PoC Released: Critical Linux Kernel ptrace Flaw Publicly Disclosed—Unprivileged Root File Access Possible
ID: 134a1f50-e665-5a52-b919-e48f9eaaa8c2
STIX ID: report--134a1f50-e665-5a52-b919-e48f9eaaa8c2
Feed Name: securityonline.info
A long-standing logic bug in the Linux kernel's ptrace handling (ptrace_may_access skipping the "dumpable" check when task->mm == NULL) permitted a race window during process exit that attackers can exploit with pidfd_getfd to steal open file descriptors from privileged processes; public PoC exploits target ssh-keysign (to steal host private keys) and chage (to grab /etc/shadow). The issue was fixed by Linus Torvalds on May 14, 2026 by preserving a cached dumpability flag or requiring CAP_SYS_PTRACE, but systems running kernels prior to the fix remain at risk and administrators are urged to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
