logo

PoC Released: Critical Linux Kernel ptrace Flaw Publicly Disclosed—Unprivileged Root File Access Possible

ID: 134a1f50-e665-5a52-b919-e48f9eaaa8c2

STIX ID: report--134a1f50-e665-5a52-b919-e48f9eaaa8c2

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

A long-standing logic bug in the Linux kernel's ptrace handling (ptrace_may_access skipping the "dumpable" check when task->mm == NULL) permitted a race window during process exit that attackers can exploit with pidfd_getfd to steal open file descriptors from privileged processes; public PoC exploits target ssh-keysign (to steal host private keys) and chage (to grab /etc/shadow). The issue was fixed by Linus Torvalds on May 14, 2026 by preserving a cached dumpability flag or requiring CAP_SYS_PTRACE, but systems running kernels prior to the fix remain at risk and administrators are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.