New “Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices
ID: d5c38628-8402-5662-a550-d2fedda43123
STIX ID: report--d5c38628-8402-5662-a550-d2fedda43123
Feed Name: cybersecurityNews.com
**Executive Summary:** The report describes a newly disclosed Linux kernel privilege-escalation vulnerability named "Bad Epoll" (CVE-2026-46242), a use-after-free in the epoll subsystem that can be reliably exploited to obtain root on Linux and Android (including from within Chrome's renderer sandbox); the exploit uses careful race-window widening, cross-cache manipulation and ROP to achieve high reliability, and remediation requires applying the upstream kernel patch since epoll cannot be disabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
