RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP race condition in the strparser that affects multiple major Linux distributions including CentOS Stream 9 and Ubuntu 26.04 LTS. The timing-sensitive exploit uses x86 prefetch side-channel attacks to leak kernel base addresses and reclaims freed memory to achieve unprivileged privilege escalation.
RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP use-after-free race condition in the strparser subsystem. The timing-sensitive exploit derives the kernel base via x86 prefetch side-channel, races socket teardown, and reclaims freed memory to escalate privileges. As of September 2026, the vulnerability affects standard kernels in CentOS Stream 9 and Ubuntu 26.04 LTS.