logo

CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path

ID: e82c839b-cf13-5274-b84a-475db0bba1b0

STIX ID: report--e82c839b-cf13-5274-b84a-475db0bba1b0

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Saeed Abbasi

...
...

Qualys TRU disclosed CVE-2026-46333, a critical Linux kernel logic flaw in __ptrace_may_access() combined with pidfd_getfd that allows local unprivileged users to capture file descriptors and escalate to root or exfiltrate sensitive files (e.g., /etc/shadow and SSH host keys). The issue dates to mainline kernel v4.10-rc1 (Nov 2016), working exploits covering common setuid binaries and daemons are circulating, vendor patches and mitigations (raise kernel.yama.ptrace_scope to 2) are available, and operators should apply vendor kernel updates and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.