Recently, a local privilege escalation vulnerability (CVE-2026-46333) has been disclosed in the Linux kernel ptrace subsystem. When a target process has no associated mm, ptrace_may_access() bypasses the dumpable flag check. A local low-privilege user can exploit this via pidfd_getfd() to steal high-privilege file descriptors left by a de-escalated process (such as /etc/shadow, SSH host private keys), reading sensitive data and achieving privilege escalation.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-46333
https://lore.kernel.org/linux-cve-announce/2026051554-CVE-2026-46333-662a@gregkh/
important
(Severity: low, medium, important, and critical)
4.10 <= Linux kernel < 5.10.256
5.11 <= Linux kernel < 5.15.207
5.16 <= Linux kernel < 6.1.173
6.2 <= Linux kernel < 6.6.139
6.7 <= Linux kernel < 6.12.89
6.13 <= Linux kernel < 6.18.31
6.19 <= Linux kernel < 7.0.8
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 5.10 >= 5.10.256 (commit 93d4ba49d18e)
Linux Kernel 5.15 >= 5.15.207 (commit 15b828a46f30)
Linux Kernel 6.1 >= 6.1.173 (commit 4709234fd1b9)
Linux Kernel 6.6 >= 6.6.139 (commit 8f907d345bae)
Linux Kernel 6.12 >= 6.12.89 (commit 6e5b51e74a40)
Linux Kernel 6.18 >= 6.18.31 (commit 2a93a4fac7b6)
Linux Kernel 7.0 >= 7.0.8 (commit 01363cb3fbd0)
Linux Kernel 7.1 (commit 31e62c2ebbfd, original fix)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/93d4ba49d18e3d7fb41a9927c2d0cca5e9dfefd6
https://git.kernel.org/stable/c/15b828a46f305ae9f05a7c16914b3ce273474205
https://git.kernel.org/stable/c/4709234fd1b95136ceb789f639b1e7ea5de1b181
https://git.kernel.org/stable/c/8f907d345bae8f4b3f004c5abc56bf2dfb851ea7
https://git.kernel.org/stable/c/6e5b51e74a40d377bcd3081dd33fbaa0e1aa7e3d
https://git.kernel.org/stable/c/2a93a4fac7b6051d3be7cd1b015fe7320cd0404d
https://git.kernel.org/stable/c/01363cb3fbd0238ffdeb09f53e9039c9edf8a730
https://git.kernel.org/stable/c/31e62c2ebbfdc3fe3dbdf5e02c92a9dc67087a3a
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us