CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path

2026-05-25T20:52:02Zaafef6c84cb7795a72a79a1612e3dd3fb6b25c3896642e18a69ed6ba5825b3d8
CVE-2026-43284CVE-2026-43500CVE-2026-46333credential-disclosureinformation-disclosurekernellinuxlocal-privilege-escalationptracequalysrootvulnerability

What happened

Qualys Threat Research Unit published an advisory for CVE-2026-46333: a logic flaw in the Linux kernel's __ptrace_may_access() path that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions. The bug exists in mainline Linux; Qualys notes it enables local privilege escalation (LPE) and credential disclosure via the ptrace path. The feed also references related kernel LPEs (Dirty Frag: CVE-2026-43284 and CVE-2026-43500). Apply vendor/kernel patches immediately and mitigate by restricting unpr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
aafef6c84cb7795a72a79a1612e3dd3fb6b25c3896642e18a69ed6ba5825b3d8
Enrichment time
2026-05-25T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.