EIP-2026-102913

PRE-CVE

Linux libc 5.3.12/5.4 (RedHat Linux 4.0) - 'vsyslog()' Local Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102913. PoCs published by Solar Designer.

AI-analyzed exploit summary This exploit targets a buffer overflow in the vsyslog() function in Linux libc 5.4.32 and below, leveraging the suid root program 'su' to execute arbitrary code and gain root access. The exploit uses a shellcode payload and stack manipulation to achieve local privilege escalation.

Description

Linux libc 5.3.12/5.4 (RedHat Linux 4.0) - 'vsyslog()' Local Buffer Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by Solar Designer · clocallinux
https://www.exploit-db.com/exploits/19360

This exploit targets a buffer overflow in the vsyslog() function in Linux libc 5.4.32 and below, leveraging the suid root program 'su' to execute arbitrary code and gain root access. The exploit uses a shellcode payload and stack manipulation to achieve local privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Linux libc 5.4.32 and below
No auth needed
Prerequisites: Access to a system with vulnerable libc version · Presence of the 'su' binary with suid root permissions
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026