Nine-Year-Old Linux Kernel Bug Lets Local Users Root on Major Distros

1 min read
Source: The Hacker News
Nine-Year-Old Linux Kernel Bug Lets Local Users Root on Major Distros
Photo: The Hacker News
TL;DR Summary

Qualys disclosed CVE-2026-46333, a nine-year-old Linux kernel privilege-escalation flaw in __ptrace_may_access() that can let an unprivileged local user read /etc/shadow, access SSH private keys, and execute commands as root on Debian, Fedora, and Ubuntu; a PoC is available, patches have been released, and mitigations include updating the kernel or setting kernel.yama.ptrace_scope=2 and rotating host keys.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

2 min

vs 3 min read

Condensed

88%

44355 words

Want the full story? Read the original article

Read on The Hacker News