HIGHVulnerability
Verified
Global
Google Project Zero Discloses Linux Kernel Zero-Day in eBPF Subsystem
Saturday, February 28, 2026 at 03:00 PM UTC·Source: Google Project Zero
Updated: Sunday, March 1, 2026 at 10:00 AM UTC
Executive Summary
Google Project Zero discloses a critical privilege escalation in the Linux kernel eBPF verifier. Affects cloud workloads, containers, and Android.
Analysis
CVE-2026-0399 is a verifier bypass in the Linux kernel eBPF subsystem allowing unprivileged users to escalate to root. Impacts kernel versions 5.15 through 6.8. Particularly dangerous in multi-tenant cloud environments and container orchestration platforms where eBPF is widely used. Kernel patches released for all LTS branches. Cloud providers patching managed instances.
Timeline
Discovered
Feb 15, 2026
Published
Feb 28, 2026
Patch Available
Feb 28, 2026