CVE-2026-46333
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità ed exploit
Una shell locale su sistemi Debian, Fedora e Ubuntu interessati è ora un percorso verso root. L’errore è trattare questo come un bug locale a basso impatto; il PoC pubblicato e gli exploit funzionanti rendono sufficiente il normale accesso utente per oltrepassare il confine dei privilegi e sottrarre i segreti dell’host.
2 fonti · 21 mag
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
The Hacker News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
CVE-2026-46333 is a nine-year Linux kernel improper privilege management flaw introduced in November 2016 with a CVSS score of 5.5.
originaleInfosecurity Magazine
Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
originalePart of the PlainSec briefing for 2026-05-21
Every edition of this story: Exploit pubblici trasformano un vecchio bug Linux in un percorso verso root