logo

PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released

ID: 3a9a9f35-bb3c-5158-862e-68ac1151e808

STIX ID: report--3a9a9f35-bb3c-5158-862e-68ac1151e808

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Guru Baran

...
...

A public proof-of-concept for "PinTheft"—a Linux local privilege escalation in the RDS zerocopy send path—allows local attackers to gain root by exploiting a zerocopy double-free to steal FOLL_PIN references via io_uring. A kernel patch is available; recommended mitigations include applying vendor kernel updates, blacklisting the rds/rds_tcp modules (e.g. creating /etc/modprobe.d/pintheft.conf), and removing loaded modules with rmmod. Exposure is limited to systems with CONFIG_RDS and CONFIG_IO_URING enabled (reported enabled by default on Arch), but the public PoC increases risk for those affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.