CVE-2026-46333
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 2% (72nd percentile). Microsoft patch: CBL-Mariner Releases.
Vulnerabilities & Exploits
A local shell on affected Debian, Fedora, and Ubuntu systems is now a root path. The mistake is treating this as a low-impact local bug; the published PoC and working exploits make ordinary user access enough to cross the privilege boundary and pull host secrets.
CVE-2026-46333 has sat in Linux since November 2016 in __ptrace_may_access(). Qualys says the flaw can expose /etc/shadow and /etc/ssh/*_key, and working exploits now exist for chage, ssh-keysign, pkexec, and accounts-daemon; patches are available from distributions.
The practical risk has shifted from latent kernel exposure to repeatable local-to-root compromise on default major-distro installs. Any host that allowed untrusted local users during the exposure window now has a credential-theft problem, not just a patching problem.
2 sources · May 21
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 2% (72nd percentile). Microsoft patch: CBL-Mariner Releases.
The Hacker News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
CVE-2026-46333 is a nine-year Linux kernel improper privilege management flaw introduced in November 2016 with a CVSS score of 5.5.
originalInfosecurity Magazine
Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
originalPart of the PlainSec briefing for 2026-05-21
Every edition of this story: Public Exploits Turn Old Linux Bug Into Root Path