{"id":250502,"date":"2026-05-20T11:40:00","date_gmt":"2026-05-20T15:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\/"},"modified":"2026-05-20T11:55:08","modified_gmt":"2026-05-20T15:55:08","slug":"cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\/","title":{"rendered":"CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path"},"content":{"rendered":"<p><a href=\"https:\/\/blog.qualys.com\/misc\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\">CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path<\/a><\/p>\n<p><a href=\"https:\/\/blog.qualys.com\/misc\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\">https:\/\/blog.qualys.com\/misc\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-20 11:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"blog.qualys.com\">blog.qualys.com<\/a><\/p>\n<p>The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel\u2019s __ptrace_may_access() function that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions. The bug has resided in mainline Linux since November 2016 (v4.10-rc1). Upstream patches and distribution updates are already available. Working exploits are circulating in public, and administrators should apply vendor kernel updates without delay.<\/p>\n<h2 id=\"what-was-found\" class=\"wp-block-heading\"><strong>What Was Found<\/strong><\/h2>\n<p>During ongoing research into Linux kernel privilege boundaries, TRU identified a narrow window in which a privileged process that is dropping its credentials remains reachable through ptrace-family operations even though its dumpable flag should have closed that path. By pairing this window with the pidfd_getfd() syscall (added in v5.6-rc1, January 2020), an attacker can capture open file descriptors and authenticated inter-process channels from a dying privileged process and re-use them under their own uid.<\/p>\n<p>The primitive is reliable and turns any local shell into a path to root or to sensitive credential material. To characterize impact across real systems, TRU built four exploits against widely deployed userland targets:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>chage<\/strong>\u00a0(set-uid-root or set-gid-shadow): discloses \/etc\/shadow. Tested on default installs of Debian 13, Ubuntu 24.04, Ubuntu 26.04, Fedora 43, and Fedora 44.<\/li>\n<li><strong>ssh-keysign<\/strong>\u00a0(set-uid-root): discloses host private keys under \/etc\/ssh\/*_key. Tested on default installs of Debian 13, Ubuntu 24.04, and Ubuntu 26.04.<\/li>\n<li><strong>pkexec<\/strong>\u00a0(set-uid-root): executes arbitrary commands as root. The attacker can be remotely logged in via sshd provided an allow_active session is present at the console. Tested on default installs of Debian 13, Ubuntu Desktop 24.04 and 26.04, and Fedora Workstation 43 and 44.<\/li>\n<li><strong>accounts-daemon<\/strong>\u00a0(root daemon): executes&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/blog.qualys.com\/misc\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path https:\/\/blog.qualys.com\/misc\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path&#8230;<\/p>\n","protected":false},"author":1,"featured_media":250504,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/ik.imagekit.io\/qualys\/wp-content\/uploads\/2024\/05\/qblog-thumbnail.png","fifu_image_alt":"","footnotes":""},"categories":[48],"tags":[90,91,97,89,71,79],"class_list":["post-250502","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","tag-cve","tag-debian","tag-fedora","tag-flaw","tag-linux","tag-ubuntu"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250502"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=250502"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250502\/revisions"}],"predecessor-version":[{"id":250506,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250502\/revisions\/250506"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/250504"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=250502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=250502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=250502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}