Linux exploit instantly grants administrator access on most distributions since 2017 — cryptography optimization snafu grants root privileges to local users

TL;DR AI
2 min readKey summary
Researchers disclosed a patched Linux kernel bug in the AF_ALG cryptography path that can let local users gain root privileges.
The flaw abuses an optimization in algif_aead to overwrite executable data in memory, enabling privilege escalation on major distributions.
It has reportedly existed since 2017 and affects environments such as Ubuntu 24, RHEL 10, SUSE 16, Amazon Linux 2023, and WSL2.
Shared servers, containers, CI/CD systems, and other multi-user Linux deployments are at risk until patches are fully applied.

