CVE-2026-7270CWE-783

Local privilege escalation via execve()

High · published April 30, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
7.5
In the wild
Unconfirmed
What it is

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers.

The bug may be exploitable by an unprivileged user to obtain superuser privileges.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00179 · 7.5th percentile
Weakness
CWE-783 · Operator Precedence Logic Error
Published
2026-04-30T07:02Z
EPSS history
Timeline
  • 30 APR 07:02Z
    Local privilege escalation via execve()
    cvelistv5