalation by manipulating UID mappings in a new user namespace. It sets up a chroot environment and uses a cloned process to gain root privileges.
Description
Linux Kernel 3.0 < 3.3.5 - 'CLONE_NEWUSER|CLONE_FS' Local Privilege Escalation
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Sebastian Krahmer · clocallinux
https://www.exploit-db.com/exploits/38390
This exploit leverages the CLONE_NEWUSER feature in the Linux kernel to perform local privilege escalation by manipulating UID mappings in a new user namespace. It sets up a chroot environment and uses a cloned process to gain root privileges.
Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target:
Linux kernel (versions affected by CLONE_NEWUSER vulnerability)
No auth needed
Prerequisites:
Local access to the system · Kernel version vulnerable to CLONE_NEWUSER exploitation
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026