HIGHVulnerability
Verified
Global

Google Project Zero Discloses Linux Kernel Zero-Day in eBPF Subsystem

Saturday, February 28, 2026 at 03:00 PM UTC·Source: Google Project Zero

Updated: Sunday, March 1, 2026 at 10:00 AM UTC

Executive Summary

Google Project Zero discloses a critical privilege escalation in the Linux kernel eBPF verifier. Affects cloud workloads, containers, and Android.

Analysis

CVE-2026-0399 is a verifier bypass in the Linux kernel eBPF subsystem allowing unprivileged users to escalate to root. Impacts kernel versions 5.15 through 6.8. Particularly dangerous in multi-tenant cloud environments and container orchestration platforms where eBPF is widely used. Kernel patches released for all LTS branches. Cloud providers patching managed instances.

Timeline

Discovered
Feb 15, 2026
Published
Feb 28, 2026
Patch Available
Feb 28, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-0399
Source Attribution

Originally published by Google Project Zero on Feb 28, 2026. Verified by: Google Project Zero, Linux Kernel Team.

Related Threats