- Coordinated disclosure dated September 14.
What changed
The Zero Day Initiative published details of CVE-2026-22999, a use-after-free vulnerability in the Linux kernel's QFQ Plus scheduler. According to the advisory, an attacker must already be able to execute low-privileged code locally. Successful exploitation could allow code execution in the kernel. ZDI links an upstream correction.
Why it matters
The prerequisite changes how this disclosure should be understood: it concerns escalation from an existing foothold. For administrators, the useful next question is whether their distribution includes the correction, since an upstream commit alone does not identify every installed package's status.
What remains unproven
The advisory does not report exploitation in the wild or provide a distribution-by-distribution fix matrix. Its timeline dates vendor notification to March 2025; September 14 marks public disclosure, not the initial discovery or necessarily the patch release.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
