New Linux pedit COW Exploit Allows Attackers to Gain System Root Access
ID: f93a265e-0ffe-5b84-a45c-301df78705de
STIX ID: report--f93a265e-0ffe-5b84-a45c-301df78705de
Feed Name: cybersecurityNews.com
A high-severity Linux kernel vulnerability (CVE-2026-46331) in the net/sched act_pedit traffic-control component enables an unprivileged local attacker to escalate to root by abusing a partial COW page-cache corruption to overwrite the ELF entry point of /bin/su. The exploit (packet_edit_meme) was verified in June 2026 against multiple distributions (notably RHEL 10 and Debian 13) and impacts kernels v5.18 through v7.1-rc6; vendors have released patches (fixed in v7.1-rc7) and administrators are urged to apply patches and restrict unprivileged user namespaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
