ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

Executive Summary

A race condition in the Linux kernel usbnet driver allows physically present attackers to gain root privileges without authentication. The vulnerability, rated CVSS 7.1, is identified as CVE-2025-22050 and can be exploited on affected kernel installations.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-14T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.

"Fortune favours the brave."

— Virgil
Source: Zero Day Initiative