logo

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

ID: a2e0ded2-d272-547b-b947-4210914f818f

STIX ID: report--a2e0ded2-d272-547b-b947-4210914f818f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: [email protected] (The Hacker News)

...
...

## Executive summary A critical local privilege-escalation flaw in the Linux kernel traffic-control pedit action (CVE-2026-46331, “pedit COW”) allows an unprivileged user inside a namespace to corrupt page-cache copies of setuid binaries and gain root; a public working exploit appeared within a day of the fix being merged. Affected systems include RHEL, Debian (trixie), and multiple Ubuntu releases; recommended actions are to install the patched kernel and reboot, or mitigate by blocking the act_pedit module or disabling unprivileged user namespaces while treating exploited hosts as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.