CVE-2026-46333
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità · 132 giorni fa
Una visione limitata alle patch perde di vista l’ampiezza dell’impatto qui: un difetto ptrace vecchio di un decennio offre a qualsiasi utente locale sui sistemi Linux interessati un percorso verso root e verso credenziali sensibili, e il problema si trova nelle installazioni predefinite di diverse distribuzioni principali. La vecchia ipotesi era che i LPE su Linux si nascondessero dietro configurazioni insolite o moduli opzionali. Questo non vale più per CVE-2026-46333.
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
4 fonti che coprono questa storia
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that permits an unprivileged…
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that permits an unprivileged…
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
DirtyDecrypt PoC targets CVE-2026-31635 in CONFIG_RXGK Linux systems, enabling local privilege escalation.
PoC Released for DirtyDecrypt Linux Kernel Vulnerability
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
Exploit available for new DirtyDecrypt Linux root escalation flaw
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems.
Part of the PlainSec briefing for 2026-05-19