A use-after-free race condition in the Linux kernel's network traffic-control subsystem allows local privilege escalation to root. The flaw affects kernels from 4.14 onward, with fixes in versions 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, and 7.0.13. Exploitation requires unprivileged user namespaces and specific kernel options.