{"id":999,"date":"2026-05-21T08:38:44","date_gmt":"2026-05-21T08:38:44","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=999"},"modified":"2026-05-21T08:38:44","modified_gmt":"2026-05-21T08:38:44","slug":"9-year-old-linux-kernel-flaw-enables-root-command-execution-on-major-distros","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=999","title":{"rendered":"9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 21, 2026<\/span><\/span><span class=\"p-tags\">Linux \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiCjgJwva2lZrAwxHWPZFiphHAhxBdWRyU4gUiAZIStkUP4JU6yej3Z1xVhUtrhaIYVu4IL5KpvOomBDHU_aLtvgHV-R9_41nUSrngG0BGBlCv2pByfkVZNKxmwA3Nf6NR7pi6XgwdUjkwFw27lm_vNR_w2Cr1An46yOM8kfIEphrSCq2aRcaKNNj9D-PiN\/s1700-e365\/linux-exploit.gif\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years.<\/p>\n<p>The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. It&#8217;s also codenamed ssh-keysign-pwn.<\/p>\n<p>According to Qualys, which discovered the flaw, the problem is rooted in the kernel&#8217;s __ptrace_may_access() function and was introduced in November 2016.<\/p>\n<p>\u00abThe primitive is reliable and turns any local shell into a path to root or to sensitive credential material,\u00bb Saeed Abbasi, senior manager of Threat Research Unit at Qualys, <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2026\/05\/20\/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Successful exploitation of the flaw could permit a local attacker to disclose \/etc\/shadow and host private keys under \/etc\/ssh\/*_key, as well as execute arbitrary commands as root through four different exploits targeting chage, ssh-keysign, pkexec, and accounts-daemon.<\/p>\n<p>The disclosure comes as a proof-of-concept (PoC) exploit for the vulnerability was <a href=\"https:\/\/github.com\/0xdeadbeefnetwork\/ssh-keysign-pwn\/\">released<\/a> last week, shortly after a public kernel commit emerged. CVE-2026-46333 is the latest security vulnerability disclosed in the Linux kernel after Copy Fail, <a href=\"https:\/\/kb.cert.org\/vuls\/id\/980487\">Dirty Frag<\/a>, and Fragnesia over the past month.<\/p>\n<p>It&#8217;s recommended to apply the latest kernel update released by Linux distributions. If the updates cannot be carried out immediately, temporary workarounds include raising \u00abkernel.yama.ptrace_scope\u00bb to 2.<\/p>\n<p>\u00abOn hosts that have allowed untrusted local users during the exposure window, treat SSH host keys and locally cached credentials as potentially disclosed,\u00bb Qualys said. \u00abRotate host keys and review any administrative material that lived in the memory of set-uid processes.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgyABc30y-6FJS8pbsf2yHI1xiyGUCdTf449yj2qfWl3E27s1stzGg2L03d3pwIxexQOglShR4p9jmvpatdbA5HruPGPpb4llfRmmbJPAN_-hXf4mefY5sw2BqYTzKrh6tMIefl8wgPLaAwSyPc9eKVQvbpfsA0EqBiY4BzoYLn-KC0zSA-EH4OEUrHncwL\/s1700-e365\/pin.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgyABc30y-6FJS8pbsf2yHI1xiyGUCdTf449yj2qfWl3E27s1stzGg2L03d3pwIxexQOglShR4p9jmvpatdbA5HruPGPpb4llfRmmbJPAN_-hXf4mefY5sw2BqYTzKrh6tMIefl8wgPLaAwSyPc9eKVQvbpfsA0EqBiY4BzoYLn-KC0zSA-EH4OEUrHncwL\/s1700-e365\/pin.jpg\" alt=\"\" border=\"0\" data-original-height=\"500\" data-original-width=\"900\"\/><\/a><\/div>\n<p>The development follows the release of a PoC for a local privilege escalation flaw called <b>PinTheft <\/b>that allows local attackers to gain root privileges on Arch Linux systems. The exploit requires the Reliable Datagram Sockets (RDS) module to be loaded on the target system, io_ring to be enabled, a readable SUID-root binary, and x86_64 support for the included payload.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abPinTheft is a Linux local privilege escalation exploit for an RDS zerocopy double-free that can be turned into a page-cache overwrite through io_uring fixed buffers,\u00bb Zellic and the V12 security team <a href=\"https:\/\/github.com\/v12-security\/pocs\/tree\/09e835b587bf71249775654061ae4c79e92cf430\/pintheft\">said<\/a>.<\/p>\n<p>\u00abThe bug lived in the RDS zerocopy send path. rds_message_zcopy_from_user() pins user pages one at a time. If a later page faults, the error path drops the pages it already pinned, and later RDS message cleanup drops them again because the scatterlist entries and entry count remain live after the zcopy notifier is cleared. Each failed zerocopy send can steal one reference from the first page.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 21, 2026Linux \/ Vulnerability Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1000,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1756,1223,1757,724,13,70,1571,181,1117,61],"class_list":["post-999","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-9yearold","tag-command","tag-distros","tag-enables","tag-execution","tag-flaw","tag-kernel","tag-linux","tag-major","tag-root"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=999"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/999\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1000"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}