logo

The 4th Linux kernel flaw this month can lead to stolen SSH host keys

ID: 452facb6-4408-56bb-915f-c0dcb07641c3

STIX ID: report--452facb6-4408-56bb-915f-c0dcb07641c3

Feed Name: ZDNet Security

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

ZDNET reports on CVE‑2026‑46333 ("ssh‑keysign‑pwn"), a Linux kernel ptrace logic flaw that allows unprivileged users to grab file descriptors from processes during shutdown (via pidfd_getfd), enabling theft of SSH host keys and shadow password hashes; Qualys released a reliable PoC, kernel patches have been published for multiple branches, and short‑term mitigations include tightening ptrace scope or disabling host‑based SSH/ssh‑keysign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.