Recently, a local privilege escalation vulnerability (CVE-2026-46331) has been disclosed in the Linux kernel net/sched act_pedit module. tcf_pedit_act() computes the COW range once before the key loop using tcfp_off_max_hint, but this hint does not account for runtime header offsets added by typed keys, leaving part of the write region un-COW'd. An attacker with CAP_NET_ADMIN (via unprivileged user namespaces) can construct malicious tc rules to write to shared read-only pages, tamper with setuid-root binary page cache, and achieve local privilege escalation to root.
Linux kernel is the core component of Linux operating systems. Check your system and implement timely security hardening.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-46331
https://lore.kernel.org/linux-cve-announce/2026061625-CVE-2026-46331-47be@gregkh/
important
(Severity: low, medium, important, and critical)
5.10 <= Linux kernel < 5.10.260
5.15 <= Linux kernel < 5.15.221
6.1 <= Linux kernel < 6.1.117
6.6 <= Linux kernel < 6.6.144
6.12 <= Linux kernel < 6.12.94
6.18 <= Linux kernel < 6.18.36
7.0 <= Linux kernel < 7.0.13
All Linux-based system distributions running an affected kernel version are impacted, including but not limited to Ubuntu, Red Hat Enterprise Linux, Oracle Linux, SUSE, Amazon Linux, and other embedded/custom systems.
Linux Kernel 5.10 >= 5.10.260 (commit 544d857b42a1)
Linux Kernel 5.15 >= 5.15.221 (commit d5d01d35a5a7)
Linux Kernel 6.1 >= 6.1.117 (commit a071e057518d)
Linux Kernel 6.6 >= 6.6.144 (commit b685d6ef6f07)
Linux Kernel 6.12 >= 6.12.94 (commit 2bec122b9fb9)
Linux Kernel 6.18 >= 6.18.36 (commit b198ed4e5258)
Linux Kernel 7.0 >= 7.0.13 (commit 3dee9d0c198f)
Linux Kernel 7.1 (commit 899ee91156e5, original fix)
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2
https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc
https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5
https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5
https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b
https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313
https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512
https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a
For details about the fixed versions of Linux vendors, see the security notices of Amazon Linux, Oracle Linux, Red Hat, SUSE and Ubuntu.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us