Institutional high-quality accreditation link stiky-sticky

▲ Back to Top

New vulnerability in Linux allows root escalation and credential exposure

Qualys, Inc., a cloud-based IT, security, and compliance solutions company, has unveiled a critical vulnerability in the Linux kernel that allows unprivileged local users to access sensitive information and execute arbitrary commands with privileges of root in default configurations of several widely used Linux distributions.

Identified as CVE-2026-46333, the flaw resides in the __ptrace_may_access() function and has been present in the Linux mainline branch since November 2016 (version v4.10-rc1). In fact, as of today, patches and updates are already available from major vendors, although they are also circulating publicly exploits fully functional. The vulnerability turns any shell local on a potential path to privileges of root or toward the exposure of highly sensitive information.

Impact on real systems

To show the scope of the vulnerability, Qualys researchers have experimented with four exploits functional directed at widely deployed components:

  • change (set-uid-root or set-gid-shadow): allows access to the /etc/shadow file. Tested on default installations of Debian 13, Ubuntu 24.04, Ubuntu 26.04, Fedora 43, and Fedora 44.
  • ssh-keysign (set-uid-root): enables the extraction of host SSH private keys stored in /etc/ssh/*_key. Validated on Debian 13 and Ubuntu 24.04/26.04.
  • pkexec (set-uid-root): allows executing arbitrary commands as root and even initiating remote sessions via SSH under certain conditions. Tested on Debian 13, Ubuntu Desktop 24.04/26.04 LTS, and Fedora Workstation 43/44.
  • accounts-daemon (root daemon): facilitates the arbitrary execution of commands with administrator privileges. Verified on Debian 13 and Fedora Workstation 43/44.

According to Qualys analysts, these cases represent only a sample of the potential attack surface. Other privileged binaries setuid, set-gid, special capabilities or demons executed as root they could turn out to be equally vulnerable.

Although the vulnerability requires local access to the system, its severity is high and it should not be considered low priority. In practice, the difference between an unprivileged account and total system compromise disappears. Any attacker who gains initial access through phishing, stolen credentials, restricted CI environments, or shared multi-user systems could rapidly escalate to administrator privileges.

Urgent recommendations

Qualys recommends that organizations immediately adopt the following measures:

  1. Update the kernel using the fixed packages for each distribution.
  2. Rotate SSH keys and review sensitive credentials in systems that have allowed local access to untrusted users during the exposure period.
  3. Apply temporary mitigations, raising kernel.yama.ptrace_scope to 2 in all those environments where patching must be delayed.
  4. Check the official notices published by vendors such as Red Hat, SUSE, Debian, Fedora, AlmaLinux, and CloudLinux for specific mitigation details and fixed versions.

See more

More SGSI news at the News Agency

News

News

News

News