CVE-2026-46333
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità · 131 giorni fa
Una shell locale su sistemi Debian, Fedora e Ubuntu interessati è ora un percorso verso root. L’errore è trattare questo come un bug locale a basso impatto; il PoC pubblicato e gli exploit funzionanti rendono sufficiente il normale accesso utente per oltrepassare il confine dei privilegi e sottrarre i segreti dell’host.
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 0.5% (41º percentile). Patch Microsoft: CBL-Mariner Releases.
2 fonti che coprono questa storia
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
CVE-2026-46333 is a nine-year Linux kernel improper privilege management flaw introduced in November 2016 with a CVSS score of 5.5.
Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
Part of the PlainSec briefing for 2026-05-22