CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
2026-05-21T20:51:53Z•f24b5f925c9c8039d6819d9fb5b9d982ad138b1fc852664123d83232516f5e3f
CVE-2026-43284CVE-2026-43500CVE-2026-46333ai-code-securityattack-surface-managementcloud-securitycredential-disclosuredirty-fragfedramplinux-kernellocal-privilege-escalationm365microsoft-securitypatch-tuesdayptracevulnerability-remediation
What happened
Qualys published multiple security advisories and product updates. The headline vulnerability is CVE-2026-46333, a logic flaw in the Linux kernel __ptrace_may_access() path that allows an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installs of several major distributions. Qualys also discussed the Dirty Frag local privilege escalation chain (references to CVE-2026-43284 — patched in mainline — and CVE-2026-43500), and summarized May 2026 Patch Tuesday (137 Microsoft vulnerabilities including 30 critical). Additional posts cover FedRAMP/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- f24b5f925c9c8039d6819d9fb5b9d982ad138b1fc852664123d83232516f5e3f
- Enrichment time
- 2026-05-21T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.