Vulnerabilities & Exploits

Public Exploits Turn Old Linux Bug Into Root Path

A local shell on affected Debian, Fedora, and Ubuntu systems is now a root path. The mistake is treating this as a low-impact local bug; the published PoC and working exploits make ordinary user access enough to cross the privilege boundary and pull host secrets.

CVE-2026-46333 has sat in Linux since November 2016 in __ptrace_may_access(). Qualys says the flaw can expose /etc/shadow and /etc/ssh/*_key, and working exploits now exist for chage, ssh-keysign, pkexec, and accounts-daemon; patches are available from distributions.

The practical risk has shifted from latent kernel exposure to repeatable local-to-root compromise on default major-distro installs. Any host that allowed untrusted local users during the exposure window now has a credential-theft problem, not just a patching problem.

2 sources · May 21

CVE-2026-46333

NVD KEV

CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 2% (72nd percentile). Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

Part of the PlainSec briefing for 2026-05-21

Every edition of this story: Public Exploits Turn Old Linux Bug Into Root Path

More from today