The Bad Epoll vulnerability in the Linux kernel is now in the spotlight of the cybersecurity community, as proof-of-concept (PoC) exploit code has been published that allows unprivileged processes to gain full root access on desktops, servers, and Android smartphones . The disclosure dramatically increases the risk of active exploitation of the vulnerability, putting system administrators worldwide on alert.

The vulnerability is tracked as CVE-2026-46242 and has a CVSS score of 7.8 (high severity). It is a race-condition use-after-free error in the epoll , which is the Linux kernel's I/O event notification facility .
Instead of asking programs to poll multiple file descriptors one by one, the Linux kernel maintains an epoll instance with an interest list and a ready list of file descriptors and return descriptors.
Bad Epoll is a close-vs-close race condition in the file-release path of epoll that leads to use-after-free.
If an eventpoll list of file descriptors is watching another and both are closed at the same time, one releases an object while the other continues to write to it.
See also: CVE-2026-23111: A character in the Linux kernel allows root access

The vulnerability was discovered by Jaeyoung Chung of the Computer Security Lab at Seoul National University , who reported it to Google kernelCTF as a zero-day submission . Notably, Bad Epoll was introduced in 2023 via a commit that also introduced CVE-2026-43074 , another race condition in the epoll code . This was discovered by Anthropic 's Mythos . Bad Epoll went unnoticed because, after CVE-2026-43074 was patched , it does not enable KASAN (Kernel Address Sanitizer), the Linux kernel's dynamic memory error detector.
Bad Epoll: Technical analysis of the exploit
Chung published a PoC exploit that exploits the Bad Epoll vulnerability to leak kernel memory and breach an indirect call, gaining control of the CPU's instruction pointer register. The final root access is achieved through a Return-Oriented Programming (ROP) chain , an advanced exploit technique that reuses existing kernel code. This makes the attack particularly dangerous, as it does not require the injection of malicious code.
Linux distributions based on kernel version 6.4 or later are affected . Bad Epoll has also been confirmed on Google 's Pixel 10 devices , which are running kernel version 6.6 . Since epoll is widely used on desktops, servers, and Android devices, the number of potentially exposed systems is in the billions worldwide. This includes cloud infrastructures such as AWS , Google Cloud , and Azure .
See also: 9-year-old Linux Kernel vulnerability allows root access
Security experts point out that race condition are particularly dangerous: they are difficult to detect and reproduce, but can be reliably triggered under certain conditions. The public release of PoC usually precedes active exploitation by malicious actors, especially in targeted environments such as corporate servers and cloud instances.

Bad Epoll: How to protect yourself from the vulnerability
Organizations and system administrators should take immediate steps to mitigate the risk of Bad Epoll. The first step is to immediately check all Linux systems for the kernel version they are using — especially those running versions 6.4 and later. Once official updates are released by vendors, they should be implemented as a priority.
Additionally, it is recommended to enable kernel hardening, such as CONFIG_STRICT_DEVMEM and CONFIG_DEBUG_LIST, which can mitigate the exploit. Monitoring system logs for unusual epoll or privilege escalation attempts is also critical. Restricting access to unprivileged processes through sandboxing and containerization can significantly reduce the attack surface. Finally, subscribing to vendor security bulletins ensures immediate updates on patch availability.
See also: Fragnesia: New Linux kernel vulnerability provides root access
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Bad Epoll is a reminder that even mature and widely used Linux, such as epoll, can hide critical security flaws. According to SecurityWeek, the situation is being closely monitored by the security community.
