Executive brief
Nokia SR Linux, an open network operating system used in data centers, is affected by a security flaw that allows local privilege escalation. An attacker who already has basic access to the system could exploit this to gain full administrative (superuser) control. This could lead to a complete compromise of the networking device, allowing the attacker to intercept traffic, modify configurations, or disrupt network operations.
Technical details
A local privilege escalation vulnerability exists in Nokia SR Linux. The flaw allows an authenticated user with low-level access to bypass security restrictions and execute arbitrary commands with root/superuser privileges. While the specific root cause (such as insecure file permissions or a flaw in a SUID binary) is not detailed in the summary, the impact is a full compromise of the local operating system environment. Attackers must already have a valid local account or shell access to exploit this vulnerability. Organizations should refer to Nokia's security advisory for specific version impact and patching instructions.
Affected products
- Nokia SR Linux
Timeline
- 2026-06-16: disclosed: Initial disclosure by Nokia and NVD publication.