CVE-2026-46333
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 2% (72nd percentile). Microsoft patch: CBL-Mariner Releases.
Vulnerabilities · 117 days ago
A patch-only view misses the blast radius here: a decade-old ptrace flaw gives any local user on affected Linux systems a path to root and to sensitive credentials, and the problem sits in default installs of several major distributions. The old assumption was that Linux LPEs hide behind odd configs or optional modules. That no longer holds for CVE-2026-46333.
Qualys says the bug lives in __ptrace_may_access() and has been in mainline since November 2016. It published the full advisory, confirmed working exploits are circulating in public, and says upstream patches and distribution updates are available. The impact includes root execution and disclosure of files such as /etc/shadow and host SSH keys on tested default builds of Debian, Ubuntu, and Fedora releases.
For defenders, the risk is not just privilege gain. Any multi-user host that allows untrusted local code can also leak privileged file descriptors and authenticated inter-process channels, which keeps exposure alive even after the kernel is patched.
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic… EPSS 2% (72nd percentile). Microsoft patch: CBL-Mariner Releases.
4 sources covering this story
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that permits an unprivileged…
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that permits an unprivileged…
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
DirtyDecrypt PoC targets CVE-2026-31635 in CONFIG_RXGK Linux systems, enabling local privilege escalation.
PoC Released for DirtyDecrypt Linux Kernel Vulnerability
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
Exploit available for new DirtyDecrypt Linux root escalation flaw
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems.
Part of the PlainSec briefing for 2026-05-19