HomeSecurity9-year-old Linux Kernel Vulnerability Allows Root Access

9-year-old Linux Kernel vulnerability allows root access

The recently discovered CVE-2026-46333 vulnerability in the Linux kernel remained hidden for nine years, allowing unprivileged users to gain root privileges on major distributions such as Debian , Fedora , and Ubuntu . The severity of the vulnerability lies in the fact that it affects default installations and provides a reliable path for privilege escalation . The fact that the vulnerability remained hidden for such a long time highlights the challenges the security community faces in identifying subtle privilege management issues.

Linux Kernel

According to Qualys , which discovered the vulnerability , the problem is located in the kernel's __ptrace_may_access() function and was introduced in November 2016. The vulnerability has been codenamed ssh-keysign-pwn .

The __ptrace_may_access() is critical for process access control, and its improper implementation can lead to a bypass of system security mechanisms. This type of vulnerability is particularly dangerous because it exploits fundamental kernel mechanisms responsible for maintaining security boundaries between users.

See also: Vulnerability in Ubuntu Kernel allows Root access

Successful exploitation of the vulnerability allows a local attacker to expose the /etc/shadow and the host's private keys in /etc/ssh/*_key, as well as execute arbitrary commands as root. Access to the /etc/shadow provides attackers with the hashed passwords of all users on the system, while theft of SSH private keys can lead to lateral movement to other systems on the network.

Linux: Technical details of CVE-2026-46333 and exploitation methods

The CVE-2026-46333 is a case of improper privilege management that affects four different points of exploitation. Researchers have developed exploits that target the chage, ssh-keysign, pkexec , and accounts-daemon. This variety of targets makes the vulnerability particularly dangerous, as it provides multiple paths for privilege escalation. chage is used to manage password expiration, ssh-keysign to sign SSH, pkexec to execute commands with elevated privileges, and accounts-daemon to manage user accounts. Exploiting any of these tools can lead to a complete system compromise.

The vulnerability disclosure was accompanied by the publication of a proof-of-concept (PoC) exploit last week, shortly after a public kernel commit appeared. This timing highlights the importance of promptly applying security updates, as attackers can quickly exploit published details. The availability of the PoC means that even attackers with limited technical knowledge can exploit the vulnerability, significantly increasing the risk to unpatched systems.

See also: Fragnesia: New Linux kernel vulnerability provides root access

9-year-old Linux Kernel vulnerability allows root access

CVE -2026-46333 is the latest in a series of serious vulnerabilities disclosed in the Linux kernel over the past month, including Copy Fail, Dirty Frag , and Fragnesia. This accumulation of vulnerabilities highlights the increasing complexity of the kernel and the need for tighter security controls. Modern Linux kernel vulnerabilities are becoming increasingly sophisticated, exploiting subtle interactions between subsystems rather than obvious memory management errors.

Protection measures and workarounds for the vulnerability

Linux distributions recommend applying the latest kernel updates immediately . In cases where updates cannot be applied immediately, there are workarounds that can reduce the risk. The primary workaround involves increasing the kernel.yama.ptrace_scope parameter to 2 . This setting significantly limits the ability of processes to perform ptrace operations on other processes, thereby reducing the attack surface. In addition, administrators should consider restricting access to setuid binaries and implementing stricter SELinux or AppArmor policies .

See also: Copy Fail: Linux vulnerability allows root access to systems

Qualys warns that “on hosts that have allowed untrusted local users during the exposure window, SSH host keys and locally cached credentials should be considered exposed.” The company recommends rotating host keys and reviewing any administrative hardware that was in memory for set-uid processes. This includes changing all SSH host keys, renewing SSL/TLS certificates, and checking log files for suspicious activity during the exposure window.

9-year-old Linux Kernel vulnerability allows root access

PinTheft Vulnerability

Alongside CVE-2026-46333 , a PoC was also disclosed for another privilege escalation vulnerability called PinTheft , which allows local attackers to gain root privileges on Arch Linux systems . The exploit requires the Reliable Datagram Sockets (RDS) module to be loaded, io_ring enabled , a readable SUID-root binary , and x86_64 support . The simultaneous occurrence of multiple privilege escalation vulnerabilities highlights the criticality of the situation and the need for immediate action by system administrators.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS