CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
2026-05-25T20:52:02Z•aafef6c84cb7795a72a79a1612e3dd3fb6b25c3896642e18a69ed6ba5825b3d8
CVE-2026-43284CVE-2026-43500CVE-2026-46333credential-disclosureinformation-disclosurekernellinuxlocal-privilege-escalationptracequalysrootvulnerability
What happened
Qualys Threat Research Unit published an advisory for CVE-2026-46333: a logic flaw in the Linux kernel's __ptrace_may_access() path that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions. The bug exists in mainline Linux; Qualys notes it enables local privilege escalation (LPE) and credential disclosure via the ptrace path. The feed also references related kernel LPEs (Dirty Frag: CVE-2026-43284 and CVE-2026-43500). Apply vendor/kernel patches immediately and mitigate by restricting unpr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- aafef6c84cb7795a72a79a1612e3dd3fb6b25c3896642e18a69ed6ba5825b3d8
- Enrichment time
- 2026-05-25T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.