# CVE-2026-17523

## Summary

- **CVE ID:** CVE-2026-17523
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-825
- **Published:** Jul 27, 2026
- **Last Modified:** Sep 9, 2026

## Description

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

## Affected Products

- Red Hat — Red Hat Enterprise Linux 8 (0:4.18.0-553.156.1.rt7.497.el8_10)
- Red Hat — Red Hat Enterprise Linux 8 (0:4.18.0-553.156.1.el8_10)
- Red Hat — Red Hat Enterprise Linux 8.8 Telecommunications Update Service (0:4.18.0-477.163.1.el8_8)
- Red Hat — Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions (0:4.18.0-477.163.1.el8_8)
- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (0)
- Linux — Linux (4.19.226)
- Linux — Linux (5.4)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-17523)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2507407)
- [CNA](https://github.com/torvalds/linux/commit/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68)
- [CNA](https://access.redhat.com/errata/RHSA-2026:55765)
- [CNA](https://access.redhat.com/errata/RHSA-2026:55764)
- [CNA](https://access.redhat.com/errata/RHSA-2026:61932)
- [CNA](https://git.kernel.org/stable/c/79305a826f872fe446c6fbf8450f515053ef6951)
- [CNA](https://git.kernel.org/stable/c/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._