EIP-2026-102976

PRE-CVE

RedHat Linux 5.0/5.1/5.2 / Slackware Linux 3.5 - 'klogd' Local Buffer Overflow (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102976. PoCs published by Esa Etelavuori.

AI-analyzed exploit summary This exploit targets a buffer overflow in klogd (CVE-2026-102974) by crafting a malicious symlink with a long filename containing shellcode. It leverages environment variable manipulation and self-modifying code to execute arbitrary commands, potentially leading to local privilege escalation.

Description

RedHat Linux 5.0/5.1/5.2 / Slackware Linux 3.5 - 'klogd' Local Buffer Overflow (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Esa Etelavuori · clocallinux
https://www.exploit-db.com/exploits/19315

This exploit targets a buffer overflow in klogd (CVE-2026-102974) by crafting a malicious symlink with a long filename containing shellcode. It leverages environment variable manipulation and self-modifying code to execute arbitrary commands, potentially leading to local privilege escalation.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: klogd (older versions, e.g., Red Hat 6.2)
No auth needed
Prerequisites: Vulnerable klogd version · Local access to the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026