Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Linux Vulnerability Enables Unauthorized Root Access

Critical Linux Vulnerability Enables Unauthorized Root Access

Posted on June 26, 2026 By CWS

A significant security flaw has been identified in the Linux kernel’s traffic-control subsystem, potentially allowing local, unauthorized users to gain root access on vulnerable systems. This flaw, designated CVE-2026-46331 and dubbed ‘pedit COW’, involves an out-of-bounds write in the packet-editing action known as act_pedit, leading to corruption of shared page-cache memory. The vulnerability was publicly disclosed on June 16, 2026, and a working exploit quickly followed.

Understanding the Exploit

The exploit targets the in-memory cached copy of a setuid root binary, bypassing file-integrity checks by injecting a payload that runs with root privileges. It requires two specific conditions: the act_pedit module must be loadable, and unprivileged user namespaces must be enabled, providing the attacker the necessary CAP_NET_ADMIN capability.

On systems like RHEL and Debian, these conditions are typically met, allowing the exploit to function as intended. The vulnerability stems from the Linux tc traffic-control tool, which modifies packet headers using the pedit action. The flaw arises when the kernel inadvertently writes to a shared page-cache page instead of a private copy, due to incorrect range checks.

Systems at Risk

Unprivileged-to-root exploitation has been reported on RHEL 10 and Debian 13 (trixie), with the latter’s default settings allowing such attacks. Although Ubuntu 24.04 still permits user namespaces, Ubuntu 26.04 blocks them by default, reducing the risk but not eliminating the underlying vulnerability.

Vendors have begun addressing this issue. Debian has patched the vulnerability in version 13, while versions 11 and 12 remain susceptible. Ubuntu’s releases from 18.04 to 26.04 are also vulnerable as of June 25, 2026. Red Hat acknowledges the flaw in RHEL 8, 9, and 10, though RHEL 7 is unaffected.

Mitigation and Future Steps

System administrators are advised to install the latest patched kernel and reboot affected systems, especially those with multiple users or exposed to potential threats. For immediate mitigation, disabling the act_pedit module can prevent exploitation, though it may affect system functionality. Alternatively, disabling unprivileged user namespaces can help, albeit at the cost of breaking some applications.

Given the nature of the exploit, which targets cached memory, regular file-integrity checks might not detect it. Administrators should clear the page cache to remove any poisoned in-memory copies, although this does not resolve an already opened root shell. The fix for this vulnerability was publicly discussed in May, but the critical nature only became clear after the CVE assignment in June.

As this vulnerability highlights the need for rapid response and proactive security measures, organizations should remain vigilant and responsive to emerging threats to minimize potential impacts of similar exploits in the future.

The Hacker News Tags:act_pedit, CVE-2026-46331, Cybersecurity, Debian, Exploit, Kernel, Linux, RHEL, root access, Security, Ubuntu, Vulnerability

Post navigation

Previous Post: Bluekit PhaaS Bypasses MFA to Steal Microsoft Credentials
Next Post: Enterprise MCP Update Poses New Security Challenges

Related Posts

New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit The Hacker News
Why Executives and Practitioners See Risk Differently Why Executives and Practitioners See Risk Differently The Hacker News
CISA Urges Fortinet Users to Secure Devices Amid Attack CISA Urges Fortinet Users to Secure Devices Amid Attack The Hacker News
GlassWorm Campaign Targets Developer IDEs with Zig Dropper GlassWorm Campaign Targets Developer IDEs with Zig Dropper The Hacker News
Trust Wallet Chrome Extension Hack Drains .5M via Shai-Hulud Supply Chain Attack Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack The Hacker News
OpenAI Unveils Codex Security for Vulnerability Detection OpenAI Unveils Codex Security for Vulnerability Detection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Amazon Q Extension Flaw Risks Developer Cloud Credentials
  • CISA Identifies Critical RCE Vulnerability in PTC Software
  • GIFTEDCROOK Malware Exploits WinRAR to Steal Data
  • AI and Cybersecurity Updates: Major Breaches and Layoffs
  • Amazon Q Developer Flaw Exposes Cloud Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Amazon Q Extension Flaw Risks Developer Cloud Credentials
  • CISA Identifies Critical RCE Vulnerability in PTC Software
  • GIFTEDCROOK Malware Exploits WinRAR to Steal Data
  • AI and Cybersecurity Updates: Major Breaches and Layoffs
  • Amazon Q Developer Flaw Exposes Cloud Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark