udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.893
                        
                    
                    
                        
                            EPSS Ranking 99.5%