logo

Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords

ID: a64b00d4-8724-51ae-b422-6ff8d6ab5957

STIX ID: report--a64b00d4-8724-51ae-b422-6ff8d6ab5957

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Dhivya

...
...

A logic flaw in the Linux kernel ptrace access control (CVE-2026-46333, "ssh-keysign-pwn") creates a race window where an unprivileged local attacker can use pidfd_getfd to steal file descriptors from privileged helpers (e.g., ssh-keysign, chage), enabling theft of SSH host keys and /etc/shadow password hashes; a public GitHub PoC exists, many distributions are affected, and immediate patching, key rotation, and access restrictions are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.