logo

Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes

ID: d3f4d902-9406-5dc6-9f4e-8bcb92786c42

STIX ID: report--d3f4d902-9406-5dc6-9f4e-8bcb92786c42

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

...
...

A nine-year-old Linux kernel ptrace flaw (CVE-2026-46333) allows unprivileged local users to capture file descriptors from setuid processes using pidfd_getfd, enabling theft of SSH host private keys and /etc/shadow and, in some cases, full local privilege escalation; Qualys TRU developed PoCs and working exploits (ssh-keysign, chage, pkexec, accounts-daemon), patches and distribution updates are available, and interim mitigation is raising kernel.yama.ptrace_scope to 2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.