CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
2026-05-20T20:51:53Z•5c97cd6c48b547a423e943e0c1e7c8e452aaf518d5044ab1a163d2f29efea5b0
CVEDirty FragLPEcredential-disclosurekernellinuxlocal-privilege-escalationpage-cachepatchingprivilege-escalationptracequalysvulnerability-advisory
What happened
Qualys Threat Research Unit published multiple advisories and analyses in May 2026, most notably a full advisory for CVE-2026-46333 — a logic flaw in the Linux kernel __ptrace_may_access() path that permits unprivileged local users to disclose sensitive files and execute arbitrary commands as root on default installations of major distributions. The feed also covers the “Dirty Frag” LPE chain (CVE-2026-43284 and CVE-2026-43500) that abuses page caches to escalate to root, plus broader coverage including Microsoft May 2026 Patch Tuesday, vulnerability remediation research, and product/patching/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- 5c97cd6c48b547a423e943e0c1e7c8e452aaf518d5044ab1a163d2f29efea5b0
- Enrichment time
- 2026-05-20T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.