THE ESSENTIALS
  • Coordinated disclosure dated September 14.

What changed

The Zero Day Initiative published details of CVE-2026-22999, a use-after-free vulnerability in the Linux kernel's QFQ Plus scheduler. According to the advisory, an attacker must already be able to execute low-privileged code locally. Successful exploitation could allow code execution in the kernel. ZDI links an upstream correction.

Why it matters

The prerequisite changes how this disclosure should be understood: it concerns escalation from an existing foothold. For administrators, the useful next question is whether their distribution includes the correction, since an upstream commit alone does not identify every installed package's status.

What remains unproven

The advisory does not report exploitation in the wild or provide a distribution-by-distribution fix matrix. Its timeline dates vendor notification to March 2025; September 14 marks public disclosure, not the initial discovery or necessarily the patch release.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. TrendAI Zero Day Initiative ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗